Emergency line, 7 days a week — first response within 4 hours

PrestaShop site compromised?
Take back control in 48 hours.

Compromised modules, injections in templates and overrides, fraudulent payment modules, persistence with falsified timestamps: attack patterns our PrestaShop playbooks detect methodically.

Typical symptoms

What we see on PrestaShop

Unknown scripts injected into the theme or entry files
Mobile redirects to fake application stores
Modified or duplicated payment module (card data skimming)
Unknown employee accounts or altered permissions
File timestamps inconsistent with actual activity
Infection reappearing after a superficial cleanup

Any one of these signals warrants triage. It is included and billed only if an engagement starts.

Four phases, monitoring included

1
H0 → H4

Triage

Confirmed compromise or false positive? Scope, exposed data, legal obligations. Engagement authorisation signed online, secure access established.

2
H4 → H24

Analyse

Web server logs, integrity comparison of core and modules, analysis of tamper-resistant filesystem metadata, review of overrides and hooks, third-party access inventory.

3
H24 → H48

Eradicate

File-level and database eradication, full credential rotation, critical file locking, server and CDN cache purge, verification re-scan.

4
D2 → D30

Monitor

Integrity probes and automated watch for 30 days, with an alert channel validated by a real end-to-end test.

PrestaShop engagement

Published rates, signed scope, best-efforts obligation stated in writing.

Emergency response

from €1,500
30% deposit to start the analysis — you receive the diagnostic report; the balance unlocks eradication and monitoring
  • Triage and full forensic analysis
  • Root-cause eradication and credential rotation
  • Third-party access audit (keys, vendor accounts)
  • 30 days of monitoring included
  • Executive summary report
  • Optional insurer / ad-platform report: + €800
Start an intervention

Frequently asked questions

How fast do you respond?

First response from an engineer within 4 business hours, 7 days a week. For confirmed emergencies, triage begins as soon as the engagement authorisation is signed online.

Should we take the site offline immediately?

Not before speaking with us. Shutting down destroys volatile evidence and does not remove persistence. We move the site into controlled maintenance instead.

What if no compromise is confirmed?

Triage is included: if no engagement starts, it is not billed.

Do you guarantee we will not be attacked again?

No — and be wary of anyone who promises that. We are bound by a best-efforts obligation stated in the contract: industry standards, a defined scope, and 30 days of monitoring to verify the eradication holds.

Our ad account is suspended — can you help?

Yes, as an option: we assemble remediation evidence in the expected format, file the review request and follow it through to removal of the flag — the same process applies to cyber insurance claims.

Contact us

An engineer replies within 4 business hours — immediately for confirmed emergencies.

Emergency — 7 days a week +00 000 000 000 placeholder — replace with real number

emergency@cerbexia.com · sos@cerbexia.com
Remote engagements across Europe — EN / FR / ES / IT / PT / PL / HU / CS