Hacked PrestaShop website: malware removal, recovery and security hardening

Malicious redirects, SEO spam, Google Safe Browsing warnings or code injected into the checkout: every hour means more lost traffic and customer trust. We clean your store, get it back online and secure it for the long term.

  • Immediate support, including at weekends
  • Complete clean-up of files, database, and access credentials
  • Submitting a reconsideration request to Google after the clean-up
  • Security hardening to prevent another breach
90 €/h — View pricing
Cleaning up a PrestaShop store compromised by a cyberattack

The symptoms we check first

A systematic diagnosis, in the right order: we isolate the cause before changing a single file.

  • Unwanted redirects

    Your visitors are redirected to a third-party website, especially from search results or on mobile devices.

  • Indexed SEO spam

    Hundreds of spam pages indexed under your domain name.

  • Malicious code injected into the checkout

    A skimming script is capturing card details during checkout—an absolute emergency.

  • Unknown files

    Web shells, recently added PHP files in img/ or upload/, and suspicious scheduled tasks.

  • Employee accounts added

    Admin accounts you never created are appearing in the back office.

  • Hosting provider or Google alert

    Website suspended, emails blocked or a Safe Browsing warning displayed in the browser.

What we check—and then fix

What We Check

  • Core, theme and module file integrity
  • Recently modified files, web shells and scheduled tasks
  • Content injected into the database and unknown employee accounts
  • Access logs to identify the entry point
  • Vulnerable versions of PrestaShop, PHP and modules

What We Fix

  • File and database clean-up, including backdoor removal
  • Resetting access credentials: back office, FTP, database and hosting
  • Security updates and root vulnerability fix
  • Requesting a Google review and checking indexing
  • Ongoing security: backups, permissions and monitoring

Get emergency support now

Calling is still the fastest option. Otherwise, describe the issue and we’ll reply with an estimate.

Is it business-critical? Call us.

+33 6 31 55 57 57 — 9:00 to 22:00, seven days a week. A developer, not a call centre.

Free diagnosis · 9:00–22:00, 7 days a week

Describe the issue and we’ll reply with an estimate

Estimate provided before any work begins · 90 €/h

What to read while your store is down

The most useful pages and guides when every minute counts.

Every hour of downtime costs you orders

A French developer will review your store today. You receive an estimate before any work begins and only pay for the actual time spent.

Frequently Asked Questions

Do I need to close my store during the cleanup?

Rarely. If we find a payment data skimming script, we temporarily disable checkout while we clean the site. This is essential to protect your customers.

Does the incident need to be reported?

If personal data may have been exposed, the CNIL may need to be notified within 72 hours. We provide all the technical information you need.

How long does it take to remove a Google security warning?

Once the malware has been removed, the review request is usually approved within 24 to 72 hours.

How can you prevent it from happening again?

Our maintenance plan addresses the root cause, keeps PrestaShop and its modules up to date, and includes backups and monitoring.