Emergency response
If needed the site goes into maintenance mode, every admin, hosting, FTP and database password is changed and active sessions are ended. A complete snapshot of the site is taken before any cleaning.
A compromised site does not always announce itself. Picture a hypothetical food exporter in Gaziantep. The site loads normally, until a customer abroad writes to say that googling the company's name brings up illegal betting and casino pages. The attacker has planted thousands of hidden pages inside the site and shows them only to search engine crawlers. At the same time the server has begun sending spam, so some quotations to customers are landing in junk folders. Deleting the visible files will not fix this. A clean-up that ignores how the attacker got in usually unravels within days. Recovery runs in a fixed order: understand what happened, shut the door, then rebuild reputation.
The scope varies with the type of attack, but every recovery includes the following.
If needed the site goes into maintenance mode, every admin, hosting, FTP and database password is changed and active sessions are ended. A complete snapshot of the site is taken before any cleaning.
Files are compared with a clean version, the database is searched for hidden links and redirects, and server logs are examined. The aim is to find which plugin, weak password or flaw let the attacker in.
Malicious code and backdoors are removed. Where damage is widespread, core, theme and plugins are reinstalled from trusted sources, and only content and verified clean files are brought back.
Review requests are filed for security issues in Google Search Console, removal requests are made for spam pages, and blocklist entries are checked.
Spam sending from the server is stopped, SPF, DKIM and DMARC records are corrected, and steps to repair sender reputation are planned if needed.
Unused plugins and accounts are removed, two-step sign-in becomes mandatory, file write permissions are tightened and, where useful, a web application firewall is added.
A typical recovery takes from a few hours to a few days depending on severity. Search engine warnings may need several more days to clear.
On a video call we hear what you have observed and receive hosting and admin access through a secure channel. The first urgent steps are taken as soon as possible.
We establish the scope of the attack and the entry point, and answer a key question: could personal data such as customer records or form submissions have been exposed?
The site is cleaned or rebuilt, hardened, tested and brought back online. Search engine and blocklist procedures are started.
You receive a written report on what happened, how the attacker got in, what was done and what we recommend to prevent a repeat. In the following weeks the site is watched closely for new signs.
When personal data is affected, a deadline starts running that matters as much as the technical clean-up. Under KVKK, the data controller must notify the Board within 72 hours of learning of a breach, and informing affected individuals may also be required. On a site holding form submissions, member accounts or order data, data access is therefore one of the first questions in our analysis. Your adviser makes the legal assessment; we supply the technical findings for the notification quickly and in writing.
Sometimes, on two conditions: the backup must be from before the compromise, and the entry point must be closed. Otherwise the restored site is taken over again the same way. Orders or content added after the backup may also be lost.
Hosting providers can suspend accounts when they detect malicious content or spam. We first contact the provider to get access to files and database. Once cleaning is complete, we send them an explanation of the work done so the account can be reinstated.
Usually not. Most of these attacks are automated and untargeted, and the real source cannot be traced. Our focus is finding and closing the way in. If you want to pursue legal action, we hand over all logs and findings.
The report lists recommendations specific to your site. Generally, few plugins, current software, two-step sign-in, off-site backups and regular maintenance provide solid protection. We can also take on ongoing care of the site if you wish.
Briefly describe what you have noticed, the site address and the system it runs on. Urgent cases are handled with priority and we respond as quickly as we can.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.