Under attack right now? We’ll call you straight back. Hacked?

01932 593642

Emergency response · incident line open

Hacked? We’ll start now.

Call us or start emergency triage. We contain the attack, find the first point of infection, remove the malware and get you back online, with evidence of everything we did.

Prefer a callback? and we’ll call you straight back.

Quick answer

What to do in the next 10 minutes.

If your website has been hacked, don’t delete anything yet. Change your hosting and admin passwords from a clean device, take a backup snapshot of the infected state for forensics, and write down what you saw. Then call us, and we’ll contain it and find how they got in.

  1. Don’t delete files yet.

    It’s tempting, but deleting infected files destroys the evidence that shows how the attacker got in. Leave them for now: evidence helps us find patient zero.

  2. Change passwords from a clean device.

    Hosting control panel, WordPress admins, database, FTP/SFTP and SSH. Use a device you trust, not the one you use to manage the site if it may be compromised.

  3. Take a backup snapshot.

    Snapshot the server or download a full copy of files and database in its current state. It is useful for forensics and a safety net before clean-up starts.

  4. Note what you saw.

    Times, URLs, screenshots, redirects, emails from your host or Google, and anything you have already tried. It speeds up triage.

What happens next

From first call to locked down.

Every emergency follows the same forensic process, so nothing is missed.

Triage

We call you back, understand what you’re seeing and agree secure access. Never send passwords by email.

Contain

We stop the bleeding: block active redirects and shells, pause what’s harmful and preserve evidence.

Investigate and clean

Forensic scan to find patient zero, then removal of every backdoor, rogue admin and injected file, across every site.

Harden and verify

Close the way in, verify every site is clean and online, and hand you a plain-English report.

What we need from you

Access, and a few details.

  • SSH access gives the most thorough clean-up. Control panel or SFTP works to start.
  • The affected site(s) and anything else on the same server.
  • When you first noticed, and what you’ve tried.
  • We’ll arrange access securely. How we handle access.

How you’re covered

Every plan includes emergency clean-ups.

New accounts start with the one-off £129.99 security audit and setup. From then on, your plan covers unlimited malware removal, including any re-infection, from £99/month.

Emergency triage

Tell us what’s happening.

Our team is alerted the moment you submit. Prefer to talk? Call 01932 593642.

Step 1 of 5

What’s happening?

What’s happening?
What are you seeing?What matters most to you?

Tick everything that applies

When did you notice?

Is the site offline?

Payments or customer data?

Choose your priorities

Your stack

Platform

Hosting

Access you can provide SSH access lets our scan engine inspect the whole server: cron jobs, system users and every site. That’s where persistent malware hides, and why it gives the most thorough clean-up.

Number of sites

Servers

Existing security

Quick risk check

Five quick questions. Honest answers get you an honest plan.

  • Recent off-server backup (last 7 days)?

    Without a clean off-server copy, recovery takes longer and evidence can be lost.

  • WordPress core, plugins and themes updated in the last month?

    Outdated plugins are the most common way in.

  • 2FA on admin accounts?

    Stolen or guessed passwords stop working when 2FA is on.

  • Any nulled / pirated plugins or themes?

    No judgement: it is a very common source of infection.

  • Shared hosting with other sites on the same account?

    One infected site can reach every other site on the account.

Your details and next step

Preferred next step

Never send passwords here. We’ll arrange secure access with you.

FAQs

Emergency questions

Straight answers. If yours isn’t here, call 01932 593642.

How quickly can you start?

We start triage as soon as you get in touch. Call 01932 593642 or request a callback and our incident team is alerted immediately.

Do I need to be a customer already?

No. Every plan includes emergency clean-ups. New accounts start with the one-off £129.99 security audit and setup, then the clean-up is covered by your plan, and so is any re-infection.

What access do you need?

SSH access gives the most thorough clean-up because persistent malware often hides outside WordPress. If you only have a hosting control panel or SFTP, we can still start and help you get the right access.

Should I take the site offline?

If the site is redirecting visitors, serving malware or taking card payments, putting it into maintenance mode or pausing payments limits harm. Don't delete anything. We'll advise on the call.

Is a hacked website a data breach?

It can be. If personal data may have been accessed, UK GDPR may require you to report it to the ICO within 72 hours of becoming aware. Our forensic report gives you the evidence to decide.

Guides

If you’re waiting for our call

Hacked sites9 min read

12 Signs Your Website Has Been Hacked

From redirects and Google warnings to unknown admin accounts and rogue cron jobs, these are the 12 signs we see most often on hacked websites, and how to check for each.

Get protected

Incident line

Under attack? We’ll call you straight back.

Leave three details and our incident team is alerted immediately. Or call now on 01932 593642.

Never send passwords here. We’ll arrange secure access with you.