>< Lynx Rescate · Incident response service

Incident response for compromised PrestaShop, WordPress and WooCommerce stores

1st
preserve the evidence before touching anything
PS · WP
PrestaShop, WordPress and WooCommerce
1
technical report with timeline and entry point
2nd
review after clean-up to confirm there is no reinfection

How a store finds out it has been compromised

Almost never from an alarm. Almost always from a customer, from Google or from the bank.

"My card was stolen on your site"

A skimmer injected into the checkout copies payment data while purchases keep working. The store looks healthy; the customers don't.

Google flags it as dangerous

Red warning in Chrome, drop in search results, ads paused. The reputational damage starts before anyone knows what happened.

Admins and files nobody created

New accounts in the back office, unknown modules, odd scheduled tasks, PHP files inside image folders. They are back doors for getting in again.

"We already cleaned it and it came back"

Deleting the visible file without finding the entry vector or rotating credentials guarantees reinfection. And every blind clean-up destroys the evidence of the previous one.

What Lynx Rescate includes

The full incident cycle, from containment to report. As a one-off intervention or with ongoing monitoring.

Activation and containment

Initial triage of the scope and decision on whether to keep the store online or isolate it. Before changing anything, a copy of the file system, the database and the server logs: evidence is preserved first.

Locating the compromise

Inventory of added or modified files. Search for webshells, back doors, malicious scheduled tasks, unrecognised admin accounts and code injected into templates, modules and the database, with specific attention to payment-data skimmers.

Dating and scope

Timeline reconstruction from file-system metadata and Apache, Nginx or LiteSpeed logs. Entry vector, exposure window and whether customer or payment data was accessed or exfiltrated.

Eradication

Clean-up and reinstallation of core and modules from verified sources. Rotation of database, FTP/SSH, control panel, admin and webservice or API credentials. Review of accounts and permissions.

Hardening

File permissions, pending version updates, security headers and content security policy, and web application firewall rules to close the vector that was used.

Verification and deliverable

Second review after clean-up, check of the domain against blocklists and browser warnings, and a technical report with timeline, indicators of compromise, entry point, scope and measures applied and pending.

The technical report works for your insurer, your hosting provider or as the basis for later proceedings. If the incident ends in a claim or in court and you need an expert-witness opinion, that is done by a chartered IT expert witness: not by Lynx Devs, but by Oliver CG (see below).

How it works

From first contact to closing the incident. Order matters: contain without destroying the evidence.

01

Contact and triage

You tell us what you have seen and what access you have (hosting, FTP/SSH, store back office). Together we decide whether the store stays online, goes into maintenance mode or is isolated.

  • Access
  • Symptoms
  • Online / isolate decision
02

Preservation and analysis

Full copy of files, database and logs. On that copy we look for the malicious code, date the intrusion and locate the entry vector.

  • Forensic copy
  • Webshells
  • Logs
  • Timeline
03

Clean-up and closure

Reinstallation from verified sources, rotation of every credential, closing of the vector and hardening of the installation.

  • Clean source
  • Credentials
  • Permissions
  • WAF
04

Verification and report

Second review, review request to Google if the site was flagged, and a technical report with what happened, what we did and what remains pending.

  • Reinfection
  • Safe Browsing
  • Report
  • Pending items

When to call Lynx Rescate

The sooner the evidence is preserved, the more can be known. Every improvised clean-up erases clues.

  • Confirmed or suspected infection

    Redirects, spam in search results, a Google warning, unknown files or accounts, processes eating the server with no explanation.

  • Card fraud warning

    If your payment gateway, your bank or several customers agree that cards used in your store have been compromised, the checkout is the first place we look.

  • It was cleaned and came back

    Reinfection means a back door was left behind or the entry vector is still open. We look for the cause, not the symptom.

Before, during and after the incident

Lynx Rescate closes the incident. These services prevent the next one or escalate it to an expert opinion.

Lynx Perímetro

Managed web application firewall on Cloudflare, configured with your store's real traffic, so the vector they used stops working.

See the managed WAF

Lynx Monitor

Continuous monitoring of availability, certificates, versions and new admin accounts, with our team receiving the alert. Included in maintenance.

See monitoring

IT expert witness

If the incident ends in a claim, insurance or court, the forensic analysis with expert-witness standing is signed by Oliver Calvo, chartered IT expert (CPITIA).

Go to expert services

Frequently asked questions

Should I take the store offline in the meantime?
Why not just restore a backup?
Which platforms do you cover?
Is the report valid for court or for the insurer?
How is it contracted?

Tell us what you have seen

With the symptoms and whatever access you have to hand we can triage and tell you what comes first. In the meantime, don't delete anything.

Contact us, don't be afraid.
Chat on WhatsApp