Securantis

Hacked Site Response

Providing Access After Payment — Secure Procedure

How Securantis receives and uses your access only after payment via the secure client area: steps, precautions, common errors and troubleshooting.

← Back to help center

Securantis how-to guide

But

This guide explains why and how Securantis requests access to a hacked site only after receiving payment, how to provide that access securely from the client area, and what protections and verifications are performed afterwards. It applies to all supported platforms (WordPress, WooCommerce, PrestaShop).

Why this rule

  • Ensure confidentiality and traceability of interventions.
  • Avoid prematurely opening access to unauthorized third parties.
  • Enable the setup of a dedicated encrypted channel (client area) to transmit temporary credentials.

Important security principles

  • Securantis never asks for your passwords by email, message, or chat.
  • The access required for the intervention is provided only after payment, in the secure client area. The information is encrypted and recorded with access traceability.
  • Any action on malicious files (quarantine, deletion, restoration) requires a human decision by the client or authorized staff.
  • If a paid intervention requires action on your hosting, Securantis will request distinct access (FTP/SFTP, hosting panel, database) or will propose a temporary access created by you.

Prerequisites (before purchasing the intervention)

  1. Have created a client account on the Securantis site and verified your email address.
  2. Have the billing information necessary to complete the order.
  3. If possible, have administrator accounts for the CMS and hosting access to create temporary credentials (recommended but not mandatory before payment).
  4. Have performed a full backup if possible (database + files) — Securantis can assist, but the initial backup protects your data.

Steps: ordering and transmitting access

  1. Order the intervention
  • Select the service corresponding to your incident (platform WordPress / WooCommerce / PrestaShop).
  • Complete the order form: site URL, hosting provider, observed symptoms, availability and preferences.
  • Confirm and pay via the secure payment flow offered (cards, bank transfer depending on options). Payment triggers the opening of the intervention case.
  1. Receive confirmation and instructions
  • After payment, you will receive a confirmation and a link to access your secure client area.
  • The client area contains the intervention case and a dedicated form to transmit the required access (CMS access, FTP/SFTP access, hosting panel access, database access).
  1. Create and transmit secure access (recommended)
  • Create a temporary user account with limited rights if possible (for example: temporary administrator role in the CMS, dedicated FTP/SFTP account for the intervention).
  • Note the validity period and limit the IP address if your hosting provider allows it.
  • In the client area, enter only the designated fields (URL, username, password); the client area encrypts these values and transmits them to the team after validation.
  • Never send passwords by email or insecure messaging.
  1. Validation and takeover
  • The Securantis team verifies receipt of the access, confirms availability and schedules the intervention.
  • A case manager contacts you to confirm the scope of proposed actions (quarantine, cleanups, restoration, security fixes). Any permanent deletion of files or data requires your explicit consent.

Expected outcome

  • Access transmitted via the client area and handled by the team only after payment.
  • Full traceability of accesses and actions performed as part of the intervention.
  • Intervention plan proposed and approved before any deletion or restoration.

Prudent settings and recommendations

  • Prefer creating a temporary user on your CMS rather than providing the primary account access.
  • If possible, restrict access by IP address to the intervention period.
  • Note the validity period of temporary credentials and revoke them after the intervention ends.
  • Keep a full backup before any manipulation performed by an operator.
  • Enable 2FA on administrative accounts after access restoration and case closure.

Common mistakes when transmitting access

  • Providing credentials via email or chat (do not do this) — this prevents handling: Securantis will not consider this information valid.
  • Providing an overly privileged account without justification (use a temporary administrator account if necessary).
  • Forgetting to indicate the hosting provider or the type of access required (FTP vs SFTP, cPanel vs Plesk hosting panel) — complete the form in the client area.
  • Creating a user with an unconfirmed email address — this can prevent certain notifications.

Troubleshooting if something goes wrong

  • I don't see the access form in the client area: refresh the page, log out and log back in, check that you are in the correct intervention case. If the problem persists, send a message via the client area ticket system (without credentials).
  • The site is not accessible even after I provided the access: the team will indicate connection errors (wrong FTP host, port, protocol SFTP vs FTP, hosting provider firewall). Provide the exact parameters requested in the client area.
  • I'm afraid to transmit access: request that you create a temporary account yourself and limit its duration/IP. You can also propose a "read-only" access if available — the team will tell you if this is sufficient.

Legal and operational precautions

  • Never send credentials by public or unencrypted email.
  • Keep proof of payment and of transmission via the client area: these elements constitute contractual traceability.
  • Any intrusive action (file deletion, database modification) is subject to your explicit agreement before execution.

When to contact support

Contact support via the client area if:

  • You did not receive the link to the client area after payment (also check your spam folder).
  • The access form does not display or rejects your data.
  • The team reports connection errors you do not understand.
  • You want to modify the provided access or withdraw authorization before the intervention ends.

Additional information for each platform

  • WordPress / WooCommerce: ideally provide a temporary WordPress administrator account. If the shop is critical, indicate time windows to avoid for the intervention. Mention payment plugins and custom plugins, as some fixes may require testing on a preproduction environment.
  • PrestaShop (1.7 to 9): provide a back-office account with temporary administrative rights or FTP/SFTP access to allow a complete analysis. Indicate the exact PrestaShop version and sensitive third-party modules.

Conclusion

Transmitting access after payment via the secure client area ensures confidentiality and traceability of interventions. Follow the steps above, create temporary accounts if possible and limit their scope. Securantis will not automatically delete malware: any quarantine, deletion or restoration will be submitted to you for validation. If in doubt, contact support from the client area to obtain instructions before providing access.

Cookies

We use cookies necessary for the operation of the site. With your consent, we can also use analytics and personalization cookies. Learn more.

Necessary

Essential for the site and the client area.

Active