We run a small-scale e-commerce site based in Germany selling spare parts for commercial kitchen equipment. We turn over around 12,000 euros a month and get about 400 unique visitors a day. Two days ago, two different customers told us they were redirected to a weird betting-style page when accessing the site from mobile. I tested it multiple times on desktop from my own computers, and there is no redirect or any sign of weird behavior.
At the same time, I noticed CPU usage suddenly maxing out in the server control panel, and I got an automated warning from our hosting provider about 1,500 suspicious outgoing emails sent from the server. Last week, an update for our form plugin failed halfway through and threw a database error; we've been having minor glitches ever since.
Right now I can't quite tell: Is this just a technical glitch caused by the broken plugin getting stuck in a loop, or did someone actually breach the system and inject malicious code into the files? Before shelling out 800-1000 euros to a security firm for an audit, is there a concrete way we can verify this ourselves and manually tell a hack apart from a software conflict?