A real engineer picks up in about 11 minutes, day or night.

My website sends visitors to a site I do not recognise.

Customers tell you your website took them somewhere strange. You check, and it looks completely normal to you. You are not going mad. This kind of attack is built to hide from the owner and show itself only to visitors on phones, or only to people who arrive from Google. Here is how to prove it in two minutes, and how we remove it today for a flat $249.

Clean or your money back. Written. Flat $249, no hourly meter.

You do not need to know what your website is built with. We will tell you in the first 10 minutes.

Last updated · Reviewed by Ali Yasin Jatoi

Tell us what your site needs

One form for every service. Maintenance, emergencies, development, migrations, speed, security and SEO. A senior engineer reads it, not a bot.

A WordPress engineer replies within 1 business hour. 150+ WordPress sites managed by founder at Pearl Lemon No card, no contract

Free. No sales pitch. If we are not the right fit, we will tell you who is.

Secure and private 30 day money back No lock in contract

Is this you?

  • A customer says your website took them to a page selling something you do not sell
  • It happens on their phone but not on your computer
  • It only happens when they click your site from Google, never when they type the address
  • It happened once, then stopped, then happened again days later
  • Your website looks perfectly fine every time you check it while logged in
  • Google results for your business show titles in another language
  • Your bounce rate collapsed or your enquiries stopped without warning

If you ticked even one of these, send us the address of your website and we will look at it for free within the hour.

Prove it in two minutes, right now

Take your phone. Open a private or incognito browsing window. Search Google for your business name, and click your own result rather than typing your address. If you land anywhere other than your own homepage, you have a redirect. Do the same on your laptop and it will very likely behave perfectly, because that is exactly what the attack is designed to do.

Why it hides from you specifically

The code checks three things before it decides whether to redirect: whether you are on a phone, whether you arrived from a search engine, and whether you are logged in as an administrator. Owners are logged in and type their address directly, so owners see a healthy website. The person doing this is not trying to annoy you, they are trying to stay unnoticed for as long as possible, because they are paid per visitor delivered.

Where it usually lives

In the sites we clean, a redirect is almost never in one place. It sits in a few files at the top level of the website, in a settings table inside the database, and often in a small hidden add on that does not appear in any normal list. Deleting the one file you can find removes it for about a day. This is the single most common reason an owner tells us the problem came back.

What this is costing while it runs

Every person Google sends you is being handed to somebody else. Google notices quickly, drops your pages, and often adds a red warning screen on top, which then also frightens the visitors who did reach you. Two weeks of this can undo two years of search visibility, and recovery is far slower than the cleanup.

What happens once you say go

  1. First 15 minutes

    We reproduce it

    We request your website the way an attacker expects a real visitor to, from a phone and from a search result, and capture exactly where it sends people.

  2. Hour 1

    Redirect off

    Full copy taken, then every place the redirect is triggered from is removed at once, files and database together, so it cannot reinstall itself.

  3. About 4 hours

    Way back in closed

    Hidden admin accounts, scheduled tasks and add ons that nobody installed are all removed, and every password is rotated.

  4. Day 1 to 30

    Search recovered

    We ask Google to review the site, clean up any spam pages already indexed, and watch for 30 days in case a second copy is still waiting.

What it costs

No quotes, no discovery calls, no hourly meter. You know the number before we touch anything.

  • Emergency cleanup
    $249 flat

    One website, one price. Median clean time about 4 hours from the moment we have access. Written report at the end.

  • Cleanup plus hardening
    $449 flat

    Everything above, plus locked down logins, file monitoring, and 60 days of reinfection cover.

  • Care plan after the fix
    $99 a month

    Updates on staging, daily backups, monitoring, and a real engineer on call so this never repeats.

Clean or your money back. Written.

Want to try it yourself first?

Two safe checks you can do before you call anyone, and one thing you should not do.

  1. 1Do the phone and private window test above, and write down the exact address it sends you to. Screenshot it. That address tells an engineer a great deal in seconds.
  2. 2Log out of your website completely, then visit it again in a private window on your laptop. If it misbehaves logged out but not logged in, that confirms the diagnosis.
  3. 3Change your hosting and website passwords from a different device before anything else, because a reused password is the most common way in.

Stop and call us if: you are being told to edit a file called .htaccess or wp-config, or to run a find and replace across the database. A careless replace in a database breaks stored settings in a way that is much harder to undo than the redirect itself.

Questions people ask us at this exact moment

Why does my website only redirect on mobile?+

Because the code reads the visitor's device and only fires for phones. Phone visitors are worth more to the people running these campaigns and are far less likely to report it. It is a deliberate choice to keep the infection alive longer, not a glitch.

Why does it only happen when I come from Google?+

The code checks where the visitor came from. Traffic from a search engine is a stranger, so it gets redirected. Traffic that typed your address is probably you or a regular, so it gets your real homepage. Same reason: stay invisible to the owner.

I deleted the file and it came back. Why?+

Because the redirect had more than one home. There is usually a copy in the database and a scheduled task that rewrites the file if it goes missing. Until all three are removed at the same time, it will keep returning within a day or two.

Will Google penalise me for this?+

Google will not punish you for being a victim, but it will stop trusting the pages while they send people elsewhere, and it may show a warning screen. Ranking damage is real and it grows with time, which is why we treat redirects as same day work rather than a queue job.

How much does it cost to remove a redirect?+

A flat $249 for a standard single website, including the report, the Google review request and 30 days of watching. If your site is a shop taking payments, we look for card stealing code at the same time and quote if it needs a deeper forensic job.

How long does it take?+

The redirect itself normally stops within the first hour. The full cleanup, meaning every way back in closed, takes about four hours from the moment we have access.

Could this be my advertising or tracking code instead?+

Occasionally, yes, and we check that first because it is free to rule out. A badly configured tracking script or an expired domain in an old plugin can look identical from the outside. If that is what it turns out to be, we tell you and you do not pay for a cleanup you did not need.

Related pages

Emergency Book a call