Service · Websites and web apps

Website recovery

By the time this service is needed, things are already bad: a white screen instead of the home page, a red warning in Chrome, hundreds of pages selling fake designer trainers in Google results, or a shop that disappeared together with its hosting account after an unpaid invoice. We get the site working first, then work out what happened and shut the route the problem came in by. Always in that order, with no shortcuts.

First step
stopping the damage
Clean-up
including hidden backdoors
Google warning
review requested in Search Console
Root cause
fixed, not hidden

Included in this service

We always follow one order: contain the damage, bring the site back, eliminate the cause. Skipping any step means a repeat performance a few weeks later.

Talk the scope through with an engineer

Diagnosis

We pin down the actual cause: a break-in, a hosting provider failure, a failed update, an expired domain, a full disk or a suspended account.

Isolation

When a site is spreading malicious code or redirecting visitors, we put it behind a maintenance page returning a 503 code so it stops harming customers and the reputation of your domain.

Cleaning

We compare files against original versions, search the database for injected scripts and look for hidden administrator accounts, suspicious cron jobs and webshell files.

Restoration

From your backup or, if there is none, from snapshots held by the host, cached pages in search engines and the Internet Archive. Much of the content can often be rescued.

Warnings and search results

With the threat removed, we ask Google for a review through Search Console, remove spam URLs from the index and check whether the domain has landed on email blocklists.

Closing the gap

Up-to-date software, fresh credentials everywhere (admin panel, FTP, database, hosting, email), unused accounts removed and a backup that actually works going forward.

How we work together

Timing depends on the scale of the compromise and whether a backup exists. With no backup it drags on, and no honest firm can promise full recovery.

01

Assessment

A review of the site, hosting and logs. We gauge the damage and find out what copies exist.

02

Containment

The site goes into maintenance mode, all credentials are replaced and attacker access is severed.

03

Recovery

A clean installation, restored content and data, tests of forms, payments and login. The site goes back online.

04

Hardening

Current versions, regular off-server backups and file change monitoring. At the end you receive a report describing the incident.

Where an intruder may have reached personal data, the breach must be notified within 72 hours to the President of UODO, the Polish data protection authority. That includes shop customer records, user accounts and form submissions. While we work we log what happened, when, and what data might have leaked. Your DPO or lawyer gets material for the risk assessment and any notification, rather than rebuilding events from memory.

Questions and answers

Usually a good deal, though rarely all of it. Many hosts retain snapshots covering recent days or weeks and release them on request. After that we check search engine caches, the Internet Archive and files on the computers of your editors. Structure and copy can often be recovered; orders from the last few days sometimes cannot.

Common symptoms: visitors on smartphones land on unknown sites, Google lists pages you did not publish, your host suspends the account over spam, or browsers display a warning. Occasionally all you notice is organic traffic falling off a cliff.

Rarely. Attackers are often inside for weeks before anyone notices, so yesterday’s copy already contains their backdoor. Restoring without finding the hole means the whole thing repeats within days.

Once the site is clean and a review has been submitted in Search Console, the decision rests with Google and usually comes within a few days. Should Google detect malicious code a second time, the next review takes longer, which is why we never clean just the surface but hunt down every backdoor.

For most companies reporting through incydent.cert.pl is voluntary, but worth doing, especially if your site was used for phishing. Entities covered by the Polish national cybersecurity system act have their own reporting duties, and we help prepare the technical description of the incident.

Let us get your site back

Describe the problem and when you first noticed it. We reply within one working day, and if you have a contract with us, your plan's response time applies.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.