Immediate measures
A maintenance page instead of tampered content, suspicious accounts locked, new passwords for hosting, database, FTP and admin accounts, with a second factor wherever possible.
In an incident, order matters. Clean up first and investigate later, and you destroy the traces that show how the attacker got in.
A maintenance page instead of tampered content, suspicious accounts locked, new passwords for hosting, database, FTP and admin accounts, with a second factor wherever possible.
A copy of the compromised state, review of server and access logs, and a search for malicious code, hidden admin accounts and scheduled jobs. The aim is to find the way in.
Depending on the findings, we clean the existing installation or rebuild it from a clean backup and fresh sources. Content is checked item by item before being brought across.
Outdated plugins, weak credentials, wrong file permissions or an insecure server configuration are fixed; otherwise the clean-up is merely a pause.
A review request to Google after security warnings, removal of spam pages from the index, delisting requests to blocklists and checks on SPF, DKIM and DMARC.
If personal data may have been affected, such as customer accounts or form submissions, a notification to the Data Protection Authority within 72 hours may be required. We supply the technical facts for it.
A typical sequence, which takes anything from a few hours to several days depending on how severe the incident is.
Once you contact us, we get an overview via remote access and agree the first steps with you. The most important thing is that nobody deletes files in a hurry.
Maintenance mode, accounts locked, current state secured. Where needed we contact the host so suspended services are released again after the clean-up.
Malicious code removed or the site rebuilt, the entry point closed, updates applied, monitoring set up and the site brought back online.
A written report covering cause, actions and recommendations, plus checks on search results and blocklists over the following weeks.
Email is often the second casualty. A compromised host that sends spam ends up on blocklists. For days afterwards, even the everyday emails of the business, quotes and invoices included, land in customer spam folders or never arrive. So alongside the website we check whether the domain and server are listed, request delisting and verify the SPF, DKIM and DMARC records.
A maintenance page is usually sensible so visitors are not exposed to malware or spam. But do not delete files or reinstall the server before the current state has been secured, or it will be impossible to trace how the attack happened.
If personal data may be affected, check with your data protection adviser whether the Data Protection Authority needs to be notified within 72 hours. A report to CERT.at can also be useful. We provide the technical information for both.
Then we clean the existing installation file by file and inspect the database for injected content. It takes longer but is possible in most cases. Afterwards we set up backups so the situation does not repeat itself.
With regular updates, a small number of well maintained extensions, two-factor sign-in, separate accounts and monitoring that reports file changes. All of this is part of our website maintenance service.
Describe what you are seeing and since when. Please do not delete anything until we reply. We will get back to you within one working day.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.