Site down, hacked, or disappearing from search? Call (754) 302-4631
sosSTEVIE Start with the Diagnostic

Who Is Stevie, and Why Should I Trust Him With My Website?

Two years ago I lost my own business to a hack I couldn’t see. What happened, what it taught me, and how a panicked client’s text message became my name.

The story

The phone didn’t ring on a Tuesday. That happens. It didn’t ring much on the Wednesday either, and by the Friday I’d started telling myself it was the season.

It went on like that for a few weeks. Nothing dramatic. No alert, no ransom note, no defaced homepage with a flag on it. I opened my site every morning and it looked exactly the way it had always looked. Same pages, same photos, same everything. I had no reason to think anything was wrong except that the work had stopped arriving.

When I finally went looking properly — not at the site, at what Google thought the site was — I found tens of thousands of pages I had never written. Casinos. Pharmaceuticals. Mail-order brides. Someone had made himself primary administrator months earlier and quietly built an entire second website inside mine, invisible to me and perfectly visible to search engines.

I took the whole thing down. Not repaired — down. And then I sat there and did the arithmetic on how long it had been running while I congratulated myself on how clean my homepage looked.

Here’s the direct answer

Stevie is Jacques Schinazi, the developer behind sosSTEVIE — a one-person practice that rescues, rebuilds and maintains small-business websites. The reason to trust him with a broken site is that he’s been on the receiving end of one. In 2024 his own website was taken over by a spammer who built tens of thousands of hidden pages beneath it, and it cost him the business before he noticed.

Key Takeaways

  • A compromised website usually looks completely normal to its owner. That’s the point of a good compromise — the attacker needs the site working, not broken.
  • The damage isn’t vandalism. It’s your domain being quietly rented out to somebody else’s business.
  • Most owners find out the way I did: from the silence, months late, by which time the ranking loss has compounded.
  • Nothing I sell is theoretical. Every service on this site exists because a version of it would have saved me.
  • The name came from a client, not a marketing workshop — and it came nine years before I needed it myself.

Where the name came from

I have a French name. Jacques. In fifteen years of doing this in the States I’ve heard it pronounced correctly maybe half the time, and I stopped correcting people a long while ago.

One client never got near it. He’d try, give up, and land somewhere else entirely every time. Then one night his site went down — properly down, mid-campaign, the kind of down where you can hear him doing the arithmetic on what every hour is costing him — and he didn’t attempt my name at all.

The text just said: SOS STEVIE.

I fixed his site. The name stuck — first as a joke between the two of us, then as what half his referrals called me, and eventually as the only thing anybody could remember. In May 2015 I registered sosstevie.com, because by then it was simply what people called me when something was on fire.

That’s the part I’d rather you noticed. I spent nine years trading under a name that promised emergency rescue before I became the emergency myself. The registration date is public and you’re welcome to check it. I didn’t build this brand after the disaster to explain the disaster — the name was already on the door when the disaster arrived, which is a considerably less comfortable thing to admit.

You cannot tell by looking

This is the part I want anyone reading to take away, even if they never contact me.

Your website has two audiences and you only ever see one of them. You see the site your browser renders when you, a logged-in administrator on a familiar device, type your own domain. Search engines see something assembled differently — different pages served to different visitors, redirects that only fire for traffic arriving from search, content that appears for a crawler and vanishes for you.

A competent attacker is not trying to break your website. He needs it up. He needs it fast, indexed, and trusted, because he’s borrowing the reputation you spent years building to rank pages he could never rank on a domain of his own. Breaking it would destroy the only thing he came for.

So the symptom isn’t a broken site. The symptom is silence. Enquiries thin out. Rankings for your actual services slide. Someone mentions they couldn’t find you and you assume they typed it wrong.

The cost of doing nothing here isn’t a repair bill. It’s every month of trading you lose before you notice, plus however long it takes to earn back the trust the domain lost while it was hosting somebody else’s casino.

Why this is worse now than it was when it happened to me

Two things have moved, and neither has moved in your favour.

The number of ways in keeps climbing. Patchstack’s State of WordPress Security in 2026 recorded 11,334 new vulnerabilities across the WordPress ecosystem during 2025 — a 42% increase on the previous year, with 91% of them found in plugins rather than in WordPress itself. Read that carefully, because it’s routinely misquoted: it counts holes discovered, not sites broken into. Most never touch you. What it tells you is where the risk concentrates — in third-party code you installed once and stopped thinking about.

Nobody finds these things quickly. IBM’s Cost of a Data Breach Report 2025 puts the average breach lifecycle at 241 days — 181 to identify, 60 to contain — and that was the lowest figure in nine years. That’s enterprise data, from organisations with security teams and budgets, and I’m not going to pretend it maps cleanly onto a small business website. It doesn’t. But if companies with a security operations centre take six months to notice, the honest expectation for a small business with no monitoring at all is longer, not shorter.

