Emergency response
Hacked or under attack? Talk to us now.
Tell us what you are seeing. We contain the damage, find how they got in, clean your site and make sure it cannot happen the same way again.
Calling is fastest. Prefer to write? Use the form and we will contact you as quickly as we can.
Recognise the signs
How to tell your website has been hacked.
Any one of these is a reason to get in touch. Many hacks stay hidden for weeks.
It redirects visitors
Your site sends people to another website, often casinos, pharmacy or scam pages.
Google or the browser warns
“Deceptive site ahead” or “This site may be hacked” appears in search or the browser.
Pages or text you did not write
Spam pages, hidden links or a defaced homepage you did not create.
You are locked out
Your password stopped working, or admin accounts appeared that you do not recognise.
Malware or odd files
Your host or a scanner flagged malicious code, or files appeared that you cannot explain.
The site is down or suspended
Your host took the site offline, or it is suddenly very slow or showing errors.
Strange search results
Your site shows foreign-language titles or product spam in Google.
Visitors complain
Customers report pop-ups, odd emails from your domain or being sent somewhere else.
While you wait
What to do right now.
Five steps that protect your data and make the cleanup faster.
- 1
Do not delete anything
Files and logs show how the attacker got in. Deleting them makes cleaning harder.
- 2
Change passwords from a clean device
Hosting, website admin, email and FTP or SSH. Use a computer you trust, not the one you think is infected.
- 3
Tell your hosting provider
Ask them to keep their logs and to tell you if other sites on your account are affected.
- 4
Take the site offline if people are at risk
Maintenance mode protects customers while the site is dirty, especially if you take payments or logins.
- 5
Do not pay a ransom or reply to the attacker
Payment does not guarantee anything. Contact us first.
How we help
What we do when your site is hacked.
From the first call to a tested, hardened and monitored site.
Malware scan and cleanup
We find and remove malicious code, backdoors, rogue admin accounts and spam pages, across files and the database.
Incident response
We contain the attack, preserve evidence and work out how the attacker got in, so the same hole is closed.
Restore and recovery
We rebuild from a clean backup where one exists, restore your data and bring the site back online safely.
Warning and blacklist removal
After cleanup we request reviews from Google and other lists so the warnings come off your site.
VAPT testing
Vulnerability Assessment and Penetration Testing after the cleanup, to prove the holes are closed and find any that remain.
Hardening and monitoring
Patching, firewall, two-factor logins, backups and uptime monitoring, through a Care Plan so it stays fixed.
Our process
Six steps from attack to protected.
- 01
Contain
Stop the attack from spreading and protect your visitors, your data and your customers.
- 02
Investigate
Find the entry point and what the attacker changed, using logs, file comparisons and scans.
- 03
Clean
Remove malware, backdoors and rogue accounts. Replace infected core files from trusted sources.
- 04
Restore and harden
Bring the site back, then patch, lock down access and add a firewall.
- 05
Test with VAPT
Scan and manually test the site to confirm the weakness is gone and nothing else is exposed.
- 06
Monitor and report
Get a plain-English report of what happened, what we fixed and how to prevent a repeat.
VAPT: Vulnerability Assessment and Penetration Testing
Prove it is fixed. Or find the weak spots before an attacker does.
After a cleanup, VAPT shows that the entry point is closed and nothing else is exposed. It is also worth doing before you are attacked, for sites that take payments, logins or personal data. Our founder specialises in penetration testing.
- 01
Scan
Automated checks for known vulnerabilities, outdated software and misconfigurations.
- 02
Manual testing
Hands-on attempts to break in, the way a real attacker would, including logins, forms and APIs.
- 03
Report
Each finding rated by severity, with evidence and a clear fix, in plain English.
- 04
Fix and retest
We fix what we can, then test again to confirm every issue is closed.
Questions
What people ask when they have been hacked.
In most cases, yes. A clean backup makes it fastest. Without one we can usually clean the existing files. We will tell you honestly what we find after the first look.
Not hacked, just worried? Try our free security and speed check.

Let's build something that lasts.
Tell us about your business. You'll get a written quote with a fixed price within one working day.

