Get started
Security

Website Hacked? What to Do in the First Hour

A calm, ordered response to a hacked website: how to spot it, what to do in the first hour, why a restore alone is not enough, and how to stop it happening again.

WebXSentry guide: what to do in the first hour after a website hack

Discovering that your website has been hacked is stressful, but the first hour matters most, and a calm, ordered response limits the damage. This guide walks through what to do, in order. It is general guidance; if customer data may have been exposed, also speak to a professional about your legal duties.

Signs your site may be compromised

  • Google shows a "This site may be hacked" or "Deceptive site ahead" warning
  • Your pages redirect to unfamiliar sites, or show spam or foreign-language content
  • New admin users appear that you did not create
  • Your host suspends the account or emails you about malware
  • Visitors report pop-ups, or email from your domain starts landing in spam
  • The site suddenly slows down or goes offline

The first hour, step by step

1. Do not panic-delete anything

Deleting files, or the whole site, destroys evidence you need to find out how the attacker got in, and you may remove the clean backup you need. Take notes on what you see instead, with screenshots and times.

2. Contain it

If visitors are at risk (redirects, fake pages, stolen card details), put the site into maintenance mode or ask your host to take it offline briefly. A short outage costs less than sending customers to a malicious page.

3. Change every password, from a clean device

Use a computer you trust that is free of malware. Change the passwords for your hosting account, website admin users, database, FTP or SFTP, the email accounts tied to the site and your domain registrar. Turn on two-factor authentication wherever it is offered.

4. Tell your host

Hosts see this every day. They can often identify infected files, tell you when the compromise began, and may hold server-side backups from before it happened.

5. Find a clean backup

Locate the most recent backup from before the compromise. Keep the infected copy in a separate place for investigation. Restoring a clean backup is often faster than cleaning by hand, but only if the hole that let the attacker in is also closed.

6. Find and close the way in

Attackers usually get in through an outdated plugin or theme, a weak or reused password, or a vulnerability in old custom code. If you restore or clean without patching, the site is usually reinfected within days. Update everything, delete unused plugins and themes, and remove admin users you do not recognise.

7. Look for backdoors

Hackers often leave hidden files that let them come back. Scan the files and the database, look for files modified around the time of the incident, and check for scheduled tasks and unfamiliar code in core files.

8. Ask Google to review the site

If Google flagged the site, fix it first, then request a review in Google Search Console. Warnings are removed after the review passes, which can take from hours to a few days.

9. Tell the people affected

If customer information may have been exposed, notify the people affected. The rules differ by country and region, so get advice on what you must do and by when.

What not to do

  • Do not delete files at random. You may remove evidence and still leave the way in open.
  • Do not restore a backup straight away. If it was taken after the infection it brings the problem back.
  • Do not log in from a device you think may be infected. Use a clean computer.
  • Do not ignore the warning. A flagged site loses visitors every hour it stays that way.
  • Do not pay anyone who promises a fix without looking at the site first.

How to tell the clean-up worked

  1. The browser warning is gone, or a review of the flag has been requested.
  2. Scans of the files and database come back clean.
  3. No unknown admin users remain, and every password has been changed.
  4. The plugin, theme or password that let the attacker in has been dealt with.
  5. You have a written record of what was found and what was changed.

What to tell your customers

If customer details may have been exposed, be prompt and plain. Say what happened, what you have done, what they should do (such as changing a password) and how to reach you. Keep it short, avoid blaming anyone and do not guess about things you do not yet know. If you are unsure of your legal duties, ask a qualified adviser before you publish anything.

What to keep for the record

  • Screenshots of the warnings or odd pages, with dates.
  • The date and time you first noticed the problem.
  • The names of everyone who had access to the site.
  • The report from whoever cleaned the site.

Preventing the next one

  • Keep software, plugins and themes updated, and remove what you do not use
  • Use a firewall and scheduled malware scans
  • Give each person their own login, with two-factor authentication
  • Keep backups away from the web server, and test restores
  • Monitor uptime so a problem is noticed in minutes, not days

When to call for help

If you are not sure what you are looking at, or the site is your main source of income, getting a specialist involved early is cheaper than a second infection. WebXSentry's Emergency Recovery is a one-time $399 engagement with no plan and no contract: malware cleanup, blacklist delisting, hardening and a written incident report. If you start a plan within 30 days, $199 is credited against your first three months.

Keep reading

Add-ons

Fixes related to this guide

Fixed-price add-ons, bought separately from a plan.

Security

WordPress Security Optimisation Service

One-time deep security hardening for your WordPress or WooCommerce website

$99 per site, one-time

Security

Website Firewall Hardening Service (WAF Setup)

One-time WAF setup on Cloudflare Pro that blocks attacks before they reach your website

$249 per site, one-time

Speed and search

WordPress Speed Optimisation Service

Faster pages on mobile and desktop: caching, image, database and render-blocking fixes, with a before and after PageSpee...

$149 per site, one-time

See all add-ons

Straight answers

Questions this article answers

Should I take my website offline if it is hacked?

If visitors are being redirected, shown malicious pages or having data captured, yes, briefly. Maintenance mode or a host-level suspension limits harm while you investigate.

Can I just restore a backup?

Often, but only a backup from before the compromise, and only after the way in is closed. Otherwise the site is usually hacked again within days.

How long does Google take to remove a hacked warning?

After you fix the site and request a review in Search Console, it commonly takes from a few hours to a few days.

Website care for businesses in every country

This guide applies wherever your business is. Pick your country to see how we work with your time zone.

All countries and time zones

Want someone to look after your website?

Pick a plan and a real person takes over the updates, security and backups, with hours for the changes you ask for. Month to month, and a 30-day money-back guarantee.

  • From $99/mo with hours included
  • Month to month
  • 30-day money-back guarantee
From $99/mo · hours included See plans