Repairing a hacked small-business website commonly costs $300 to $1,000 for a contained compromise with usable clean backups and full administrative access. A complex incident involving persistent access, unknown changes, several systems, sensitive data, or an outdated platform may cost $1,000–$3,000. Rebuilding from a known-clean foundation may cost $2,000–$6,000 or more.

These planning ranges use Vertinus's published rate of $49.99 per hour. No responsible provider can quote cleanup reliably from a screenshot alone. The work depends on the affected systems, access, evidence, backups, persistence, data exposure, platform condition, and business obligations.

Quick answer: 2–6 hours of urgent triage is about $100–$300; 6–20 hours for contained cleanup is about $300–$1,000; 20–60 hours for a complex incident is about $1,000–$3,000.

Typical hacked-site recovery price ranges

Urgent triage and containment: 2–6 hours

Estimated Vertinus cost: $99.98–$299.94.

This may include confirming signs of compromise, preserving available evidence, restricting dangerous access, coordinating a maintenance page, checking backups, identifying affected accounts, and defining the immediate recovery path.

Contained cleanup and hardening: 6–20 hours

Estimated Vertinus cost: $299.94–$999.80.

This range may fit one website with known access, recent clean backups, an identifiable vulnerable plugin or credential, limited malicious changes, and no evidence that other business systems were affected.

Complex investigation and recovery: 20–60 hours

Estimated Vertinus cost: $999.80–$2,999.40.

This range can apply to persistent reinfection, unknown entry, several administrator accounts, modified databases, malicious redirects, spam pages, search warnings, compromised email, shared hosting, unavailable backups, or extensive outdated components.

Clean rebuild and migration: 40–120+ hours

Estimated Vertinus cost: $1,999.60–$5,998.80 or more.

A rebuild may be safer when the platform is unsupported, integrity cannot be established, backups are contaminated, malicious changes are widespread, or the old theme and plugin stack would remain a continuing liability.

Do these things before ordinary website edits

If compromise is active or suspected:

  • Contact the hosting provider and the person responsible for incident response.
  • Preserve available logs, backups, timestamps, warnings, and suspicious files before destroying evidence.
  • Restrict access or place the site in a controlled maintenance state when continuing operation creates harm.
  • Use a known-clean device to secure hosting, registrar, domain, email, administrator, deployment, and related accounts.
  • Do not reuse potentially exposed passwords or restore an unverified backup over the only available evidence.
  • Identify what information the site stores, transmits, or can access.
  • Escalate suspected personal, payment, employee, health, or other sensitive-data exposure to qualified legal, privacy, insurance, and security advisers.

Emergency action depends on the incident. A developer can help with website containment and recovery, but broader compromise may require a specialized incident-response firm, hosting provider, payment provider, counsel, insurer, or law enforcement.

The ten biggest cost drivers

1. Scope of affected systems

One isolated website is simpler than compromise involving hosting control panels, domain accounts, email, repositories, deployment keys, customer databases, payment scripts, backups, or employee devices.

2. Quality of logs and evidence

Access, application, audit, deployment, file-change, and security logs can help identify timing and scope. Missing or short-retention logs increase uncertainty.

3. Known-clean backups

A verified backup from before the compromise can accelerate recovery. A backup taken after intrusion may preserve malicious code or accounts and must not be assumed clean.

4. Platform condition

A maintained static or custom site is easier to verify than an outdated content-management system with many themes, plugins, shared accounts, writable files, and unknown customizations.

5. Persistence

Attackers may add accounts, scheduled jobs, hidden files, database content, redirect rules, deployment credentials, or external loaders. Removing the visible spam page may not remove continued access.

6. Data sensitivity

A brochure site with a contact form has different consequences from a site holding accounts, applications, orders, payment flows, employee records, health information, or uploaded documents.

7. Search and reputation effects

Malicious pages, redirects, spam links, altered metadata, browser warnings, or search-engine security notices can require URL inventory, cleanup, verification, sitemap work, and monitoring after recovery.

8. Access ownership

Recovery slows when the business lacks registrar, DNS, hosting, repository, database, email, administrator, analytics, or search-console access.

9. Availability requirements

A site that can remain offline during investigation is easier to control than a booking, portal, ordering, or support system that the business needs continuously.

