Service · Websites and web apps

Website recovery

When a site has been hacked, the temptation is to delete whatever looks odd, change the admin password and move on. It almost never works: attackers usually leave several ways back in, some outside the site itself, in FTP, the hosting account or a scheduled task, and they return within days. Take an Alicante estate agency that finds on Monday that its site redirects to a casino, Google lists thousands of Japanese pages under its domain and the host has suspended the account for spamming. Getting it running again is urgent, but so is understanding what happened, or the clean-up only lasts until the following weekend.

Evidence copy
taken before anything is touched
Rebuild
from official components
Blacklists
domain and server checked
Technical report
useful for insurer and AEPD

What falls within the scope of this service

Recovery covers the site, the hosting and the email, because an attack rarely stays in one place. These are the tasks.

Pin down the details with one of our engineers

Containment

A full copy of the infected state, every credential changed, sessions closed and a maintenance page if needed.

Attack analysis

Logs, modification dates, added users and scheduled tasks, vulnerable versions and any possible access to personal data.

Clean rebuild

Core, plugins and theme reinstalled from official sources, the database sanitised and content verified, or a clean backup restored.

Hardening

The vulnerability fixed, abandoned plugins removed, two-factor sign-in and filtering rules placed in front of the site.

Email and reputation

Blacklist checks, delisting requests, SPF, DKIM and DMARC verification and a review request in Google Search Console.

Documentation

A report with timeline, scope and actions taken, useful for deciding on AEPD notification, for the insurer or for a police report.

How the engagement unfolds, one stage at a time

We start as soon as we have access. An information site is usually back the same day; a shop compromised for weeks needs longer.

01

The first hours

A full copy of the current state as evidence, every credential changed and a joint decision on whether the site goes offline or shows a maintenance page.

02

Clean rebuild

Rather than hunting through files one by one, we rebuild the site from official components and verified content, or from an earlier clean backup.

03

Close and harden

The entry point fixed, two-factor sign-in for administrators, hosting and email reviewed, and filtering rules added.

04

Repairing reputation

Review requests in Google Search Console and on blocklists, junk pages removed from the index and a final report on what happened with recommendations.

Email is often the second casualty. A compromised host that sends spam ends up on blacklists, and for days the company's normal email, invoices included, lands in customers' spam folders or never arrives. So alongside the website we check whether the domain and server appear on blocklists, request delisting and verify SPF, DKIM and DMARC.

Common questions

If the attack may have affected personal data and poses a risk to people, the GDPR requires the breach to be notified to the AEPD within 72 hours of becoming aware of it. We provide the technical facts to assess the risk; the decision and notification rest with your company as controller.

That depends on how far the attack reached and the state of your backups. A small information site is often sorted in a few hours; a shop with live orders and no backups takes considerably more. Work is billed at €75 per hour + VAT, with an estimate as soon as the initial diagnosis is done.

Many policies cover recovery and require the incident to be documented. We keep a copy of the infected state and prepare a technical report with dates, scope and actions, which is usually what insurers ask for. Check your policy first in case it names a required supplier.

Yes. You can file a report with the Policía Nacional or the Guardia Civil, and our technical report serves as supporting evidence. INCIBE also offers businesses free guidance on what to do after an incident.

Keep updates current, run few plugins, require two-factor sign-in for administrators, store backups off the server and use monitoring that alerts you before visitors notice. That is exactly what a care plan covers, making it the natural next step after an incident.

Is your site down or hacked?

Tell us what you are seeing and when it started. Include your host and the platform the site runs on so work can begin immediately.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.