Incident response for compromised PrestaShop, WordPress and WooCommerce stores
Almost never from an alarm. Almost always from a customer, from Google or from the bank.
A skimmer injected into the checkout copies payment data while purchases keep working. The store looks healthy; the customers don't.
Red warning in Chrome, drop in search results, ads paused. The reputational damage starts before anyone knows what happened.
New accounts in the back office, unknown modules, odd scheduled tasks, PHP files inside image folders. They are back doors for getting in again.
Deleting the visible file without finding the entry vector or rotating credentials guarantees reinfection. And every blind clean-up destroys the evidence of the previous one.
The full incident cycle, from containment to report. As a one-off intervention or with ongoing monitoring.
Initial triage of the scope and decision on whether to keep the store online or isolate it. Before changing anything, a copy of the file system, the database and the server logs: evidence is preserved first.
Inventory of added or modified files. Search for webshells, back doors, malicious scheduled tasks, unrecognised admin accounts and code injected into templates, modules and the database, with specific attention to payment-data skimmers.
Timeline reconstruction from file-system metadata and Apache, Nginx or LiteSpeed logs. Entry vector, exposure window and whether customer or payment data was accessed or exfiltrated.
Clean-up and reinstallation of core and modules from verified sources. Rotation of database, FTP/SSH, control panel, admin and webservice or API credentials. Review of accounts and permissions.
File permissions, pending version updates, security headers and content security policy, and web application firewall rules to close the vector that was used.
Second review after clean-up, check of the domain against blocklists and browser warnings, and a technical report with timeline, indicators of compromise, entry point, scope and measures applied and pending.
The technical report works for your insurer, your hosting provider or as the basis for later proceedings. If the incident ends in a claim or in court and you need an expert-witness opinion, that is done by a chartered IT expert witness: not by Lynx Devs, but by Oliver CG (see below).
From first contact to closing the incident. Order matters: contain without destroying the evidence.
You tell us what you have seen and what access you have (hosting, FTP/SSH, store back office). Together we decide whether the store stays online, goes into maintenance mode or is isolated.
Full copy of files, database and logs. On that copy we look for the malicious code, date the intrusion and locate the entry vector.
Reinstallation from verified sources, rotation of every credential, closing of the vector and hardening of the installation.
Second review, review request to Google if the site was flagged, and a technical report with what happened, what we did and what remains pending.
The sooner the evidence is preserved, the more can be known. Every improvised clean-up erases clues.
Redirects, spam in search results, a Google warning, unknown files or accounts, processes eating the server with no explanation.
If your payment gateway, your bank or several customers agree that cards used in your store have been compromised, the checkout is the first place we look.
Reinfection means a back door was left behind or the entry vector is still open. We look for the cause, not the symptom.
Lynx Rescate closes the incident. These services prevent the next one or escalate it to an expert opinion.
Managed web application firewall on Cloudflare, configured with your store's real traffic, so the vector they used stops working.
See the managed WAFContinuous monitoring of availability, certificates, versions and new admin accounts, with our team receiving the alert. Included in maintenance.
See monitoringIf the incident ends in a claim, insurance or court, the forensic analysis with expert-witness standing is signed by Oliver Calvo, chartered IT expert (CPITIA).
Go to expert servicesWith the symptoms and whatever access you have to hand we can triage and tell you what comes first. In the meantime, don't delete anything.