Initial response within 1 hour

My Server Got Hacked. What Now?

Emergency Linux server investigation, malware removal and security recovery.

Submit your incident details and we'll review your request and provide an initial response within 1 hour. You don't need to know exactly what's wrong.

Or email us directly at help@myserverhacked.com

Server status
SECURITY INCIDENT DETECTED
Suspicious process
DETECTED
Unknown SSH key
DETECTED
Outbound traffic
REVIEW
System integrity
INVESTIGATE
[ REQUEST EMERGENCY HELP ]

Illustrative example. This page does not scan your server.

Common symptoms

Something Isn't Right With Your Server?

These are the situations we see most often. If any of them sound familiar, it's worth investigating properly.

  • Server suddenly using 100% CPU
  • Unknown processes running as an unfamiliar user
  • Crypto miner detected by you or your provider
  • An SSH key in authorized_keys you did not add
  • Outbound traffic to addresses you cannot account for
  • Website serving content you did not publish
  • A Docker container behaving unexpectedly
  • Server became slow or unresponsive without explanation

How it works

Three Steps, Starting Right Now

No lengthy intake process. Tell us what you're seeing and we'll take it from there.

  1. 01

    Tell us what happened

    Submit the incident details with whatever information you currently have. You do not need to diagnose the problem yourself.

  2. 02

    We investigate

    We review the information and determine the safest next steps, then reply with our initial assessment and what we need from you.

  3. 03

    Recover & secure

    We investigate the incident, remove malicious persistence where possible, harden the system and provide recommendations.

Important: For deeply compromised systems, rebuilding from a known-good image may be safer than attempting to clean the existing system. We'll tell you when that's our honest recommendation.

Why it matters

A Stopped Process Is Not a Solved Incident

Killing the obvious symptom rarely ends a compromise. The question that matters is how someone got in, and what else they left behind.

A compromised server may carry persistence mechanisms that survive reboots, credentials copied from configuration files, modified services, additional access paths, or processes that only activate when nobody is watching.

Credentials found on a server rarely stay on that server. Database passwords, cloud API keys and deployment tokens are often reusable elsewhere in your infrastructure, which is why scope matters as much as cleanup.

The goal of incident response is to determine what actually happened, establish how far it reached, and then choose the safest recovery strategy based on evidence rather than assumption.

Questions we work to answer

  • How did they get in?
  • When did it start?
  • What did they touch?
  • Is anything still running?
  • What credentials were exposed?
  • Can this system be trusted again?

Technical approach

What an Investigation Looks At

A structured review of the areas where compromises hide and leave evidence.

Processes & services

What is running, under which account, started by what, and whether it belongs there.

Users & SSH keys

Accounts, authorised keys, sudo rights and authentication history across the system.

Persistence mechanisms

Service units, cron and timer entries, shell profiles, preloaded libraries and startup hooks.

Network connections

Listening services, established connections and outbound destinations that need explaining.

Containers

Docker configuration, exposed sockets, mounted host paths, privileged flags and image provenance.

Logs & timeline

Authentication records, service logs and file timestamps, assembled into a timeline of events.

File integrity

Modified binaries, unexpected files in system paths and packages that no longer match their source.

System configuration

Firewall rules, exposed services, patch status and settings that widen the attack surface.

Honest limitations

What We Don't Promise

Security work attracts overclaiming. Here's what we will not tell you.

We don't promise every server can be cleaned

Some compromises go deep enough that no amount of cleaning produces a system you should trust again. When that is the case, we say so.

Rebuilding is sometimes the safer choice

For deeply compromised systems, rebuilding from a known-good image is often safer and faster than attempting to clean the existing one. We will recommend it when it is the right call.

We never ask for your passwords or private keys

Not through the contact form, not by email. If secure access is needed later, we will provide instructions for sharing it safely.

We don't guarantee a specific recovery time

Recovery depends on your backups, your architecture and the extent of the compromise. We will give you a realistic estimate once we understand the situation.

The 1-hour target is the initial response

It means a real reply from someone who has read your incident details. It is not a promise of resolution, recovery or removal within that hour.

Pricing

Transparent From the Start

Initial assessment

from €149

Emergency response pricing depends on the incident complexity. Complex incidents may require a custom quote — we'll agree scope and cost with you before any substantial work begins.

FAQ

Common Questions

Straight answers to what people ask us when a server is compromised.

My Linux server was hacked. What should I do first?

Decide first whether the system is causing active harm — sending spam, attacking others, or leaking data. If it is, containment such as isolating it at the network level is usually the priority. If it is not, avoid making changes: rebooting, deleting files or reinstalling packages can destroy the evidence needed to understand what happened. Submit the incident details and we will advise on the safest next step.

Can you remove malware from my VPS?

In many cases, yes. We identify the malicious components and the persistence mechanisms keeping them alive, and remove them where it is safe to do so. For deeply compromised systems we will tell you honestly when rebuilding from a known-good image is the safer choice.

Can you remove XMRig?

Yes, and we treat the miner as the symptom rather than the problem. Stopping the process is straightforward; the important work is finding how it got there and closing that path, so it does not return within days.

Can you investigate an SSH compromise?

Yes. We review authorised keys across every account, authentication logs, sudo activity and the SSH daemon configuration, then remove unauthorised access and re-establish access on terms you control.

Can you clean a Docker server?

Yes. We review container configuration, exposed sockets, mounted host paths, privileged flags and image provenance, and assess whether the incident stayed inside the container boundary or reached the host.

Do I need to give you root access?

Not to start. Submit the form with whatever information you have. If hands-on access becomes necessary, we will agree the method with you first and provide secure instructions at that point. Never send credentials through the form or by email.

Should I reboot my server?

Usually not before an investigation. A reboot can clear volatile evidence such as running processes and open network connections, and some malicious software is specifically designed to survive it. The exception is when the system is causing immediate harm or data loss.

Can you guarantee the server is clean?

No, and we will not claim otherwise. Nobody can prove the absence of every possible backdoor on a system that has been compromised. We can tell you what we found, what we removed and how much confidence the evidence supports — and when that confidence is not high enough, we will recommend a rebuild.

How quickly will you respond?

Our target is an initial response within 1 hour of receiving your request. That is the first response — a real reply from someone who has read your details — not a resolution time.

How much does it cost?

An initial assessment starts from €149. Final cost depends on the complexity of the incident, and complex cases may require a custom quote. We will agree scope and cost with you before any substantial work begins.

Do I need to send my password?

No. Never send passwords, private SSH keys, API tokens, cloud credentials or database passwords through the form or by email. If secure access is needed later, we will provide instructions for sharing it safely.

What happens after I submit the form?

You receive an automatic confirmation email immediately. We then review your details and reply personally, with an initial response target of within 1 hour, covering our reading of the situation, what we need from you and the recommended next step.

Think your server has been compromised?

Tell us what happened. We'll review your request and provide an initial response within 1 hour.