Service · Websites and web applications

Website recovery after incidents

When a site has been hacked, the obvious move is to delete whatever looks odd, change the admin password and carry on. It almost never works. Attackers usually leave several back doors, some of them outside the site itself: in the FTP account, the hosting panel or a scheduled task. Within days they are back. Picture an estate agency in Vienna discovering on a Monday that its site redirects visitors to a gambling page, Google lists thousands of pages of Japanese text under its domain and the host has suspended the account for sending spam. The site has to come back fast. Understanding what happened matters just as much, because without that the clean-up only lasts until the next weekend.

First assessment
within one working day of your request
Evidence first
before any clean-up begins
Blocklists
Google, mail filters and hosting providers
Report
cause, actions taken, open points

Everything this covers

In an incident, order matters. Clean up first and investigate later, and you destroy the traces that show how the attacker got in.

Settle the details with an engineer

Immediate measures

A maintenance page instead of tampered content, suspicious accounts locked, new passwords for hosting, database, FTP and admin accounts, with a second factor wherever possible.

Evidence and analysis

A copy of the compromised state, review of server and access logs, and a search for malicious code, hidden admin accounts and scheduled jobs. The aim is to find the way in.

Clean-up or rebuild

Depending on the findings, we clean the existing installation or rebuild it from a clean backup and fresh sources. Content is checked item by item before being brought across.

Close the gap

Outdated plugins, weak credentials, wrong file permissions or an insecure server configuration are fixed; otherwise the clean-up is merely a pause.

Restore your reputation

A review request to Google after security warnings, removal of spam pages from the index, delisting requests to blocklists and checks on SPF, DKIM and DMARC.

Clarify reporting duties

If personal data may have been affected, such as customer accounts or form submissions, a notification to the Data Protection Authority within 72 hours may be required. We supply the technical facts for it.

Our working method

A typical sequence, which takes anything from a few hours to several days depending on how severe the incident is.

01

Assess the situation

Once you contact us, we get an overview via remote access and agree the first steps with you. The most important thing is that nobody deletes files in a hurry.

02

Contain and preserve

Maintenance mode, accounts locked, current state secured. Where needed we contact the host so suspended services are released again after the clean-up.

03

Clean and harden

Malicious code removed or the site rebuilt, the entry point closed, updates applied, monitoring set up and the site brought back online.

04

Follow-up

A written report covering cause, actions and recommendations, plus checks on search results and blocklists over the following weeks.

Email is often the second casualty. A compromised host that sends spam ends up on blocklists. For days afterwards, even the everyday emails of the business, quotes and invoices included, land in customer spam folders or never arrive. So alongside the website we check whether the domain and server are listed, request delisting and verify the SPF, DKIM and DMARC records.

Frequently asked questions

A maintenance page is usually sensible so visitors are not exposed to malware or spam. But do not delete files or reinstall the server before the current state has been secured, or it will be impossible to trace how the attack happened.

If personal data may be affected, check with your data protection adviser whether the Data Protection Authority needs to be notified within 72 hours. A report to CERT.at can also be useful. We provide the technical information for both.

Then we clean the existing installation file by file and inspect the database for injected content. It takes longer but is possible in most cases. Afterwards we set up backups so the situation does not repeat itself.

With regular updates, a small number of well maintained extensions, two-factor sign-in, separate accounts and monitoring that reports file changes. All of this is part of our website maintenance service.

Has your website been attacked?

Describe what you are seeing and since when. Please do not delete anything until we reply. We will get back to you within one working day.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.