Triage
We call you back, understand what you’re seeing and agree secure access. Never send passwords by email.
Emergency response · incident line open
Call us or start emergency triage. We contain the attack, find the first point of infection, remove the malware and get you back online, with evidence of everything we did.
Prefer a callback? and we’ll call you straight back.
Quick answer
If your website has been hacked, don’t delete anything yet. Change your hosting and admin passwords from a clean device, take a backup snapshot of the infected state for forensics, and write down what you saw. Then call us, and we’ll contain it and find how they got in.
It’s tempting, but deleting infected files destroys the evidence that shows how the attacker got in. Leave them for now: evidence helps us find patient zero.
Hosting control panel, WordPress admins, database, FTP/SFTP and SSH. Use a device you trust, not the one you use to manage the site if it may be compromised.
Snapshot the server or download a full copy of files and database in its current state. It is useful for forensics and a safety net before clean-up starts.
Times, URLs, screenshots, redirects, emails from your host or Google, and anything you have already tried. It speeds up triage.
What happens next
Every emergency follows the same forensic process, so nothing is missed.
We call you back, understand what you’re seeing and agree secure access. Never send passwords by email.
We stop the bleeding: block active redirects and shells, pause what’s harmful and preserve evidence.
Forensic scan to find patient zero, then removal of every backdoor, rogue admin and injected file, across every site.
Close the way in, verify every site is clean and online, and hand you a plain-English report.
What we need from you
How you’re covered
New accounts start with the one-off £129.99 security audit and setup. From then on, your plan covers unlimited malware removal, including any re-infection, from £99/month.
Emergency triage
Our team is alerted the moment you submit. Prefer to talk? Call 01932 593642.
We start triage as soon as you get in touch. Call 01932 593642 or request a callback and our incident team is alerted immediately.
No. Every plan includes emergency clean-ups. New accounts start with the one-off £129.99 security audit and setup, then the clean-up is covered by your plan, and so is any re-infection.
SSH access gives the most thorough clean-up because persistent malware often hides outside WordPress. If you only have a hosting control panel or SFTP, we can still start and help you get the right access.
If the site is redirecting visitors, serving malware or taking card payments, putting it into maintenance mode or pausing payments limits harm. Don't delete anything. We'll advise on the call.
It can be. If personal data may have been accessed, UK GDPR may require you to report it to the ICO within 72 hours of becoming aware. Our forensic report gives you the evidence to decide.
Guides
Your site has just been hacked. This is the calm, practical plan for the first hour: what to do, in what order, and what not to touch.
From redirects and Google warnings to unknown admin accounts and rogue cron jobs, these are the 12 signs we see most often on hacked websites, and how to check for each.
Not every website hack is a reportable breach, but many are. How to decide, what the ICO 72-hour clock means, and the forensic evidence you need to make the call.