Website hacked — we clean it, close the entry point and remove penalties
Redirects to third-party pages, Google warnings, hosting blocked for spam. We start recovery by finding the entry point, not by deleting files: otherwise everything will come back in a week. Recovery €690, typical timeframe 1-3 days.
turnkey
to return to operation
after cleaning
entry point first
What a hacked website looks like
Symptoms vary, but the cause is usually the same: an outdated plugin, a stolen password, or a vulnerability in third-party code. The sooner you act, the less damage to search and email.
Redirects to third-party websites
From a phone or from search results the site leads to a casino or pharmacy, while from your computer it opens normally — this is how it hides from the owner.
Warning in search
Google flags "This site may harm your computer" or drops pages from search results. Sanctions are lifted by submitting a request after cleanup.
Hosting blocked for spam
A mailing was sent from your server, the domain ended up on blocklists, and emails to clients stopped being delivered.
Unknown users in the admin panel
Accounts with administrator rights appeared that nobody created, or access to your account was lost.
Suspicious files and injected code
PHP files with random names in the site root, an unknown script in the header, and injected links in the database.
The site has become slow
Server load has increased sharply: someone else's code is mining, sending spam, or distributing third-party files at your expense.
Restoration step by step: first the entry point, then cleanup
Isolation and snapshot
We take a copy of the infected site — it will be needed for investigation. If necessary, we put up a temporary page to avoid accumulating penalties.
Finding the entry point
We review access logs, file modification dates, known plugin vulnerabilities, and environment versions. Until we understand how the attacker got in, cleanup is pointless.
Cleanup and closing the hole
We remove malicious code from files and the database, update vulnerable components, and change all credentials: hosting, admin panel, database, FTP, email.
Removing penalties and monitoring
We submit a reconsideration request in Google Search Console and remove the domain from blocklists. We keep file change monitoring for 30 days.
How much does recovery after a hack cost
We quote after an initial inspection. If the site has been infected for a long time and there is no clean copy, we will say so directly: rebuilding is cheaper.
We work with WordPress, Bitrix, Joomla, Laravel and custom PHP. Recovery includes a report: how they got in and what was done to prevent it from happening again.
What you get besides a clean website
Report with the entry point
How exactly they got in, what they managed to do, what was closed. Without this, you cannot be sure they will not return.
Clean copy
Verified backup of files and database after cleaning, stored outside the site server.
New access list
All passwords changed and provided to you: hosting, admin panel, database, FTP, email, repository.
Hygiene checklist
What to update, who to remove excess permissions from, where to enable two-factor authentication.
When cleaning is not worth it
Sometimes restoration costs more than rebuilding, and we say this before invoicing:
- Infection lasts for months — no clean copies remain, thousands of files have been modified, and the engine has not been updated for a long time. Checking every file is more expensive than rebuilding on the current version.
- Engine is no longer supported — old Joomla, Drupal 7, custom code on PHP 5: there is nothing to patch the hole with, the next hack is a matter of weeks.
- No hosting access — without server access you can neither view logs nor change passwords. First we regain control.
- The site will have to be redone anyway — if a new version is planned in the coming months, it is more reasonable to invest the budget in it and temporarily close the current site.
In such cases we will show two invoices side by side — cleanup and a new version — and tell you what we would choose ourselves.
Frequently asked questions about recovery after a hack
Can you just restore from a backup?
How long will it take?
What should be done right now?
Google has already flagged the site. Is this permanent?
How did they get in at all?
Emails to clients are not being delivered — is this related?
What should be done to prevent it from happening again?
We use WordPress — is it attacked more often?
Describe what is happening with the website
We need the website address, when you noticed the problem, and what you have already done. We reply within 60 minutes during working hours (GMT+3).
Request sent
Thank you! We will contact you within an hour. If the site is already flagged in search, write to Telegram and we will take it urgently.
Cleaning without finding the cause is a delay, not a solution
Send the site address and symptoms. We will come back with an assessment of the scope, timeline and fixed price for the work.