5 min read · Last updated 7 August 2026
Act quickly but do not delete anything before we have looked at it — the logs and the modified files are what tell us how the attacker got in.
Immediately
- 1Open a High priority Technical Support ticket so we can take the site offline behind a maintenance page.
- 2Change your portal, cPanel, CMS and database passwords.
- 3Do not restore an old backup yet — it may contain the same vulnerability.
What we do
- Scan and identify the malicious files and the entry point.
- Clean the infection and patch the vulnerability.
- Review logs to determine what, if anything, was accessed.
- Advise you on whether the incident is notifiable under the Cyber and Data Protection Act.
If personal information may have been accessed, there are breach notification obligations under the Act. Our data protection team will advise on the timeline and reporting requirements.
Was this article helpful?
If it didn't answer your question, open a ticket and we'll help directly — and improve the article.