Diagnostics
What actually happened: a break-in, a hardware failure, a bad update, an overdue payment.
The sequence never changes: stop the damage, restore service, remove the cause. Skipping steps is not allowed.
What actually happened: a break-in, a hardware failure, a bad update, an overdue payment.
We close the site to visitors if it is distributing malware or diverting people to other resources.
We find and remove injections in the files and the database, and separately check for backdoors left for re-entry.
From backups, and if there are none, from search engine caches and archives, as far as that goes.
We submit the re-check request only once the threat has genuinely been removed.
Updates, changing every password without exception, closing the admin area, setting up backups for the future.
An ordinary break-in is dealt with in one to three days. Without backups the work takes longer and nobody promises completeness.
We look at the site and the hosting and establish the scale and whether backups exist. It takes a few hours.
We take it offline for visitors, reissue every password and shut down the malicious activity.
We restore the content and bring the site back to working order.
Current versions, regular backups, monitoring. So it does not happen again in a month.
A copy sitting on the same server as the site is not a backup. In a breach it is deleted along with everything else; on a disk failure it disappears at the same moment as the original. A backup must be stored elsewhere, otherwise recovery means digging through a search engine cache.
The first thing we check is the hosting platform: providers often keep their own copies of the last day or two, and the client has no idea. Next come search engine caches and web archives. Usually the structure and the texts come back, but not everything.
The signs are these: some visitors are diverted to other sites, pages you never created have appeared, the host complains about spam being sent, the browser shows a warning. Sometimes the only symptom is a sharp drop in rankings.
Once the threat is removed and a re-check requested, it is usually lifted within a few days. It drags on if the infection is found again during the check, so the clean-up must be thorough rather than superficial.
Tell us what happened and since when. We inspect the same day, and if the site is fully down we start immediately.
Request received
It is already with a manager. You will get an answer within the working day, and urgent requests go to the duty engineer immediately.
There is no such city in the list. Check the spelling.