Store compromised?Emergency — our response time right now: Under 1 h · It's a weekday — emergencies go to the front of the queue
PrestaChamps
Under 1 hour to respond — weekdays · Official PrestaShop Partner

PrestaShop store hacked? We take over now. €50 for the first hour, the full quote after that.

Malware, a skimmer on your checkout, redirects to somebody else's site, a back office you can't get into, a "dangerous site" warning in Google. You buy one hour of emergency work for €50 and a PrestaShop developer starts on your store straight after. We cut off the attacker's access, neutralise whatever is harming your customers, then price the rest of the job in hours — you decide from there.

Weekdays: reply in < 1 h Weekends: reply in 2–3 h Quoted in hours, not vague packages
< 1 hWeekday response time
2–3 hWeekend response time
€50To start the intervention
0PrestaShop specialists on the team
Certified by Official PrestaShop Partner Google Partner We publish our own security module
02 Our response times, in writing

The only question that matters right now: how long before someone replies?

Two response times, depending on the day. Whichever applies right now is highlighted, based on the clock on your own device.

Right now Monday to Friday
under 1 h to respond

A PrestaShop developer — not an automated acknowledgement, not a salesperson — replies in under an hour and can start work straight after.

The clock starts at your message or your payment
Right now Saturday and Sunday
2–3 h to reply

We don't work weekends as standard. We do still check what comes in and reply within two to three hours. If it's burning — a live skimmer, a suspended merchant account — we can usually get someone on it the same day.

No surcharge: the hour is still €50
On your device it is —, — —

These are response times, not repair times. Nobody can promise to repair a compromised store in an hour without knowing what is inside it. What we do promise is that within an hour on a weekday — 2–3 hours at a weekend — somebody actually looks at your store, tells you what they see, and stops the bleeding.

03 What you are seeing

What is happening on your store?

Each symptom maps to a different family of attack, with its own priorities inside the first hour. Pick the one closest to what you can see: you will get what it means and what we do first.

04 What is running while you search

The hack is not the worst part.
The three clocks it starts are.

All three start before you have repaired anything.

72 hours to notify

GDPR Article 33 gives you 72 hours from the moment you become aware of a personal data breach to notify your supervisory authority. The clock started when you found out, not when you are repaired.

72 hstatutory notification window, GDPR Art. 33

Your payment provider can cut you off

A skimmer on the checkout page is a card incident. Providers and acquirers suspend the merchant account while they investigate — and a suspended account does not reopen in an afternoon, even once the store is clean.

€0taken while the merchant account is suspended

Google puts a red screen in front of your shop window

Once Safe Browsing flags the domain, the store stops being visited: Chrome, Firefox and Safari show a full-screen warning before your homepage. Paid traffic keeps being billed and stops reaching the catalogue.

1,068compromised PrestaShop stores detected in early June 2026, up from 327 in February (Turaco Labs)
05 How we start

€50. One hour. Then a quote priced in hours.

We have split the emergency into two decisions instead of one. The first costs €50 and takes thirty seconds. You make the second once you know exactly what is inside your store — and how many hours it takes to get it out.

Emergency package
€50one hour of immediate intervention

You pay, you send us the access, we go in. No meeting to schedule, no brief to write.

  • 60 minutes of a PrestaShop developer, not a first-line support junior
  • The emergency is handled inside that hour — the bleeding stops before the quote even exists
  • A written report of what was found, when the intrusion started and what was touched
  • A quote in hours for the full fix, line by line — you decide afterwards, no commitment
  • Same price at weekends. No surcharge, no out-of-hours uplift
Buy the emergency hour — €50

After payment you immediately get the link to send us your access credentials securely.

1 You buy the hour — €50 Online payment. Nothing to describe, nothing to justify. It is the only financial commitment you make at this point.
2 We reply Under an hour on weekdays, 2–3 hours at weekends. We ask for three things: FTP or SSH access, database access, back-office access.
3 We handle the emergency inside the hour We do not try to repair everything in sixty minutes. We stop whatever is currently costing you money, customers or a legal obligation.
4 You get the quote for the full fix Priced in hours, line by line, with what each hour covers. Accept it, decline it, or take it elsewhere with our report in hand.

Why €50 and not a free audit? A free audit gets you a report. €50 gets you an hour of someone actually working on the store. It is also what lets us put you ahead of the queue on a Sunday evening.

06 What happens after you pay

The first hour, minute by minute

The order matters. We don't clean before there is evidence, and we don't restore a backup before knowing how long the intrusion has been running — last night's may already contain the backdoor.

0–5

Contact and access

A developer replies, not a form. We collect FTP/SSH, database and back-office access. If the attacker changed your passwords, we go through the host — it is common and it is workable.

