On Magento, the primary risk is payment card skimming at checkout. Every hour counts, for your customers and for your notification obligations.
The Magento price is public and fixed: €1,490 excl. VAT if your store is not compromised, €2,990 excl. VAT if it already is.
Open Source and Adobe Commerce are not supported the same way. Extended support is reserved for Adobe Commerce customers; it does not exist for Magento Open Source. An Open Source store therefore falls out of support far earlier than its operator believes, and no further patches are published for it.
It is the platform most targeted by card data theft. Code injected into the checkout is often conditional: it fires only on the payment page, for a real basket, and stays invisible to a surface scan. A store can look clean and be stealing cards for months.
Hosts exclude Magento from their cleanup offers. Major managed hosts explicitly restrict their malware removal to WordPress and WooCommerce and refer Magento merchants to third parties. In practice, you have no one to call at your host.
The technical scope is wider. Core, modules, theme, but also message queues, cron jobs, API integration tokens, admin accounts, and the database holding your orders and customer data. A partial eradication lets the attacker back in.
Confirmed compromise or false positive? Scope, exposed data, legal obligations. Engagement authorisation signed online, secure access established.
Checkout flow and third-party script analysis, core and module integrity, logs, database, admin accounts and API tokens.
Skimmer removal, credential and token rotation, strict content security policy, admin hardening, support with regulatory notifications where required.
Integrity probes and automated watch for 30 days, with an alert channel validated by a real end-to-end test.
Published rates, signed scope, best-efforts obligation stated in writing.
What is included, what is not →
Start an interventionFirst response from an engineer within 5 hours, Monday to Friday, 8am to 8pm. “Response” means talking to an engineer, not an automated acknowledgement.
Not before speaking with us. Shutting down destroys volatile evidence and does not remove persistence. We move the site into controlled maintenance instead.
You keep the diagnostic report and nothing else is billed. If you prefer, the amount paid becomes a credit towards preventive hardening.
No — and be wary of anyone who promises that. We are bound by a best-efforts obligation stated in the contract: industry standards, a defined scope, and 30 days of monitoring to verify the eradication holds.
Yes, as an option: we assemble remediation evidence in the expected format, file the review request and follow it through to removal of the flag — the same process applies to cyber insurance claims.
An engineer replies within 4 to 5 hours — within 4 hours for continuous-protection subscribers.
✉ [email protected] · [email protected]
Remote engagements across Europe — EN / FR / ES / IT / PT / PL / HU / CS