SUPPORT
Something is on your site that you didn’t put there.
Redirects to somewhere else, pages you’ve never seen, a browser warning or a message from your host. We clean it up, then find how they got in.
Don’t delete anything yet. What’s on the server right now includes how they got in, and that matters more than the cleanup.
What it usually looks like from outside.
What it usually looks like from outside.
Visitors get redirected somewhere else
Often only on mobile, only from search results, or only for people who aren’t logged in.
Pages you never created
Usually spam in a language you don’t sell in, indexed and sitting in Google under your domain.
Your host suspended the account
Usually for sending spam or eating resources. Your site was being used to attack someone else.
Search results look wrong
Titles and descriptions in Google that aren’t yours.
Admin users you don’t recognize
Check the user list. New administrators nobody created is a clear sign.
Straight talk about website security.
Almost nobody is targeted personally
Nearly every compromise is automated. Software scans the internet for a specific vulnerable plugin version, finds yours, and exploits it with no human involved. Your business isn’t interesting to them. Your server is.
Cleanup without finding the cause is a subscription
Plenty of services will remove the malware. Fewer will tell you how it got in, because that takes longer and sometimes means saying something uncomfortable about a plugin, a password or a hosting arrangement.
What to expect
- We preserve the evidence first
- We work out how far it spread
- We find the way in
It depends on how far it spread, how long it was there, whether the hosting account is involved and whether there’s a clean backup.
Security questions.
Security questions.
Can we just restore a backup?
Sometimes. Two catches: you need a backup from before the compromise, which is usually further back than people think, and restoring puts back whatever let them in.
How did they get in?
Most often a known vulnerability in an out-of-date plugin, theme or module. After that: weak or reused passwords, an exposed admin area, a compromised computer in your own office, or another site sharing the same hosting account.
How long does a cleanup take?
A straightforward one doesn’t take long. A site that’s been compromised for months, or where the hosting account is involved, takes longer.
Patching on a schedule is the real prevention.
Web HostingWhen the hosting account itself is part of it.
How Websites Actually Get HackedThe real entry points, in order of how often we see them.
Patching on a schedule is the real prevention.
Web HostingWhen the hosting account itself is part of it.
How Websites Actually Get HackedThe real entry points, in order of how often we see them.
Cleanup is the emergency. Website Care is what stops the next one, and if a site under our care is ever hacked, putting it right is included.
$199 per month
Hosting included. Kept updated. Watched and backed up.
Not what you need? See all three ways we work
Not what you need? See all three ways we work
Think you’ve been hacked?
Tell us what you’re seeing and who spotted it first: a visitor, Google, or your host. That alone narrows it down.
Rather talk it through? Call 833-336-6453.