Skip to content
Webcrab

Emergency response

Hacked or under attack? Talk to us now.

Tell us what you are seeing. We contain the damage, find how they got in, clean your site and make sure it cannot happen the same way again.

Calling is fastest. Prefer to write? Use the form and we will contact you as quickly as we can.

Get emergency help

Tell us what you see. A phone number is enough, so we can call you back.

Do not include passwords in this form. We will ask for access through a secure channel.

We reply within 1 working day.

Recognise the signs

How to tell your website has been hacked.

Any one of these is a reason to get in touch. Many hacks stay hidden for weeks.

  • It redirects visitors

    Your site sends people to another website, often casinos, pharmacy or scam pages.

  • Google or the browser warns

    “Deceptive site ahead” or “This site may be hacked” appears in search or the browser.

  • Pages or text you did not write

    Spam pages, hidden links or a defaced homepage you did not create.

  • You are locked out

    Your password stopped working, or admin accounts appeared that you do not recognise.

  • Malware or odd files

    Your host or a scanner flagged malicious code, or files appeared that you cannot explain.

  • The site is down or suspended

    Your host took the site offline, or it is suddenly very slow or showing errors.

  • Strange search results

    Your site shows foreign-language titles or product spam in Google.

  • Visitors complain

    Customers report pop-ups, odd emails from your domain or being sent somewhere else.

While you wait

What to do right now.

Five steps that protect your data and make the cleanup faster.

  1. 1

    Do not delete anything

    Files and logs show how the attacker got in. Deleting them makes cleaning harder.

  2. 2

    Change passwords from a clean device

    Hosting, website admin, email and FTP or SSH. Use a computer you trust, not the one you think is infected.

  3. 3

    Tell your hosting provider

    Ask them to keep their logs and to tell you if other sites on your account are affected.

  4. 4

    Take the site offline if people are at risk

    Maintenance mode protects customers while the site is dirty, especially if you take payments or logins.

  5. 5

    Do not pay a ransom or reply to the attacker

    Payment does not guarantee anything. Contact us first.

How we help

What we do when your site is hacked.

From the first call to a tested, hardened and monitored site.

Malware scan and cleanup

We find and remove malicious code, backdoors, rogue admin accounts and spam pages, across files and the database.

Incident response

We contain the attack, preserve evidence and work out how the attacker got in, so the same hole is closed.

Restore and recovery

We rebuild from a clean backup where one exists, restore your data and bring the site back online safely.

Warning and blacklist removal

After cleanup we request reviews from Google and other lists so the warnings come off your site.

After cleanup

VAPT testing

Vulnerability Assessment and Penetration Testing after the cleanup, to prove the holes are closed and find any that remain.

Hardening and monitoring

Patching, firewall, two-factor logins, backups and uptime monitoring, through a Care Plan so it stays fixed.

Our process

Six steps from attack to protected.

  1. 01

    Contain

    Stop the attack from spreading and protect your visitors, your data and your customers.

  2. 02

    Investigate

    Find the entry point and what the attacker changed, using logs, file comparisons and scans.

  3. 03

    Clean

    Remove malware, backdoors and rogue accounts. Replace infected core files from trusted sources.

  4. 04

    Restore and harden

    Bring the site back, then patch, lock down access and add a firewall.

  5. 05

    Test with VAPT

    Scan and manually test the site to confirm the weakness is gone and nothing else is exposed.

  6. 06

    Monitor and report

    Get a plain-English report of what happened, what we fixed and how to prevent a repeat.

VAPT: Vulnerability Assessment and Penetration Testing

Prove it is fixed. Or find the weak spots before an attacker does.

After a cleanup, VAPT shows that the entry point is closed and nothing else is exposed. It is also worth doing before you are attacked, for sites that take payments, logins or personal data. Our founder specialises in penetration testing.

  1. 01

    Scan

    Automated checks for known vulnerabilities, outdated software and misconfigurations.

  2. 02

    Manual testing

    Hands-on attempts to break in, the way a real attacker would, including logins, forms and APIs.

  3. 03

    Report

    Each finding rated by severity, with evidence and a clear fix, in plain English.

  4. 04

    Fix and retest

    We fix what we can, then test again to confirm every issue is closed.

Questions

What people ask when they have been hacked.

In most cases, yes. A clean backup makes it fastest. Without one we can usually clean the existing files. We will tell you honestly what we find after the first look.

Not hacked, just worried? Try our free security and speed check.

Let's build something that lasts.

Tell us about your business. You'll get a written quote with a fixed price within one working day.

Get a quote