Your site is hacked. Do not delete anything yet.

The first hour decides whether you find out how they got in or only that they did. Here is what to do right now, what a real investigation involves, and what you should expect to be given at the end of it.

The first hour

Seven things, in this order.

You can do all of this yourself, and you should start now whether or not you call anyone. The order matters more than the speed.

01

Preserve before you clean

Take a full snapshot of the files, the database and the server logs, and put it somewhere the site cannot reach. Deleting the malicious files first is the most common mistake there is, and it destroys the only record of the entry point.

02

Contain it

Put the site into maintenance mode if customer data may be exposed or the site is serving malware to visitors. A page that says you are working on it costs far less than a browser warning or a blocklisting.

03

Rotate every credential

From a device you trust, not the one you may have been compromised on. Hosting, administrator accounts, database, FTP and SFTP, API keys and anything reused elsewhere. Assume everything the site could read has been read.

04

Look for what was added

Administrator accounts you do not recognize, scheduled tasks, new plugins, modified core files, unexpected redirects. Attackers almost always leave a way back in, and it is rarely the same one they came through.

05

Do not just restore a backup

Restoring puts the site back and puts the vulnerability back with it, usually along with their access. It also overwrites the evidence. Restore after you know the entry point, not instead of finding it.

06

Check what the site could reach

Payment processors, mailing lists, CRM connections, cloud storage, anything holding an API key. The website is often not the target so much as the way in to something else.

Then work out whether you have a notification obligation. In Canada, PIPEDA requires reporting breaches that create a real risk of significant harm, and other jurisdictions have their own rules. That is a question for a lawyer, and it is better asked early than late.

What we do

Investigate first. Then recover.

Most services in this market clean the files and hand the site back. That removes the symptom and leaves the cause, which is why so many sites are compromised twice through the same hole.

01

Contain and preserve

Stop the bleeding, isolate the site, and take a forensic copy before anything is altered.

02

Establish the entry point

Access logs, file modification timestamps, the database and the version history of every component, reconciled into a timeline of what actually happened.

03

Assess the reach

Which files were touched, which data was accessible, what was exfiltrated or altered, and what else the site had credentials for.

04

Recover properly

Restored from clean backups where they exist and rebuilt from source where they do not, with the vulnerability closed before anything goes back online.

05

Harden and monitor

Patching, hardening and active monitoring afterwards, because the same automated scanners that found you the first time are still running.

06

Report

A written account you can hand to an insurer, an auditor or a board without needing to translate it first.

The report

The part almost nobody gives you.

A one-off malware removal costs somewhere between one hundred and two hundred and fifty dollars, and gives you a clean site and no explanation. Corporate digital forensics starts around twenty-five thousand. Almost every business that gets hacked needs something in the middle, and that is the gap we work in.

01

Entry point and timeline

How they got in, when, and what happened in what order.

02

Scope of access

Which files and which data were reachable, and what the evidence shows was actually reached.

03

Indicators of compromise

What was added, changed or left behind, so it can be recognized if it appears again.

04

Attack characterization

The toolkit, campaign or automated activity behind it, and attribution where the evidence determines it. We say what the evidence supports and no more.

05

Remediation applied

What was fixed, what was rebuilt, and what was closed.

06

Recommendations

What to change so the same category of attack does not work a second time.

Cyber insurers and PCI assessors ask for exactly this document, and most small businesses cannot produce one. That is usually the moment people discover their cleanup service did not write anything down.

Questions

Straight answers.

My website was hacked. What should I do first?

Preserve the evidence before you clean anything. Take a full snapshot of the site, the database and the server logs, then put the site into maintenance mode if customer data may be exposed. Change passwords from a device you trust, rotate hosting, administrator, database and API credentials, and check for administrator accounts and scheduled tasks you do not recognize. Only then start removing anything. The most common mistake is deleting the malicious files immediately, which destroys the only record of how the attacker got in.

Can I just restore a backup?

Restoring a backup puts the site back and puts the vulnerability back with it, usually along with the attacker’s access. It also overwrites the evidence. A backup is part of recovery, but only after you know the entry point and can close it. If you do not know how they got in, you are restoring to the exact condition that was exploited.

How do I know how they got in?

Through the logs, the file modification timestamps, the database, and the version history of every component on the site. Access logs usually show the request that succeeded, the file timestamps show what changed and when, and the component versions show which known vulnerability was available at that moment. This is what a forensic investigation does, and it is why the evidence has to be preserved before cleanup.

What does a real incident report contain?

The entry point and how it was exploited, a timeline of what happened and when, which files and which data were reached, the indicators of compromise, what was changed or added, and the remediation applied. Where the evidence determines it, characterization of the attack – the toolkit, campaign or automated activity behind it. It should be written so it can be handed to an insurer, an auditor or a board without translation.

Do I have to tell my customers?

Possibly, and it depends where you and they are. In Canada, PIPEDA requires organisations to report breaches of security safeguards that create a real risk of significant harm to the Privacy Commissioner and to affected individuals, and to keep records of all breaches. Other provinces and US states have their own rules. This is a legal question rather than a technical one, and it is worth asking a lawyer early rather than late – we are not lawyers and do not give legal advice.

How much does incident response cost?

Between the two extremes this market usually offers. A one-off malware removal runs roughly one hundred to two hundred and fifty dollars and gives you a cleaned site with no explanation. Corporate digital forensics starts around twenty-five thousand. Most businesses need something in between: the site recovered, the entry point identified and closed, and a written report they can actually use. We scope it after we know what we are looking at, and tell you the number before we start.

Can you help if we are not already a client?

Yes. Most sites we take on after an incident were built and hosted by someone else. We investigate, recover and report first; whether you stay on a care plan afterwards is a separate conversation and not a condition of the work.

Get help

Tell us what you are seeing.

What is on the screen, what your host has told you, and when you first noticed. We will tell you what we think it is and what it will take, before you commit to anything.