Diagnosis
What really happened: a hack, a hosting failure, a botched update or an unpaid invoice.
People contact us once the site has already stopped working: a white screen, unfamiliar ads in place of content, a browser warning, or a site that vanished along with the hosting account. First we get it running again, then we find out how it happened and make sure it does not repeat.
The order never changes: stop the damage, bring the site back, remove the cause. No step can be skipped.
What really happened: a hack, a hosting failure, a botched update or an unpaid invoice.
The site is taken offline if it spreads malicious code or sends people to foreign pages.
We find and remove injected code in files and database and hunt specifically for backdoors and hidden admin accounts.
From backup or, failing that, from the hosting provider's copies, search engine caches and web archives.
We request a new review in Google Search Console once the threat is gone.
Updates, new passwords for everything, a locked-down admin area and backups that work from now on.
A typical hack is resolved within one to three days. Without backups it takes longer, and nobody can promise everything returns.
We examine the site and hosting, establish the scope and check which copies exist. This takes a few hours.
The site goes offline, every password is changed and the malicious activity is stopped.
Content is restored and the site is brought back into service.
Current versions, regular backups and monitoring, so it does not happen again next month.
If the attacker had access to personal data, you have 72 hours to report the breach to the Danish Data Protection Agency. That includes customer data from an online store or contact forms. We document what happened and which data may be affected as we go, so you have a basis for the notification and the assessment is not guesswork afterwards.
We check the hosting provider first: many keep their own copies from the last few days without the customer knowing. Then come search engine caches and web archives. Structure and copy can usually be saved, though not always everything.
Typical signs: some visitors are redirected elsewhere, pages you never created appear, the host complains about spam, or the browser shows a warning. Sometimes the only symptom is a sudden drop in Google traffic.
Once the threat is removed and a review has been requested, it usually disappears within a few days. It drags on if Google finds malicious code again, which is why the clean-up must be thorough rather than superficial.
Tell us what happened and when it started. We look the same day, and if the site is completely down we start immediately.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.