Service · Websites and web applications

Website recovery after an attack

A compromised site does not always announce itself. Picture a hypothetical food exporter in Gaziantep. The site loads normally, until a customer abroad writes to say that googling the company's name brings up illegal betting and casino pages. The attacker has planted thousands of hidden pages inside the site and shows them only to search engine crawlers. At the same time the server has begun sending spam, so some quotations to customers are landing in junk folders. Deleting the visible files will not fix this. A clean-up that ignores how the attacker got in usually unravels within days. Recovery runs in a fixed order: understand what happened, shut the door, then rebuild reputation.

Snapshot first
a full copy kept as evidence before cleaning
Entry point
no clean-up is finished until it is found
Warnings lifted
review requests to Google and browsers
KVKK check
notification steps if personal data was hit

What the work covers in practice

The scope varies with the type of attack, but every recovery includes the following.

Agree the scope with the engineer who will do the work

Emergency response

If needed the site goes into maintenance mode, every admin, hosting, FTP and database password is changed and active sessions are ended. A complete snapshot of the site is taken before any cleaning.

Diagnosis and root cause

Files are compared with a clean version, the database is searched for hidden links and redirects, and server logs are examined. The aim is to find which plugin, weak password or flaw let the attacker in.

Clean-up or clean rebuild

Malicious code and backdoors are removed. Where damage is widespread, core, theme and plugins are reinstalled from trusted sources, and only content and verified clean files are brought back.

Search engine and browser warnings

Review requests are filed for security issues in Google Search Console, removal requests are made for spam pages, and blocklist entries are checked.

Email and domain

Spam sending from the server is stopped, SPF, DKIM and DMARC records are corrected, and steps to repair sender reputation are planned if needed.

Hardening

Unused plugins and accounts are removed, two-step sign-in becomes mandatory, file write permissions are tightened and, where useful, a web application firewall is added.

How we approach the job, from first call to handover

A typical recovery takes from a few hours to a few days depending on severity. Search engine warnings may need several more days to clear.

01

First contact and access

On a video call we hear what you have observed and receive hosting and admin access through a secure channel. The first urgent steps are taken as soon as possible.

02

Analysis

We establish the scope of the attack and the entry point, and answer a key question: could personal data such as customer records or form submissions have been exposed?

03

Clean and relaunch

The site is cleaned or rebuilt, hardened, tested and brought back online. Search engine and blocklist procedures are started.

04

Report and watch

You receive a written report on what happened, how the attacker got in, what was done and what we recommend to prevent a repeat. In the following weeks the site is watched closely for new signs.

When personal data is affected, a deadline starts running that matters as much as the technical clean-up. Under KVKK, the data controller must notify the Board within 72 hours of learning of a breach, and informing affected individuals may also be required. On a site holding form submissions, member accounts or order data, data access is therefore one of the first questions in our analysis. Your adviser makes the legal assessment; we supply the technical findings for the notification quickly and in writing.

Frequently asked questions

Sometimes, on two conditions: the backup must be from before the compromise, and the entry point must be closed. Otherwise the restored site is taken over again the same way. Orders or content added after the backup may also be lost.

Hosting providers can suspend accounts when they detect malicious content or spam. We first contact the provider to get access to files and database. Once cleaning is complete, we send them an explanation of the work done so the account can be reinstated.

Usually not. Most of these attacks are automated and untargeted, and the real source cannot be traced. Our focus is finding and closing the way in. If you want to pursue legal action, we hand over all logs and findings.

The report lists recommendations specific to your site. Generally, few plugins, current software, two-step sign-in, off-site backups and regular maintenance provide solid protection. We can also take on ongoing care of the site if you wish.

What is happening to your site?

Briefly describe what you have noticed, the site address and the system it runs on. Urgent cases are handled with priority and we respond as quickly as we can.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.