My Server Got Hacked. What Now?
Emergency Linux server investigation, malware removal and security recovery.
Submit your incident details and we'll review your request and provide an initial response within 1 hour. You don't need to know exactly what's wrong.
Or email us directly at help@myserverhacked.com
- Suspicious process
- DETECTED
- Unknown SSH key
- DETECTED
- Outbound traffic
- REVIEW
- System integrity
- INVESTIGATE
Illustrative example. This page does not scan your server.
Common symptoms
Something Isn't Right With Your Server?
These are the situations we see most often. If any of them sound familiar, it's worth investigating properly.
- Server suddenly using 100% CPU
- Unknown processes running as an unfamiliar user
- Crypto miner detected by you or your provider
- An SSH key in authorized_keys you did not add
- Outbound traffic to addresses you cannot account for
- Website serving content you did not publish
- A Docker container behaving unexpectedly
- Server became slow or unresponsive without explanation
Services
What We Help With
Focused entirely on Linux server incidents — investigation, recovery and hardening.
Linux Server Compromise
Your server is behaving strangely and you suspect unauthorised access.
Malware & Backdoor Removal
Identify malicious files, persistence mechanisms and unauthorised access paths.
Crypto Miner Removal
Unexplained CPU load, throttled workloads, or an abuse notice from your provider.
SSH Compromise
Unknown keys, unexpected logins, or credentials you believe are exposed.
Docker Security Incidents
A container behaving unexpectedly, or a host you think was reached through one.
Server Hardening
Reduce the attack surface after recovery — or before anything goes wrong.
Incident Investigation
Establish what happened, when it started, and what it touched.
Suspicious Processes & Network Activity
An unfamiliar process or outbound connections you cannot account for.
Production Server Recovery
Get a business-critical system back to a state you can trust.
Security Audits
A structured review of a server you want checked, with no active incident.
How it works
Three Steps, Starting Right Now
No lengthy intake process. Tell us what you're seeing and we'll take it from there.
- 01
Tell us what happened
Submit the incident details with whatever information you currently have. You do not need to diagnose the problem yourself.
- 02
We investigate
We review the information and determine the safest next steps, then reply with our initial assessment and what we need from you.
- 03
Recover & secure
We investigate the incident, remove malicious persistence where possible, harden the system and provide recommendations.
Important: For deeply compromised systems, rebuilding from a known-good image may be safer than attempting to clean the existing system. We'll tell you when that's our honest recommendation.
Why it matters
A Stopped Process Is Not a Solved Incident
Killing the obvious symptom rarely ends a compromise. The question that matters is how someone got in, and what else they left behind.
A compromised server may carry persistence mechanisms that survive reboots, credentials copied from configuration files, modified services, additional access paths, or processes that only activate when nobody is watching.
Credentials found on a server rarely stay on that server. Database passwords, cloud API keys and deployment tokens are often reusable elsewhere in your infrastructure, which is why scope matters as much as cleanup.
The goal of incident response is to determine what actually happened, establish how far it reached, and then choose the safest recovery strategy based on evidence rather than assumption.
Questions we work to answer
- How did they get in?
- When did it start?
- What did they touch?
- Is anything still running?
- What credentials were exposed?
- Can this system be trusted again?
Technical approach
What an Investigation Looks At
A structured review of the areas where compromises hide and leave evidence.
Processes & services
What is running, under which account, started by what, and whether it belongs there.
Users & SSH keys
Accounts, authorised keys, sudo rights and authentication history across the system.
Persistence mechanisms
Service units, cron and timer entries, shell profiles, preloaded libraries and startup hooks.
Network connections
Listening services, established connections and outbound destinations that need explaining.
Containers
Docker configuration, exposed sockets, mounted host paths, privileged flags and image provenance.
Logs & timeline
Authentication records, service logs and file timestamps, assembled into a timeline of events.
File integrity
Modified binaries, unexpected files in system paths and packages that no longer match their source.
System configuration
Firewall rules, exposed services, patch status and settings that widen the attack surface.
Honest limitations
What We Don't Promise
Security work attracts overclaiming. Here's what we will not tell you.
We don't promise every server can be cleaned
Some compromises go deep enough that no amount of cleaning produces a system you should trust again. When that is the case, we say so.
Rebuilding is sometimes the safer choice
For deeply compromised systems, rebuilding from a known-good image is often safer and faster than attempting to clean the existing one. We will recommend it when it is the right call.
We never ask for your passwords or private keys
Not through the contact form, not by email. If secure access is needed later, we will provide instructions for sharing it safely.
We don't guarantee a specific recovery time
Recovery depends on your backups, your architecture and the extent of the compromise. We will give you a realistic estimate once we understand the situation.
The 1-hour target is the initial response
It means a real reply from someone who has read your incident details. It is not a promise of resolution, recovery or removal within that hour.
Pricing
Transparent From the Start
Initial assessment
from €149
Emergency response pricing depends on the incident complexity. Complex incidents may require a custom quote — we'll agree scope and cost with you before any substantial work begins.
FAQ
Common Questions
Straight answers to what people ask us when a server is compromised.
My Linux server was hacked. What should I do first?
Decide first whether the system is causing active harm — sending spam, attacking others, or leaking data. If it is, containment such as isolating it at the network level is usually the priority. If it is not, avoid making changes: rebooting, deleting files or reinstalling packages can destroy the evidence needed to understand what happened. Submit the incident details and we will advise on the safest next step.
Can you remove malware from my VPS?
In many cases, yes. We identify the malicious components and the persistence mechanisms keeping them alive, and remove them where it is safe to do so. For deeply compromised systems we will tell you honestly when rebuilding from a known-good image is the safer choice.
Can you remove XMRig?
Yes, and we treat the miner as the symptom rather than the problem. Stopping the process is straightforward; the important work is finding how it got there and closing that path, so it does not return within days.
Can you investigate an SSH compromise?
Yes. We review authorised keys across every account, authentication logs, sudo activity and the SSH daemon configuration, then remove unauthorised access and re-establish access on terms you control.
Can you clean a Docker server?
Yes. We review container configuration, exposed sockets, mounted host paths, privileged flags and image provenance, and assess whether the incident stayed inside the container boundary or reached the host.
Do I need to give you root access?
Not to start. Submit the form with whatever information you have. If hands-on access becomes necessary, we will agree the method with you first and provide secure instructions at that point. Never send credentials through the form or by email.
Should I reboot my server?
Usually not before an investigation. A reboot can clear volatile evidence such as running processes and open network connections, and some malicious software is specifically designed to survive it. The exception is when the system is causing immediate harm or data loss.
Can you guarantee the server is clean?
No, and we will not claim otherwise. Nobody can prove the absence of every possible backdoor on a system that has been compromised. We can tell you what we found, what we removed and how much confidence the evidence supports — and when that confidence is not high enough, we will recommend a rebuild.
How quickly will you respond?
Our target is an initial response within 1 hour of receiving your request. That is the first response — a real reply from someone who has read your details — not a resolution time.
How much does it cost?
An initial assessment starts from €149. Final cost depends on the complexity of the incident, and complex cases may require a custom quote. We will agree scope and cost with you before any substantial work begins.
Do I need to send my password?
No. Never send passwords, private SSH keys, API tokens, cloud credentials or database passwords through the form or by email. If secure access is needed later, we will provide instructions for sharing it safely.
What happens after I submit the form?
You receive an automatic confirmation email immediately. We then review your details and reply personally, with an initial response target of within 1 hour, covering our reading of the situation, what we need from you and the recommended next step.
Think your server has been compromised?
Tell us what happened. We'll review your request and provide an initial response within 1 hour.