Oogle

SUPPORT

Something is on your site that you didn’t put there.

Redirects to somewhere else, pages you’ve never seen, a browser warning or a message from your host. We clean it up, then find how they got in.

IF YOU THINK YOU'VE BEEN HACKED

Don’t delete anything yet. What’s on the server right now includes how they got in, and that matters more than the cleanup.

What it usually looks like from outside.

What it usually looks like from outside.

Visitors get redirected somewhere else

Often only on mobile, only from search results, or only for people who aren’t logged in.

Pages you never created

Usually spam in a language you don’t sell in, indexed and sitting in Google under your domain.

Your host suspended the account

Usually for sending spam or eating resources. Your site was being used to attack someone else.

Search results look wrong

Titles and descriptions in Google that aren’t yours.

Admin users you don’t recognize

Check the user list. New administrators nobody created is a clear sign.

Straight talk about website security.

Almost nobody is targeted personally

Nearly every compromise is automated. Software scans the internet for a specific vulnerable plugin version, finds yours, and exploits it with no human involved. Your business isn’t interesting to them. Your server is.

Cleanup without finding the cause is a subscription

Plenty of services will remove the malware. Fewer will tell you how it got in, because that takes longer and sometimes means saying something uncomfortable about a plugin, a password or a hosting arrangement.

What to expect

  1. We preserve the evidence first
  2. We work out how far it spread
  3. We find the way in

It depends on how far it spread, how long it was there, whether the hosting account is involved and whether there’s a clean backup.

How we bill

Security questions.

Security questions.

Can we just restore a backup?

Sometimes. Two catches: you need a backup from before the compromise, which is usually further back than people think, and restoring puts back whatever let them in.

How did they get in?

Most often a known vulnerability in an out-of-date plugin, theme or module. After that: weak or reused passwords, an exposed admin area, a compromised computer in your own office, or another site sharing the same hosting account.

How long does a cleanup take?

A straightforward one doesn’t take long. A site that’s been compromised for months, or where the hosting account is involved, takes longer.

Website Care

Cleanup is the emergency. Website Care is what stops the next one, and if a site under our care is ever hacked, putting it right is included.

$199 per month

Hosting included. Kept updated. Watched and backed up.

Not what you need? See all three ways we work

Not what you need? See all three ways we work

Think you’ve been hacked?

Tell us what you’re seeing and who spotted it first: a visitor, Google, or your host. That alone narrows it down.

Rather talk it through? Call 833-336-6453.