Access handled securelyNo access retained afterwards
5–15

A snapshot of the current state, before touching anything

A full copy of files and database in their compromised state. That is what lets you prove what happened — to your insurer, your payment provider, your supervisory authority — and stops the clean-up destroying the only evidence there is.

Evidence preservedReversible clean-up
15–30

We stop the bleeding

Skimmer on the checkout: neutralised first, before anything else. Admin accounts created by the attacker: removed. Cron jobs and web shells that reinstall the infection: disarmed. Outbound redirects: cut.

Skimmer takes absolute priorityWeb shellsMalicious cron
30–45

Since when, and how they got in

Dating the intrusion from file timestamps, server logs and PrestaShop logs. Identifying the entry point: vulnerable module, reused password, end-of-life branch, compromised FTP credentials. Without that answer, any clean-up is temporary.

TimelineEntry pointScope of the leak
45–60

Report and quote

You get it in writing: what was found, what was done during the hour, what is still open, and whether personal data was exposed — the information your GDPR notification needs. Alongside it, the number of hours the full fix takes.

Written reportQuote in hoursNo commitment
After

The full fix, if you approve it

Exhaustive clean-up of files and database, entry point closed, credentials and keys rotated, a Google review request filed once the store is genuinely clean, then monitoring. The real test of a clean-up is not the same day: it is the following week.

Blacklist recoveryHardeningPost-incident monitoring
07 Proof of specificity

We already know which files you are about to find

These are the indicators of compromise PrestaShop published in its 17 February 2026 alert. They are what we look for in the first ten minutes.

What we look for first
  • _partials/head.tpl

    The theme file modified to inject code into every page of the site. That is where a skimmer sits so it can watch the payment forms go past.

  • mloader

    A malicious loader dropped to fetch and run the next payload. It survives most "visual" clean-ups and quietly reinstalls the rest.

  • simplefilemanager

    A fake module acting as a remote file manager. While it is there, the attacker keeps a key to your server even after you change every password.

  • atob(...)

    A base64-encoded payload decoded at runtime so it reads as noise. A plain grep will not find it: you have to know where to look.

Source: PrestaShop security alert, 17 February 2026. If you recognise even one of these on your store, the infection is not superficial — and restoring a backup will not be enough.

CVE-2026-54159 — CVSS 10.0 Unauthenticated remote code execution in ps_facetedsearch, published June 2026. It exposes every store on 1.7.1.0 or above. The maximum score means: exploitable remotely, without an account, without you doing anything.
327 → 1,068 compromised stores in four months Turaco Labs telemetry: detected compromised PrestaShop sites rose from 327 in February 2026 to 1,068 by early June. You were not singled out — you are inside a wave, and that is good news, because the attack pattern is already known.
We publish our own vulnerability-fix module We are not discovering PrestaShop's codebase when we arrive at your store: we ship a security module for this platform. That is the difference between hunting for a suspicious file and knowing which one to open first.
08 The honest question

"A freelancer will clean it for €99"

True — and sometimes it is even enough. Here is where the line actually falls, so you can decide on the facts rather than on the sticker price.

What has to be dealt with A €99 clean Restoring a backup PrestaChamps€50 emergency hour, then a quote
Removing the visible malicious code Yes, that is the job Yes, on the surface Yes — but that is the easy part
Finding the backdoor that reinstalls everything Rarely — this is why it comes back No — often already in the backup Systematic sweep for known IOCs, database included
Dating the start of the intrusion Out of scope Impossible once restored File timestamps plus server and PrestaShop logs
Closing the entry point Varies No — the flaw comes back with it Module, version or credential identified and fixed
Preserving usable evidence The clean-up destroys it The restore overwrites it Snapshot of the compromised state before anything is touched
What your GDPR notification needs Not provided Not provided What was affected, since when, and what left the server
Google blacklist recovery Often filed too early, so rejected Only if the backup is clean Filed once the store is verified clean
What you know before paying for the rest A flat price with no written scope Nothing: you find out as you go A quote in hours, line by line, after the diagnosis
If it comes back in six weeks You pay the €99 again You restore again Post-incident monitoring: the real test of the clean-up

If your store is a shop window with no online payment, no customer accounts and no personal data, a €99 clean can be enough and we will say so. The maths changes the moment there are cards, customer accounts or a merchant account to protect: there, a clean-up that leaves a backdoor behind did not cost you less — it cost you six more weeks.

09 Who picks up

A PrestaShop agency, not a generic security hotline

It comes down to one thing: does the person opening your store know PrestaShop, or are they running a clean-up procedure that would apply to any CMS? We only do PrestaShop. No WordPress, no Shopify.

