Hacked site? Fixed for a flat €290
Cleanup, patching and hardening, usually within 48 hours — then ongoing website care so it doesn't happen twice. For sites we built and sites we've never seen.
How to tell your site is hacked — and what happens next?
When a website gets hacked, the typical signs are: the site redirects somewhere foreign, Google shows a "this site may be hacked" warning, strange pages appear in search results, your host emails about malware — or the site just gets inexplicably slow. Sometimes nothing shows at all: your server quietly sends spam, and you find out when your own emails stop arriving.
Rule one: don't delete anything and don't restore a backup yet. The traces show how they got in — without them you patch a symptom, not the hole, and they're back within a week. Email us; we take a full copy and start from there. Tell your host too — they can stop the attack and preserve logs; we talk to Zone and Veebimajutus for you where needed.
After cleanup comes the part that matters most: hole closed, passwords rotated, updates applied, backups running. That's why rescue and website care go hand in hand here — a maintained site doesn't end up on this page twice. For serious incidents (extortion, data theft) we also recommend notifying CERT-EE, Estonia's national cyber security center.
From infected to hardened
- ✓Full malware and virus cleanup — backdoors and rogue admin users included
- ✓The actual hole patched, not just symptoms wiped
- ✓Core, plugins and themes updated; ALL passwords rotated: admins, FTP/SSH, database, hosting account
- ✓Google "this site may be hacked" warnings cleared
- ✓Backups set up so the next incident is a restore, not a crisis
- ✓A plain-language report of what happened and what changed
Four steps, no drama
Email us before touching anything — we take a full copy first so the evidence survives.
Malware, backdoors and spam pages removed on a copy, then swapped in.
Updates, strong access with two-factor login, firewall rules — the hole that let them in gets closed.
From €49/mo we keep it patched, backed up and monitored, so this stays a one-time story.
Rescue & website care pricing
Rescue is a fixed €290 — not "from", but the actual price, however ugly things turn out to be. Ongoing website care from €49/mo keeps the site updated, backed up and watched.
Rescue
One infected site cleaned, patched, hardened and reported. Usually done within 48 hours.
Website care
Updates, offsite backups, uptime monitoring and small fixes — for any site, not just ones we built.
Smaller tasks billed hourly at €70–110 · prices excl. VAT.
Asked in every rescue
Don't delete anything and don't restore a backup over the evidence yet. Email us — we take a copy, find how they got in, and clean from there. Deleting first often destroys the trail and makes the fix slower.
Boring ways: outdated plugins, weak or reused passwords, abandoned admin accounts, pirated themes. Almost never a movie-style targeted attack — good news, because boring holes close cheaply.
Every month: WordPress core, plugin and theme updates, offsite backups, uptime monitoring and small fixes. A short quarterly note on what was done. From €49/mo, excl. VAT.
If it's infecting visitors or leaking data — yes, temporary maintenance mode is right. Otherwise we clean on a copy and visitors never notice. We tell you at first look which case yours is.
If the site held customer data (a store, forms), we check the logs for what leaked — and tell you honestly whether GDPR requires notifying customers or the Data Protection Inspectorate. Most brochure-site hacks leak nothing.
Yes — once the site is clean we request a review through Search Console; the warning typically drops within a day or two.
Website care & maintenance · PHP upgrade · SEO & website optimization
Something's wrong with your site?
Send us the address and what you're seeing — we'll tell you what it is and what it costs.