Server Hacked

Suspect your Linux server has been compromised?

We determine what happened, contain the incident, recover affected services, and decide whether the server can be safely cleaned or should be rebuilt from a known-clean environment.

Please do not include passwords, private SSH keys or other permanent credentials here. If access is needed, we'll agree on a secure way to provide it. Have screenshots or logs? You can attach them by replying to our confirmation email.

Signs of Compromise

What usually gives it away

unknown processesunexpected CPU / memory usagesuspicious SSH activity new admin usersmalicious cron jobsspam being sent modified website filesunusual outbound connections provider security warningssites redirecting visitorsIP blacklisted

One suspicious file rarely tells the whole story — we investigate the wider Linux environment before deciding on the recovery approach.

Compromised WordPress Server

One vulnerable install can become a server-wide problem

Especially on servers hosting multiple websites, where one compromised installation may affect other accounts or services. We review compromised WordPress installs, malicious PHP files, suspicious admin accounts, server-side malware, unusual processes and affected hosting accounts together.

WordPress PHP Hosting Account Linux Server
What We Investigate

The visible symptom is rarely the whole incident

Malware

May include persistence mechanisms, added cron jobs, stolen credentials, background processes and extra access paths beyond the visible infection.

Server Sending Spam

Hacked WordPress, stolen mailbox credentials, malicious PHP, or a compromised hosting account — we find the source and restore control of mail.

Suspicious SSH Access

Unknown logins, unauthorised keys, new users, privilege escalation or modified SSH config — treated seriously, always.

Redirects & Malicious Code

Redirects, injected ads, fake login pages, malicious JS, hidden PHP files, modified .htaccess.

Scope of the Incident

One website, one account, several, or the whole server?

On multi-site hosting (HestiaCP, DirectAdmin, cPanel & WHM, VestaCP), the compromise may be limited or may have spread. We determine which case you’re actually in before deciding what to do — that scope defines the entire recovery plan.

High CPU After a Compromise

High load without normal traffic, unknown processes, unusual outbound connections, or processes that keep restarting after being killed — we check whether it’s a normal application issue or a security incident.

Provider Abuse Notification

Providers may restrict or suspend a server over spam, malware, scanning or attacks against other systems. We investigate and help gather the technical information needed to respond — and confirm the activity has stopped before the server goes back to production.

IP Blacklisted

Fix the cause before requesting removal

Removing an IP from a blacklist without correcting the actual compromise usually just brings the same problem back. We review mail activity, compromised accounts, hacked websites, server processes, and DNS/mail configuration before anything else.

The Key Decision

Clean the server, or rebuild it?

A limited website infection can sometimes be cleaned safely. In more serious incidents, the operating system itself may no longer be trustworthy. A clean rebuild tends to be the safer option when there’s evidence of:

  • root-level compromise
  • unknown system modifications
  • persistent unauthorised access
  • extensive malware
  • compromised SSH credentials
  • multiple affected services

We help evaluate the situation and recommend the safer recovery path — not the fastest-looking one.

Clean Server Rebuild

Moving forward without carrying the compromise along

new server preparationOS installationSSH hardening firewall configurationweb stack installrestore websites restore databasesrestore email where appropriate backup configurationDNS reviewmigrating clean data
Recovering Websites & Data

Website files, databases, email data, configuration and customer files — reviewed carefully before moving into a clean environment. A backup is only useful if it doesn’t restore the same compromise.

Backup Review After the Incident

The most recent backup may already contain the malicious files. We check which backups exist, how old they are, and whether any predate the compromise before restoring anything.

WordPress-Only Incidents

Dedicated WordPress malware removal

For incidents limited to WordPress: infected file investigation, core review, plugin and theme review, malicious admin accounts, database inspection, permissions and security recommendations.

from €149

Depending on the extent of the compromise. If it extends to the Linux server itself, it’s handled as a broader server security incident instead.

After Recovery

Security Hardening

OS updatesSSH hardeningfirewall review Fail2Banremoving unnecessary servicesWordPress updates hosting account reviewfile permission reviewbackup improvementsmonitoring

Appropriate to the actual server, not a generic checklist.

Full server security services →

Providers We Work With
HetznerOVHcloudNetcupContabo IONOSScalewayDigitalOceanVultr

Provider-specific detail →

Pricing

Emergency, or standard follow-up work

€95/ hour

Emergency Support — active malware distribution, spam being sent, services down, or ongoing unauthorised access.

€125/ hour

Out-of-Hours Emergency — evenings, weekends, holidays.

€55/ hour

Standard Support — non-critical review, security config, post-incident checks, hardening, log review, backup planning.

Emergency assistance subject to administrator availability. Full pricing →

What We Need From You

A few details speed up the investigation

hosting providerserver IP / hostnameLinux distribution control panel (if used)affected websitesprovider notification what you noticedwhen it startedrecent changes
Please don’t send passwords or private SSH keys in the initial request. If access is required, we’ll tell you exactly what’s needed.
Independent Linux Security Experience Since 2004

More than 22 years of practical experience with Linux servers, hosting infrastructure, WordPress, email, backups and production environments. When a server has been compromised, the objective isn’t simply to remove a suspicious file.

We determine the extent of the incident, recover the affected services, and help establish a clean, trustworthy environment again.

Think your server has been compromised?

Tell us what you’re seeing — we’ll help you figure out what actually happened.

Request Support → Contact Us