PrestaShop holds a particular place in the e-commerce threat landscape: often older stores, many third-party modules, and updates postponed for compatibility reasons. Compromises follow recurring scenarios. Recognising them helps you understand what is happening — and gauge what is at stake.
Three typical scenarios
The quiet redirect. Your visitors are sent to a third-party site, often only from mobile and only when arriving from a search engine. The merchant sees nothing from their own browser: that is deliberate — the attack aims to stay invisible to the owner as long as possible.
Payment interception. Considerably more serious: the checkout flow is altered to capture your customers’ card data. The consequences then go well beyond the technical — your relationship with your payment provider, notification obligations, liability towards cardholders.
The reinfection loop. The site is cleaned, everything looks back to normal, and the problem reappears hours or days later. That is the sign that a way back in remained in place, and that only the symptom was treated.
The trap of dates
Many merchants date the intrusion to the day they discovered it. In practice the gap is often several weeks, sometimes more. Attackers know how to blur the most visible time indicators, which leads owners to underestimate how old the compromise is — and to restore a backup that already contains the problem.
Establishing a reliable timeline is one of the most technical parts of the work. It is also what governs every subsequent decision: which backup to use, what data may have been exposed, and over what period.
What you can prepare before the engagement
Gather the factual elements: since when has the problem been reported, by whom, on what device, and what changed recently — a module installed, a migration, a third-party intervention. List every existing access, including former contractors. And check the real state of your backups: do you know when the last restoration was actually tested?
These three things save considerable time and carry no risk, unlike any direct handling of the files.
The most expensive mistakes
Restoring an old backup without knowing the intrusion date. Cleaning without rotating credentials — the attacker simply walks back in with access that still works. And treating the incident as closed the same day, with no observation period: the surest way to learn about the reinfection from a customer, or from a warning in search results.
After recovery
A compromise leaves traces beyond the server: a security warning, suspended advertising campaigns, legitimate questions from your customers, sometimes an insurance claim. Each of these has its own rules and timelines, and requires properly presented evidence of remediation. It is the part of the work purely technical providers tend to leave to the merchant — at the worst possible moment.