Home Services Who We Help Packages Heist Labs Resources Answers Case Studies About Craig Blog Let's Talk Contact
(423) 482-8886 Let's Connect →
Real-Life Case Study · Website Security

A painting client's website got hacked. We had it clean and back online the same day.

Here's exactly what happened, what we did about it, and why it's the part of the job most agencies walk away from.

Same day Cleaned & back online17 Malicious files removed1 Hidden backdoor caughtClean Re-scan confirmed by host
Anatomy of the attack

How it unfolded

Three moves, start to finish. The first two took seconds and happened with nobody touching the site. The third is the part we own.

  1. 01The break-inA bot finds an old plugin and slips in
  2. 02The shutdownThe host suspends the whole site to contain it
  3. 03The rescueWe clean it, close the backdoor, and it's back — same day

01 · The situation

Last week, one of the contractor websites we look after went down — a painting company we'd built a site for. It had been hacked, and the host had pulled the whole site offline to contain it.

An automated bot, one of thousands crawling the internet around the clock, found an old plugin on the site with a known security hole and used it to get in. It didn't go after this business on purpose. The bot hits thousands of sites at once looking for that one weakness, found an unlocked door here, and walked in. Once it was inside, it dropped a batch of hidden files. The hosting company caught it and did what hosts do: they took the whole site offline to stop it from spreading. So overnight, a business that runs on its website for leads had nothing but an error page sitting there, and every hour it stayed down was calls and estimates it wasn't getting.

This is where most of these stories go sideways. The owner spends a week on hold with the host, or hands a "malware removal specialist" a few hundred bucks and waits, or worst case watches the whole site get wiped and starts over from nothing.

02 · What we did

Ours went differently. The day we got the list of infected files from the host, we went to work. We cleaned every malicious file off the site — the ones the host flagged, plus a handful more we found on our own sweep that their scan had missed. We had the host re-scan the site, confirm it was clean, and bring it back online.

Then we caught the part most cleanups miss. The attacker had quietly created a hidden admin account to sneak back in later, with a key attached to it that would have let them right back in even after the files were gone. We found it, deleted it, and shut off the key.

That's the difference between a site that's "cleaned" and a site that stays clean.

Passwords rotated, access locked down, software tightened up — all of it the same day.

03 · Why it matters for every contractor

Your website is a target even if you're a small local shop, even if you're sure nobody's looking. The bots don't know or care how big you are. If your site is running old software that nobody's keeping an eye on, it's only a matter of time. The fix isn't complicated, but it does take somebody paying attention: keeping the software current, closing the weak spots before the bots find them, and being there fast when something breaks. Keeping a website safe is an ongoing job, and it's exactly why we don't build a site, hand over the keys, and disappear.

The outcome

Down for a stretch. Clean for good.

All of it inside the same day the host handed us the list of infected files.

Same day
Cleaned & back online
17
Malicious files removed
1
Hidden backdoor found & closed
0
Threats left after re-scan
The Heist Way

Is anyone actually watching your website?

Most agencies build it and disappear. We don't. 15-minute call, no pressure.