10. Required assurance

A best-effort cleanup differs from formal forensic investigation, evidence handling, malware analysis, regulated reporting, penetration testing, or an independent security assessment.

Three example estimates

Example 1: vulnerable plugin and spam redirect

A small WordPress site redirects some visitors to spam. Hosting access and a clean backup are available. One abandoned plugin appears to be the entry point, and the site stores only ordinary contact-form submissions.

  • Triage, evidence, and containment: 2–4 hours
  • Clean restore or verified cleanup: 4–8 hours
  • Accounts, updates, and hardening: 3–6 hours
  • Testing, search checks, and monitoring setup: 2–5 hours

Planning total: 11–23 hours, or about $550–$1,150.

Example 2: persistent reinfection

A content-management site has hidden administrator accounts, modified theme files, database spam, scheduled reinfection, weak hosting credentials, and no clearly dated clean backup.

  • Containment and scope review: 5–10 hours
  • File, database, account, and persistence cleanup: 12–28 hours
  • Platform, credentials, and deployment hardening: 8–18 hours
  • Functional, search, and recurrence testing: 5–12 hours

Planning total: 30–68 hours, or about $1,500–$3,399.

Example 3: clean rebuild of an obsolete site

An eight-page business site is compromised, unsupported, and difficult to verify. The business will preserve clean content and media, replace the platform, rebuild forms, map URLs, and move to controlled hosting.

  • Evidence, content, and URL inventory: 8–16 hours
  • Clean design and development: 28–50 hours
  • Content migration, forms, and redirects: 12–25 hours
  • Security, functional, search, and launch testing: 10–20 hours

Planning total: 58–111 hours, or about $2,899–$5,549.

These examples illustrate likely scope. They are not forensic conclusions or quotes for an unseen incident.

Cleanup is not just deleting malicious files

A recovery should address containment, scope, entry point, persistence, credentials, clean restoration or repair, platform updates, functional verification, data exposure review, monitoring, and lessons learned.

CISA incident-response guidance distinguishes containment, eradication, and recovery. Returning a system to operation before removing access or understanding the affected scope can lead to reinfection.

The guide on signs a website has been hacked explains common symptoms and immediate business actions.

When restoring a backup is appropriate

A backup helps when it predates the compromise, its integrity is reasonably established, the initial vulnerability or exposed credential is addressed, and required recent business data can be reconciled.

Restoring without correcting the entry point can recreate the compromise. Restoring an infected backup can preserve it. Overwriting the current system prematurely can destroy evidence needed to determine scope.

Keep separate protected copies as appropriate and document which source was restored.

What happens after the site returns

Monitor authentication, file changes, traffic, redirects, scheduled jobs, outgoing mail, search coverage, security warnings, form delivery, and external requests for recurrence.

Rotate relevant credentials, remove unused accounts, update or replace vulnerable components, verify backups, document recovery, and assign responsibility for routine maintenance.

The small-business website security guide covers ownership, updates, passwords, backups, and recovery preparation.

What a good repair estimate should include

  • Affected systems and the initial evidence available.
  • Immediate containment and business-continuity assumptions.
  • Access, logs, backups, accounts, data, and platform condition.
  • Investigation depth and stated limitations.
  • Cleanup, restoration, rebuild, credential, and update work.
  • Functional, search, security, and recurrence testing.
  • Monitoring, documentation, handoff, and ongoing maintenance.
  • Estimated hours, rate, third-party costs, exclusions, and escalation conditions.

Vertinus provides written scope and estimated hours when the situation allows. Emergency work may begin with a small approved triage boundary because the full scope is unknown until evidence is reviewed.

What Vertinus needs for initial triage

Send the public URL, the symptoms and first observed time, platform and hosting provider if known, current business impact, whether customer accounts or sensitive data are involved, and whether backups and administrator access exist.

Do not send passwords, recovery codes, database exports, malware files, payment-card information, or unnecessary personal data through the inquiry form. Vertinus can arrange an appropriate secure handoff after reviewing the initial message.

Price safe recovery, not cosmetic cleanup

Hacked-site repair commonly costs $300–$1,000 for a contained small-business incident. Complex compromise can cost $1,000–$3,000, and an obsolete or unverifiable platform may be safer to rebuild.

Send Vertinus the website URL, symptoms, and current business impact. We will recommend the smallest safe triage step and identify when specialized incident-response or legal help is also necessary.