Cleanup of a hacked PrestaShop or WordPress website
Redirects, a Google warning, a suspended account, files nobody created. First the damage is stopped, then the door is closed.
Who it is for
Fixed price, urgency carries a premium.The site redirects elsewhere, the provider has suspended the account, Google flags the page as dangerous, files or users appear that nobody created, customers get odd emails from your domain. It has already happened: what counts now is how fast it gets closed.
For a PrestaShop shop or a WordPress site on a Linux server that can be reached. First the damage is stopped, then we find out how the attacker got in, and only at the end the site reopens.
What it covers
- immediate containment: site in maintenance, credentials changed, suspicious access closed
- removal of webshells, droppers, exposed file managers, fake admin accounts, code injected into templates
- closing the way in: vulnerable plugin or module, open upload, stolen credential, wrong permissions
- preservation of logs and removed files, for the report and for the notification to the data protection authority if personal data is involved (GDPR, article 33, within 72 hours)
Urgency carries a premium: starting within eight working hours, or within two, costs more than starting within one day. Work begins on a deposit.
What you get
Site cleaned and back online, hole closed, a report on how the attacker got in, what they touched and what was done. With the report you ask Google to lift the warning and the provider to restore the account.
Order by emailIf the site is down right now, send the email anyway: urgent messages are read first.
Questions
- Is restoring a backup enough?
- Almost never. A backup puts the site back as it was, with the same door open, and often the door has been inside the backup for weeks. Restoring can be one step of the cleanup, not the cleanup.
- How long does the site stay offline?
- As long as it takes to clean it and close the way in. Reopening earlier means getting hacked again, and Google takes longer to lift the second warning.
- Do I have to notify the data protection authority?
- If the attacker may have read personal data, yes, within 72 hours of finding out. The report says what was touched, which is what the decision rests on. The notification itself is not included.
From the email to the invoice
Times count in working days. If your mail program does not open, write to the address at the bottom of the page with the same subject line.
- Right awaypick the engagement and send the pre filled email, with the answers to the questions
- 1 working dayyou get an acknowledgement with the missing questions, or the quote with price, deliverables and timing. The quote is valid for fifteen days
- On your yesthe proforma invoice arrives. Fixed price work is paid half up front and half on completion, the cleanup starts on a deposit, the monthly block is paid before the month
- On paymentwork starts. Access is exchanged only now, on a dedicated account and over an agreed channel, never in the order email
- When the work endsreport, electronic invoice for the balance, access revoked
What stays out
- how long Google and providers take to lift a warning or restore an account: the request goes in once the cleanup is done, the answer is theirs
- a cleanup without access to the server, because nothing gets cleaned from the front end alone
- the signed forensic report and the notification to the authority, which are separate engagements
Order from Detector, the client portal: hours come off your prepaid balance and the proforma is issued from there, with no email in between.
Open Detector