  • 16 PrestaShop specialists, named and reachable — not an anonymous pool of subcontractors
  • Official PrestaShop Partner and publisher of our own modules, including a vulnerability-fix module
  • A PrestaShop agency since 2014, with clients we have supported continuously since 2019
  • Every version, 1.4 through 9.x — including the end-of-life branches where most incidents happen
  • No access retained once the work is done: the credentials you give us are revoked and you are told when
Official PrestaShop Partner PrestaShop module publisher Weekend replies at no surcharge
0PrestaShop specialists
2014Agency founded
1.4 → 9.xVersions covered in an emergency
Mon–FriOur working days — we still reply at weekends
10 Frequently asked

What we get asked in the first minute

Monday to Friday, in under one hour. We don't work weekends as standard — but we do check what comes in and reply within 2 to 3 hours. If it's genuinely urgent (a live skimmer, a suspended merchant account, a blacklisted store), we can usually get someone on it the same day. These are response times, not repair times: the first reply comes from a PrestaShop developer, not an automated acknowledgement.
One hour of a PrestaShop developer working on your store, starting now. We diagnose what happened, cut off the attacker's access, neutralise whatever is stealing data or harming your customers, and leave the store in a safe state in the meantime. At the end you get a written report of what was found and what was done, plus a quote in hours for the full fix.
Because a free diagnostic is not an intervention. For €50 you are not buying a report: you are buying an hour of real work on your store, immediately. It is also what lets us put you ahead of everything else on a Sunday evening instead of queueing you behind requests that are not urgent.
It depends on what the emergency hour uncovers: how many backdoors were installed, how deep the infection reaches into the database, the state of your backups, and the work needed to get off the Google blacklist. We do not guess before looking — a flat price quoted before diagnosis is either padded or revised mid-job. At the end of the first hour you get a quote in hours, with what each hour covers, and you decide from there.
No. The €50 hour is a standalone job. Plenty of stores already have an agency or a developer they work with — often the only problem is that nobody was available at 9pm on a Sunday. You get the written report and the quote either way, including the entry point and what still needs closing, so whoever picks it up is not starting from scratch. And if your usual developer wants to talk it through with ours, that works too.
A €99 clean removes what is visible. The problem is almost never what is visible: it is the backdoor left in a theme file, the cron job that reinstalls it, the admin account created during the attack. If a single one survives, the infection returns — usually a few weeks later, and you pay for the whole thing again. The detail is in the comparison above.
Not always. If a skimmer is capturing card data at checkout, yes: we close the checkout immediately, because every order that goes through is one more victim and one more notification obligation. In other cases the store stays open while we work. We tell you at diagnosis, with the reason.
If personal data was exposed, GDPR Article 33 gives you 72 hours from becoming aware of the breach to notify your supervisory authority. That clock is already running. We are not your legal counsel, but we give you what the notification needs: what was affected, since when, and what did or did not leave the server.
A review request can only be filed once the store is genuinely clean — a request sent too early is rejected and makes the process longer. Once the clean-up is finished and verified, we file through Search Console and Google usually lifts the warning within 24 to 72 hours.
Yes — that is the usual case in an emergency. We do not need prior knowledge of the store: we need FTP or SSH access, database access and back-office access. If you no longer have those because the attacker changed them, tell us — it is a common situation and it is solvable, usually through your host.
It happens: a 500 error after a module update looks a lot like a hack when seen from the back office. If the emergency hour concludes there is no compromise, we say so plainly, we explain the real cause, and the hour you bought goes into fixing that instead of chasing a ghost.
All of them, 1.4 through 9.x. Most compromised stores we see are on 1.6 and 1.7, because those branches no longer receive security patches — but an up-to-date store can be compromised too, typically through a third-party module: CVE-2026-54159 affects every install on 1.7.1.0 or above.
We close the entry point, rotate credentials and keys, and monitor the store through the period that follows — because the real test of a clean-up is not the same day, it is the following week. If the store runs on an end-of-life branch, we also tell you what it would take not to see us again in six months.
11 Let's go

Tell us where the store is. We'll look.

Three fields, because this is an emergency and not a tender. If you would rather start straight away, buy the emergency hour — we come back to you for the access right after.

  • A reply in under 1 hour — from a PrestaShop developer
  • €50 to start the intervention, same price at weekends
  • A quote priced in hours for the full fix, after the diagnosis
  • Your credentials are revoked when the work is done
Faster by phone?+44 2032 909329

Report a compromised store

We reply in under an hour (Monday to Friday).

Save us time — optional, but we start sooner

Don't put any passwords here. This form is the wrong channel for that — you'll get a secure link instead. These fields simply let us prepare the work before we even have access.

Three required fields, deliberately. The rest is optional — but every one you fill in gets us started sooner.

Already sure this is an emergency?

Buy the emergency hour — €50
Emergency help — €50