That’s the gap I lost a business inside. Not a dramatic gap. A boring one, made of months.

The Four Moves of a Silent Compromise

This is the shape of what happened to me, and of nearly every injection I’ve cleaned up since. It’s the same four moves almost every time.

1. The way in. An outdated plugin, an abandoned theme, a reused password, or a stale administrator account belonging to a developer who left years ago. Rarely anything clever. Almost always something ordinary that nobody had looked at in a long time.

2. Persistence. Before doing anything visible, the attacker makes sure he can get back in — a second admin user, a backdoor in a theme file, a scheduled task that recreates both if you delete them. This is why a surface clean-up so often “fails” a fortnight later. The pages come back because the door was never shut.

3. Publication. Now the pages appear. Thousands, sometimes tens of thousands, usually served only to search engine crawlers and to visitors arriving from search results. Log in as yourself and the site is spotless. It is genuinely spotless — for you.

4. The slide. Search engines re-evaluate what your domain is about. It’s now mostly about casinos. Your rankings for the thing you actually do decay, slowly enough that every individual week looks like normal variance. Then one day you realise the phone hasn’t rung properly since spring.

The reason I fix in a fixed order — security first, always, before anything else gets touched — is move 2. Rank a compromised site and you’re advertising for somebody else.

Six things you can check yourself this afternoon

None of this needs me. If you do only these, you’re ahead of where I was.

  1. Search site:yourdomain.com on Google. Read the page count. If it’s wildly more than the number of pages you believe you have, go through the results until you find something you didn’t write.
  2. Search site:yourdomain.com casino — then viagra, then payday. Substitute anything obviously unrelated to your business. This is the single fastest check there is and it takes ten seconds.
  3. Open Users in your admin panel and read every single account. Every administrator should be a person you can name. Delete the agency that stopped working for you years ago.
  4. Look at Google Search Console → Performance, set to 12 months. You’re looking for queries you don’t recognise and a decline that started abruptly rather than gradually.
  5. Fetch your own homepage as Googlebot (Search Console → URL Inspection → Test Live URL) and compare what it returns against what your browser shows you. A difference between those two is the whole game.
  6. Check when each plugin was last updated by its developer. Anything abandoned for over a year is an unlocked door, whether or not anyone’s used it yet.

If any of those turns up something you can’t explain, don’t start deleting. Deleting before you understand the persistence mechanism is how people spend the next month cleaning the same site four times.

Frequently Asked Questions

Can a website be hacked without looking hacked? Yes, and that’s the normal case rather than the exception. Defacement is rare because it’s pointless — an attacker injecting spam pages needs your site online, fast and trusted, since he’s borrowing your domain’s reputation to rank content he couldn’t rank himself. Breaking it would destroy the only asset he came for. The site looks perfect to you while thousands of pages you never wrote are served to search engines.

Why did my website traffic disappear without any warning? The three common causes are a technical fault that stopped search engines indexing you, a compromise that redirected your domain’s reputation to somebody else’s content, or an algorithm update you didn’t notice. They produce an identical symptom from the outside, which is precisely why guessing is expensive. The only way to tell them apart is to look — starting with security, because ranking work on a compromised site is wasted money.

What actually happened to your own website? In 2024, someone made himself primary administrator and built tens of thousands of casino, pharmaceutical and mail-order-bride pages underneath my site over a period of months. Nothing was visibly different in my browser at any point. I found out because enquiries stopped, not because of any alert. I took the site down entirely and rebuilt from nothing.

Why should I hire someone this happened to? Fair question, and it’s the right one to ask. The answer is that I had the same blind spots every other developer has, and I now know exactly which ones, because I paid for the list. I check for things I used to assume. I diagnose before quoting because I was once certain about the wrong thing for months. Experience of failure isn’t a substitute for competence, but it’s not nothing either — it’s the reason my checklist is longer than it was.

Is “Stevie” your real name? No. It’s Jacques Schinazi. Stevie is what a client called me in a late-night text message when his site went down and he couldn’t get near my French name, and it spread from there until it was simply what people used — enough that I registered sosstevie.com on the strength of it in 2015. I trade as sosSTEVIE, contracts and invoices carry the legal name, and both appear on this page so there’s nothing to be surprised by later.

What I do with it now

I don’t tell that story for sympathy. I tell it because it’s the reason the order of operations on this site is what it is, and because every owner I meet has the same reasonable and completely wrong instinct I had: my site looks fine, therefore my site is fine.

Looking fine is what a good compromise is for.

If you’ve read this far and something on the list above bothered you, the next step isn’t to hire me. It’s to run the six checks. If they come back clean, you’ve spent twenty minutes and bought yourself real peace of mind rather than assumed peace of mind.

If they don’t come back clean, or if you’d rather someone looked properly:

Start with the SOS Digital Diagnostic — $997 →

Site actively down, redirecting, or serving pages you didn’t write? Don’t book anything — call (754) 302-4631. That’s a different conversation and it starts now.