---
title: "Hacked PrestaShop and WordPress site cleanup · Ing. Brasile"
description: "Hacked site, redirects, Google warning, suspended account: removal of webshells and backdoors, the way in closed, a report. Urgency carries a premium."
url: https://brasile.pro/en/order/hacked-website-cleanup/
lang: en
---
[All engagements](https://brasile.pro/en/order/)

# Cleanup of a hacked PrestaShop or WordPress website

Redirects, a Google warning, a suspended account, files nobody created. First the damage is stopped, then the door is closed.

## Who it is for

**Fixed price, urgency carries a premium.**The site redirects elsewhere, the provider has suspended the account, Google flags the page as dangerous, files or users appear that nobody created, customers get odd emails from your domain. It has already happened: what counts now is how fast it gets closed.

For a PrestaShop shop or a WordPress site on a Linux server that can be reached. First the damage is stopped, then we find out how the attacker got in, and only at the end the site reopens.

## What it covers

- immediate containment: site in maintenance, credentials changed, suspicious access closed
- removal of webshells, droppers, exposed file managers, fake admin accounts, code injected into templates
- closing the way in: vulnerable plugin or module, open upload, stolen credential, wrong permissions
- preservation of logs and removed files, for the report and for the notification to the data protection authority if personal data is involved (GDPR, article 33, within 72 hours)

Urgency carries a premium: starting within eight working hours, or within two, costs more than starting within one day. Work begins on a deposit.

## What you get

Site cleaned and back online, hole closed, a report on how the attacker got in, what they touched and what was done. With the report you ask Google to lift the warning and the provider to restore the account.

[Order by email](mailto:info@brasile.pro?subject=Order%3A%20cleanup%20of%20a%20hacked%20website&body=Engagement%3A%20hacked%20website%20cleanup%0AAddress%20of%20the%20site%3A%0AWhat%20you%20see%20%28redirect%2C%20Google%20warning%2C%20email%20from%20the%20provider%2C%20odd%20files%20or%20users%29%3A%0ASince%20when%3A%0AIs%20the%20site%20still%20online%20%28yes/no%29%3A%0AHosting%20or%20control%20panel%3A%0ACMS%20and%20version%3A%0AIs%20there%20a%20backup%2C%20and%20from%20when%3A%0AUrgency%20%28within%20one%20day%20/%20within%20eight%20/%20within%20two%20working%20hours%29%3A%0AWho%20is%20ordering%20%28company%20name%2C%20VAT%20number%2C%20country%29%3A)

If the site is down right now, send the email anyway: urgent messages are read first.

## Questions

Is restoring a backup enough? Almost never. A backup puts the site back as it was, with the same door open, and often the door has been inside the backup for weeks. Restoring can be one step of the cleanup, not the cleanup. How long does the site stay offline? As long as it takes to clean it and close the way in. Reopening earlier means getting hacked again, and Google takes longer to lift the second warning. Do I have to notify the data protection authority? If the attacker may have read personal data, yes, within 72 hours of finding out. The report says what was touched, which is what the decision rests on. The notification itself is not included.

## From the email to the invoice

Times count in working days. If your mail program does not open, write to the address at the bottom of the page with the same subject line.

- **Right away**pick the engagement and send the pre filled email, with the answers to the questions
- **1 working day**you get an acknowledgement with the missing questions, or the quote with price, deliverables and timing. The quote is valid for fifteen days
- **On your yes**the proforma invoice arrives. Fixed price work is paid half up front and half on completion, the cleanup starts on a deposit, the monthly block is paid before the month
- **On payment**work starts. Access is exchanged only now, on a dedicated account and over an agreed channel, never in the order email
- **When the work ends**report, electronic invoice for the balance, access revoked

## What stays out

- how long Google and providers take to lift a warning or restore an account: the request goes in once the cleanup is done, the answer is theirs
- a cleanup without access to the server, because nothing gets cleaned from the front end alone
- the signed forensic report and the notification to the authority, which are separate engagements

Order from Detector, the client portal: hours come off your prepaid balance and the proforma is issued from there, with no email in between.

[Open Detector](https://detector.prestashops.it/)

## The other engagements

- [Linux server security audit](https://brasile.pro/en/order/linux-server-security-audit/)
- [Monthly Linux server checks](https://brasile.pro/en/order/monthly-linux-server-checks/)
- [Email that gets delivered: SPF, DKIM, DMARC](https://brasile.pro/en/order/spf-dkim-dmarc-email-deliverability/)
- [Website speed and PageSpeed](https://brasile.pro/en/order/website-speed-pagespeed/)
- [Website or VPS migration](https://brasile.pro/en/order/website-shop-vps-migration/)
- [Environmental claims review](https://brasile.pro/en/order/environmental-claims-review/)

[info@brasile.pro](mailto:info@brasile.pro)

## Sources

- [Regulation (EU) 2016/679, GDPR, article 33: breach notification within 72 hours](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
