Service · Websites and web apps

Website recovery

A site showing a blank page, redirecting visitors to a dubious pharmacy or flagged as dangerous by the browser loses you customers with every passing hour. Take a recruitment agency discovering on a Monday morning that its site has been pointing elsewhere since the weekend, that its mail service is sending junk and that the hosting provider has suspended the account. The urgency is twofold: put the service back online, and work out how the intruder got in so the same thing does not happen a fortnight later.

Diagnosis
started as soon as we take over
Cleaning
files, database and accounts
Cause
identified and then closed
GDPR
obligations examined with you

Where this service reaches

Putting the site back online is not enough. While the way in stays open, reinfection follows within days and costs twice as much.

Put your scope to an engineer

Immediate containment

The site isolated, an honest holding page for visitors, every password and key changed, active sessions revoked, and a complete copy of the infected state taken before anything is altered.

Finding the cause

Server logs, file modification dates, recently created accounts, component versions. An outdated extension, a reused password, an open transfer account, a compromised editor workstation: the answer changes everything that follows.

Cleaning and restoring

Injected files, scheduled jobs and added accounts removed, database and configuration files put right, or a backup from before the incident restored where one exists and proves healthy.

Closing the hole

Core and components updated, abandoned extensions removed, access hardened, a second factor on administrator accounts and filtering rules placed in front of the site.

Back to normal

A review request to the services flagging the site, a check that email leaves correctly, a sweep for parasitic indexed pages and search monitoring for several weeks.

The regulatory side

Where personal data may have been read or taken, a notification to the CNIL and, depending on severity, informing the people concerned may be required. We supply the technical material; the decision is taken with your legal adviser.

The way an engagement runs

Takeover is quick; the duration depends on the scale. A presentation site cleaned and mended is often handled within the day, while a shop compromised for weeks takes longer.

01

Takeover

We collect access to the hosting and the site, freeze the current state and decide with you whether to pull the site down or leave it visible.

02

Diagnosis

Traces analysed, the extent of the compromise established, a list of what was altered and an estimate of when entry occurred.

03

Cleaning and repair

Malicious code removed, service restored, the hole closed and access strengthened.

04

After the incident

A written account, recommendations, and backups and monitoring put in place so the episode does not repeat.

Restoring a backup without fixing the cause settles nothing. If the hole sits in an outdated extension or in a password doing the rounds, the site returns to exactly the state in which it was compromised, and the attacker often kept a way back in on purpose. That is why we always keep a copy of the infected state: it serves to understand what happened, and sometimes to document the incident for your insurer or your supervisory authority.

Questions and answers

Takeover starts as soon as we hold the credentials. A presentation site is often back online the same day, clean and up to date. A shop with orders in flight needs more care, because data that arrived after the incident has to survive while the injected code is removed.

That is deduced from the available traces: access logs, database queries, exported files. We state what is established, what is likely and what cannot be settled, without rounding in either direction. That account is the basis for deciding whether to notify the CNIL.

Not necessarily. Hosting providers often keep copies going back a few days, and a site can be cleaned in place where the content itself is sound. The work takes longer and the result is less tidy than with a clean backup, but in most cases it succeeds.

Warning lists refresh after a review, which we request once the site is clean. That takes anywhere from hours to days. Asking for the review before cleaning is finished works against you: a second refusal lengthens the wait.

Updates applied without delay, fewer extensions, a second factor on administrator accounts, backups stored elsewhere and tested, and monitoring that tells you before your visitors do. That is exactly what a care agreement contains, and it is the logical sequel to an incident.

Your site is down or hacked

Describe what you are seeing and since when. Give us your hosting provider and the technology behind the site so we can begin at once.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.