Discovering that your website has been hacked is stressful, but the first hour matters most, and a calm, ordered response limits the damage. This guide walks through what to do, in order. It is general guidance; if customer data may have been exposed, also speak to a professional about your legal duties.
Signs your site may be compromised
- Google shows a "This site may be hacked" or "Deceptive site ahead" warning
- Your pages redirect to unfamiliar sites, or show spam or foreign-language content
- New admin users appear that you did not create
- Your host suspends the account or emails you about malware
- Visitors report pop-ups, or email from your domain starts landing in spam
- The site suddenly slows down or goes offline
The first hour, step by step
1. Do not panic-delete anything
Deleting files, or the whole site, destroys evidence you need to find out how the attacker got in, and you may remove the clean backup you need. Take notes on what you see instead, with screenshots and times.
2. Contain it
If visitors are at risk (redirects, fake pages, stolen card details), put the site into maintenance mode or ask your host to take it offline briefly. A short outage costs less than sending customers to a malicious page.
3. Change every password, from a clean device
Use a computer you trust that is free of malware. Change the passwords for your hosting account, website admin users, database, FTP or SFTP, the email accounts tied to the site and your domain registrar. Turn on two-factor authentication wherever it is offered.
4. Tell your host
Hosts see this every day. They can often identify infected files, tell you when the compromise began, and may hold server-side backups from before it happened.
5. Find a clean backup
Locate the most recent backup from before the compromise. Keep the infected copy in a separate place for investigation. Restoring a clean backup is often faster than cleaning by hand, but only if the hole that let the attacker in is also closed.
6. Find and close the way in
Attackers usually get in through an outdated plugin or theme, a weak or reused password, or a vulnerability in old custom code. If you restore or clean without patching, the site is usually reinfected within days. Update everything, delete unused plugins and themes, and remove admin users you do not recognise.
7. Look for backdoors
Hackers often leave hidden files that let them come back. Scan the files and the database, look for files modified around the time of the incident, and check for scheduled tasks and unfamiliar code in core files.
8. Ask Google to review the site
If Google flagged the site, fix it first, then request a review in Google Search Console. Warnings are removed after the review passes, which can take from hours to a few days.
9. Tell the people affected
If customer information may have been exposed, notify the people affected. The rules differ by country and region, so get advice on what you must do and by when.
What not to do
- Do not delete files at random. You may remove evidence and still leave the way in open.
- Do not restore a backup straight away. If it was taken after the infection it brings the problem back.
- Do not log in from a device you think may be infected. Use a clean computer.
- Do not ignore the warning. A flagged site loses visitors every hour it stays that way.
- Do not pay anyone who promises a fix without looking at the site first.
How to tell the clean-up worked
- The browser warning is gone, or a review of the flag has been requested.
- Scans of the files and database come back clean.
- No unknown admin users remain, and every password has been changed.
- The plugin, theme or password that let the attacker in has been dealt with.
- You have a written record of what was found and what was changed.
What to tell your customers
If customer details may have been exposed, be prompt and plain. Say what happened, what you have done, what they should do (such as changing a password) and how to reach you. Keep it short, avoid blaming anyone and do not guess about things you do not yet know. If you are unsure of your legal duties, ask a qualified adviser before you publish anything.
What to keep for the record
- Screenshots of the warnings or odd pages, with dates.
- The date and time you first noticed the problem.
- The names of everyone who had access to the site.
- The report from whoever cleaned the site.
Preventing the next one
- Keep software, plugins and themes updated, and remove what you do not use
- Use a firewall and scheduled malware scans
- Give each person their own login, with two-factor authentication
- Keep backups away from the web server, and test restores
- Monitor uptime so a problem is noticed in minutes, not days
When to call for help
If you are not sure what you are looking at, or the site is your main source of income, getting a specialist involved early is cheaper than a second infection. WebXSentry's Emergency Recovery is a one-time $399 engagement with no plan and no contract: malware cleanup, blacklist delisting, hardening and a written incident report. If you start a plan within 30 days, $199 is credited against your first three months.