# Security and hacked site cleanup

> A hacked site is almost never limited to a single modified page. Cleanup starts with understanding how access was obtained, otherwise the problem comes back within days, sometimes more discreetly than the first time.

- Source canonique : [https://allaux.fr/en/services/securite](https://allaux.fr/en/services/securite)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## What points to a hack

- The site redirects to another domain, intermittently or only on mobile.
- Google or your host shows a warning about dangerous or deceptive content.
- Unknown pages appear in search results, with content you never published.
- An admin account exists that you didn't create, or a password changed without you doing it.
- The site is unusually slow, with high server activity and no obvious explanation.

## How the cleanup runs

1. **Containment** — Putting immediate measures in place to limit the damage during investigation, without necessarily cutting access to the site if it's not needed.
2. **Identifying the flaw** — Finding the real source of the intrusion: an outdated module, a compromised password, a flaw in a theme or extension.
3. **Cleaning the code and data** — Removing injected code, fraudulently created accounts and files added without authorisation.
4. **Closing the flaw** — Updating or fixing the identified entry point, to prevent immediate reinfection through the same path.
5. **Verification and review request** — Checking the cleaned site, then requesting removal of any Google warning if applicable.
6. **Strengthening monitoring** — Setting up a regular check after the incident, to catch any sign of recurrence earlier.

## What I can't guarantee

> I can't guarantee a site will stay safe from every future intrusion attempt indefinitely: IT security is never a fixed, permanent state. What I can guarantee is closing the identified flaw and explaining clearly what was found, without downplaying the situation to make it sound better.

## Going further

- **The first two hours** — What to do, and above all what not to do, as soon as a hack is suspected. ([/securite/que-faire-dans-les-deux-heures](/securite/que-faire-dans-les-deux-heures))
- **Checking whether the site is compromised** — The checks that confirm or rule out an intrusion before committing to a cleanup. ([/securite/verifier-si-mon-site-est-compromis](/securite/verifier-si-mon-site-est-compromis))
- **Hacked WordPress site** — Redirects, injected spam, Google warning: the cleanup on WordPress and WooCommerce. ([/wordpress-woocommerce/site-pirate](/wordpress-woocommerce/site-pirate))
- **PrestaShop hacked with no stolen password** — How a module flaw opens the shop without any login ever leaking. ([/securite/prestashop-pirate-sans-mot-de-passe-vole](/securite/prestashop-pirate-sans-mot-de-passe-vole))
- **The infection keeps coming back** — Why, and what the previous cleanup almost always missed. ([/securite/infection-revient-apres-chaque-nettoyage](/securite/infection-revient-apres-chaque-nettoyage))
- **All security questions** — Flaws, updates, customer data: answers sorted by situation. ([/securite](/securite))

## FAQ

### Will my site be hacked again after the cleanup?

A repeat hack through the same flaw is unlikely once it's closed. But no security is absolute: regular follow-up significantly reduces the risk, without eliminating it entirely.

### Do I need to notify my customers if data was leaked?

If personal data may have been exposed, a legal notification obligation can apply under the GDPR. I discuss this with you as soon as the diagnosis shows a possible data exposure.

### How long does cleaning up a hacked site take?

It depends on the scale of the intrusion and how hard the flaw is to locate. An initial diagnosis gives an idea of the time needed, before any final pricing.

### Do I need to take the site down during cleanup?

Not always, but sometimes it's the safest option while work is underway, especially if the site is still spreading malicious content.

### How do I protect against this after a hack?

Regular updates, strong passwords unique to each access point, and a maintenance follow-up to catch an anomaly before it becomes a major incident.

### Could the hack have affected my customers' data?

That's one of the first things I check: database access, any code capturing payments or credentials. I'll tell you clearly if that's the case, without downplaying it to reassure you artificially.
