FR EN

Do you suspect your website has been hacked?

If you are on this page, you suspect your website has been hacked. A redirect you did not set up, a Google warning, a message from your host, or a payment form that no longer looks like yours.

At this point, two questions come up: is it really a hack, and how far does it go.

We answer both, then we put the site back in order.

  1. We analyse the site and list the infected files.
  2. We clean the injected code and remove the backdoors.
  3. We find the vulnerability the attacker came through and we fix it.
  4. We check that everything is in order and that your site works exactly as it did before.

You receive a detailed report of what happened: every file cleaned, every backdoor removed, and the vulnerability fixed. If the site is reinfected within 7 days, we step in again free of charge.

If you are here, you suspect a hack. We look, we clean, we close the way in. 329 sites back online since 2018.

€69 excl. VAT off your first job with us €69 excl. VAT off your first job with us

Clean my website

Step 1 / 4

What are you seeing on your site?

Several answers possible. Only tick what you have seen yourself.

You cannot see it. Your customers can.

A hacked site looks normal when you are the one looking at it. The code fires for everyone else. Here are the four screens we find most often.

Google results page: among a shop's real pages, an injected page in Asian characters, circled in orange.

Japanese pages under your own domain

They only show up in Google, never while you browse your own site. The attacker creates thousands of pages under your domain to sell counterfeits, riding on the authority you spent years building. Your rankings work for someone else, and your real pages fall back by the same amount.

What we do: we remove the scripts generating those pages, delete any Search Console property the attacker may have added to steer your rankings, then identify the way in that let them run their code. The review request to Google comes only afterwards, once the site is clean: sent too early it is refused. Processing then takes a few days.

Card theft, the one that costs the most

Two forms, and the quieter one is worse. In the first, the attacker simply copies your customers' card numbers as they are typed. The payment goes through, you get paid as usual, nothing shows, sometimes without the form even looking different. It can run for months. In the second, they replace your form with their own and collect the orders in your place for as long as nobody notices: you lose your customers' card numbers, the revenue, and you still have to ship the orders.

What we do: we remove the code from the checkout, pin down exactly how long it ran so we know which customers are affected, and support you on your notification obligations if data leaked.

A shop checkout: the three-digit verification code is asked for a second time, circled in orange.
Red browser warning page shown instead of a shop's homepage.

A red screen instead of your shop

This screen does not appear on day one. It means Google itself has confirmed the compromise and is now protecting your visitors from your site: the infection has been in place and indexed for a while. Traffic drops the same day, regulars included, and your paid campaigns stop while the warning stands.

What we do: we clean, check that nothing infected is still indexed, then follow the warning through until your site comes back normally in the results.

The email from your host

This one often arrives before the others: the host sees the mass sending or the abnormal load before Google reacts. That is lucky, except the shop is already cut off, orders in progress interrupted, and you can no longer fix anything yourself because access is closed. Every hour counts.

What we do: we get in touch with the host, clean from the rescue access, and get the service restored.

Email from a hosting provider announcing account suspension for unusual activity, subject circled in orange.

Not an exhaustive list: these are the four situations we meet most often, there are others.

And in the worst case, the attacker erases everything (very rare)

It happens. In April 2026 an attacker took control of a server we were not yet managing, deleted the files and databases of two shops, then left a bitcoin ransom note claiming to hold a copy.

We did not pay. Nothing guaranteed he really held the data, nor that he would return it. We rebuilt the server, then reconstructed the catalogue from public web archives. Both shops are back.

  1. Plan A Cleaning in place, while the files are still there. That is the usual case.
  2. Plan B Your backup.
  3. Plan C Your host's backups, even when you believe there are none.
  4. Plan D Public web archives.

Archives never return a catalogue in full. They were enough to put these two shops back online.

Find out where I stand

Four questions, thirty seconds. 329 sites back online since 2018.

329 hacked websites cleaned since 2018

329
Sites cleaned
590
Security interventions
25
Years of experience
285
Google reviews
4.9/5

Why is it important to secure your website with a professional solution?

Millions of cyber attacks are recorded every day. As one of the top targets of hackers, unprotected websites are exposed to daily exploits of vulnerabilities, which allow attackers to set up scripts, which allow a whole bunch of actions that will harm your visitors and your website.

As soon as a site is hacked, your business is immediately impacted, the financial consequences can be very heavy.

Illustration of a hacker attacking a website - hacked site cleanup service

How will Mon Site Bug clean up your site?

Disinfecting a website from viruses is a complex task, requiring several steps or breaking down into several subtasks. No matter what security situation your website is facing, we deploy a multitude of skills to restore a normal situation.

Analysis and diagnosis of a malware-infected website

Situation analysis

No serious work can be done without a good analysis of the situation, we determine the type of virus, the objective of the attacker (information theft, visitor hijacking, phishing, SEO ...) and the scope of the attack.

Cleaning virus-infected files on a website

Clean up infected files

Files may have been installed, allowing the hacker to steal information, add tools offering a range of features, or infect your visitors. We proceed to the cleaning of these.

Searching for the security vulnerability exploited by the hacker

Search for the vulnerability

One of the most critical points consists in the research of the flaw, indeed the attacker could penetrate your site only by exploiting a security flaw, we search in your logs and your files to determine the original entry point.

