Immediate containment
The site isolated, an honest holding page for visitors, every password and key changed, active sessions revoked, and a complete copy of the infected state taken before anything is altered.
A site showing a blank page, redirecting visitors to a dubious pharmacy or flagged as dangerous by the browser loses you customers with every passing hour. Take a recruitment agency discovering on a Monday morning that its site has been pointing elsewhere since the weekend, that its mail service is sending junk and that the hosting provider has suspended the account. The urgency is twofold: put the service back online, and work out how the intruder got in so the same thing does not happen a fortnight later.
Putting the site back online is not enough. While the way in stays open, reinfection follows within days and costs twice as much.
The site isolated, an honest holding page for visitors, every password and key changed, active sessions revoked, and a complete copy of the infected state taken before anything is altered.
Server logs, file modification dates, recently created accounts, component versions. An outdated extension, a reused password, an open transfer account, a compromised editor workstation: the answer changes everything that follows.
Injected files, scheduled jobs and added accounts removed, database and configuration files put right, or a backup from before the incident restored where one exists and proves healthy.
Core and components updated, abandoned extensions removed, access hardened, a second factor on administrator accounts and filtering rules placed in front of the site.
A review request to the services flagging the site, a check that email leaves correctly, a sweep for parasitic indexed pages and search monitoring for several weeks.
Where personal data may have been read or taken, a notification to the CNIL and, depending on severity, informing the people concerned may be required. We supply the technical material; the decision is taken with your legal adviser.
Takeover is quick; the duration depends on the scale. A presentation site cleaned and mended is often handled within the day, while a shop compromised for weeks takes longer.
We collect access to the hosting and the site, freeze the current state and decide with you whether to pull the site down or leave it visible.
Traces analysed, the extent of the compromise established, a list of what was altered and an estimate of when entry occurred.
Malicious code removed, service restored, the hole closed and access strengthened.
A written account, recommendations, and backups and monitoring put in place so the episode does not repeat.
Restoring a backup without fixing the cause settles nothing. If the hole sits in an outdated extension or in a password doing the rounds, the site returns to exactly the state in which it was compromised, and the attacker often kept a way back in on purpose. That is why we always keep a copy of the infected state: it serves to understand what happened, and sometimes to document the incident for your insurer or your supervisory authority.
Takeover starts as soon as we hold the credentials. A presentation site is often back online the same day, clean and up to date. A shop with orders in flight needs more care, because data that arrived after the incident has to survive while the injected code is removed.
That is deduced from the available traces: access logs, database queries, exported files. We state what is established, what is likely and what cannot be settled, without rounding in either direction. That account is the basis for deciding whether to notify the CNIL.
Not necessarily. Hosting providers often keep copies going back a few days, and a site can be cleaned in place where the content itself is sound. The work takes longer and the result is less tidy than with a clean backup, but in most cases it succeeds.
Warning lists refresh after a review, which we request once the site is clean. That takes anywhere from hours to days. Asking for the review before cleaning is finished works against you: a second refusal lengthens the wait.
Updates applied without delay, fewer extensions, a second factor on administrator accounts, backups stored elsewhere and tested, and monitoring that tells you before your visitors do. That is exactly what a care agreement contains, and it is the logical sequel to an incident.
Describe what you are seeing and since when. Give us your hosting provider and the technology behind the site so we can begin at once.
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.