Patching and fixing the security vulnerability on the website

Patch the vulnerability

Once the flaw is found, it must be patched, either by updating one of your scripts, CMS, if available, or we implement ourselves a solution to prevent the flaw from being exploited again.

Do you suspect a hack? Start with the findings.

Four questions, thirty seconds, and you will know where you stand. The assessment costs nothing and commits you to nothing.

Check my site

What our customers say Emergency call-outs, sites put back online, and access handed to strangers. Here is what they took away from it.

  • Google

    A professional who listens, is patient, and genuinely honest, and doesn't overcharge. Honestly, I was a little stressed about giving out my access credentials. I can't recommend him highly enough! And all this for a service call on a Sunday!

    Helene Rbt
    Helene Rbt
    6 months ago
  • Google

    I worked with Mon Site Bug after my website was hacked. They were responsive, quick, available, and professional. I will definitely use their services again, especially since their price was competitive compared to other companies or freelance developers.

    Yan Long
    Yan Long
    9 months ago
  • Google

    We had to urgently contact this company. We spoke with Fouad on the phone, and his support was very responsive and attentive. You can really tell he knows his stuff. It's a real pleasure to be able to talk with professionals who know what they're talking about and who understand each situation perfectly. We're keeping this service provider in our address book now. Well done and thank you! 👏🥂

    Para ton air Para ton air
    Para ton air Para ton air
    1 year ago
  • Google

    Great troubleshooting… fast! And available even on weekends

    Caroline SIMONEAU (Caroline's Cooking)
    Caroline SIMONEAU (Caroline's Cooking)
    1 year ago
  • Google

    Excellent service. The teams were responsive and helpful. The problem was resolved very quickly. Thank you.

    Vert Parc
    Vert Parc
    1 year ago
  • Google

    This company is very reliable and responsive; they saved our completely crashed website. They are professional and have an excellent understanding of PrestaShop. So go ahead and trust them; you won't be disappointed.

    Lilian ROBERT
    Lilian ROBERT
    2 years ago

Frequently asked questions about hacked site cleanup

We start working as soon as we receive your request. The cleanup itself takes on average 4 to 6 hours for a standard infection (malicious files, redirects, backdoors). For more complex cases — deep infections across hundreds of files, compromised databases, or entire servers affected — the work may take longer. In all cases, we keep you updated in real time on the progress.

That is what most people who call us think, and it is what brings them back a few days later. A restore returns your files to the state they were in at an earlier date. It does not touch the vulnerability the attacker came through: that vulnerability was already there before the infection, so it gets restored along with everything else. The attacker comes back the same way, often within days, sometimes within the hour when the site is watched by a bot. Second problem, nobody knows the exact date of the intrusion until the access logs have been read: restoring an already-infected backup is very common. A restore is a useful reprieve to get a site back online quickly, but it never replaces finding and fixing the way in.

This is one of the first things we check during our analysis. We inspect access logs, suspicious database queries and any potential exfiltration scripts. If data has been compromised, we help you assess the exact impact, secure access, and notify the relevant authorities if necessary (GDPR obligation). We also provide a detailed report to document the incident.

After each intervention, we perform a complete scan of all files and the database. We provide a detailed report listing every cleaned file, every removed backdoor and every patched vulnerability. We also verify that Google no longer shows any warnings and that your host has lifted any suspension. If the problem returns, we intervene again free of charge.

Cleanup alone is not enough: we systematically identify and patch the vulnerability that allowed the intrusion. Then we implement concrete measures: CMS and plugin updates, access hardening (passwords, file permissions, FTP/SSH access), automatic backup configuration. For ongoing protection, we offer our PrestaSecure solution that monitors your site 24/7.

Yes, we systematically recommend it. You can file a report online through your government's cybercrime reporting platform or at your local police station. This is important for several reasons: it feeds ongoing investigations into hacker groups, it may be required by your professional insurance, and it is a legal obligation if personal data has been compromised (GDPR). We can provide the technical evidence to support your report.

Your website is compromised? Act now.

Every hour that passes increases the damage. Contact us for a free diagnosis and rapid intervention.

Request a free diagnosis

Running a PrestaShop store?

Cleaning up is good. Not coming back is better.

A cleaned site gets hacked again if the way in is still open. That is why we built PrestaSecure, our service dedicated to PrestaShop store security: continuous monitoring, real-time attack blocking, and an alert as soon as one of your modules is hit by a known flaw.

Serenity plan — €575 excl. VAT per year

Antivirus, firewall and, above all, unlimited clean-ups by our experts. No commitment, one domain. For comparison, a one-off clean-up alone is billed €345 excl. VAT: the second incident already pays for itself.

PrestaSecure only covers PrestaShop. On any other technology, order the clean-up from this page.

  • Scheduled antivirus scan and file integrity checks
  • Real-time firewall: SQL injection, XSS, brute force
  • Detection of known vulnerabilities in your modules
  • Unlimited expert clean-ups with Serenity

What we actually find on hacked sites

Our analyses of real infections: how attackers get in, what they leave behind, and how we clean it up.