Latest News & Blog

Google's deceptive website ahead error screen

What To Do When Your Website Has Been Hacked

Finding out that your website has been hacked is stressful, but the worst thing you can do is panic and start deleting things at random. A rushed response can remove useful evidence, break the website further or leave the real entry point untouched, allowing the same problem to come straight back. So what should you do? Do not panic, inform yourself on all the options to get it solved, or get in touch for professional help.

Get Help With a Hacked Website

Key Takeaways

  • Confirm the hack before making major changes. Redirects, downtime and login problems can sometimes have other technical causes.
  • Secure every account connected to the website, not only the CMS login.
  • Preserve a copy of the compromised site before cleanup so useful evidence isn’t destroyed.
  • Removing malware isn’t enough. You also need to identify and close the vulnerability that allowed the compromise.
  • Check Google Search Console and search visibility after cleanup because hacked content can remain visible after the site itself has been fixed.
  • Backups, updates, monitoring and stronger access controls are important after recovery to reduce the chance of reinfection.

Step 1: Confirm That the Website Has Actually Been Hacked

Start by establishing what you’re dealing with.

Common signs include:

  • unexpected redirects
  • browser security warnings
  • spam pages appearing in Google
  • unknown administrator accounts
  • unfamiliar pop-ups or content
  • files nobody on your team created
  • Search Console security alerts
  • email or domain blacklisting

A slow website or broken page alone doesn’t necessarily mean you’ve been hacked. Hosting problems, software conflicts and normal technical faults can produce similar symptoms.

If you’re still trying to establish what has happened, the signs that a WordPress site has been hacked can help separate a likely compromise from an ordinary website problem.

Step 2: Capture What You Can See

Before you start changing things, document the problem.

Take screenshots of:

  • browser warnings
  • unexpected redirects
  • spam pages
  • unusual WordPress users
  • Search Console alerts
  • changed content
  • anything else that looks suspicious

Record the affected URLs and roughly when you first noticed the issue.

This can help your developer, hosting provider or security team understand the compromise. It may also be useful if you need to communicate with customers, insurers, payment providers or other third parties later.

Step 3: Contact Your Hosting Provider

Your hosting provider may already have information you can’t see from inside the CMS.

Ask whether they have detected:

  • malware or suspicious files
  • abnormal traffic
  • unusual server resource usage
  • changes to server files
  • suspicious scheduled tasks
  • large volumes of outgoing email

Ask them to review relevant server logs as well.

If multiple websites sit under the same hosting account, establish whether the compromise affects only one website or the wider account.

Step 4: Secure Every Access Point

Don’t only change the WordPress password.

A website can be accessed through several different systems, including:

  • WordPress or another CMS
  • hosting control panels
  • FTP, SFTP or SSH
  • database accounts
  • domain registrar accounts
  • business email
  • CDN and DNS services
  • payment gateways
  • forms and other third-party integrations

Use new, unique passwords and enable multi-factor authentication wherever it is available.

Review administrator and privileged users too. Remove or disable accounts nobody recognises, but record useful details first if they may help the investigation.

If you suspect that a computer used to administer the website may itself be compromised, secure that device as well. Otherwise newly changed credentials can simply be stolen again.

Step 5: Preserve a Backup Before Cleanup

Create a complete copy of the compromised website before cleaning it.

This isn’t necessarily the version you’re going to restore.

The point is to preserve the affected files and database so you can investigate what changed, identify suspicious code and avoid destroying evidence before you understand the problem.

Store the compromised backup securely and clearly label it so nobody accidentally restores it to the live site later.

For WordPress, the backup should normally include:

  • the database
  • WordPress files
  • plugins
  • themes
  • media uploads
  • configuration files
  • custom code

Step 6: Decide Whether the Website Should Go Offline

Not every compromised website needs to be shut down immediately.

The decision depends on what the site is doing and the risk to visitors.

Restrict access or take the site offline if it is:

  • serving malware
  • redirecting visitors to harmful websites
  • hosting phishing pages
  • collecting sensitive information through compromised forms
  • delivering malicious downloads

If the issue is contained and visitors aren’t actively at risk, your developer or host may be able to clean the website while it remains online.

The goal isn’t to create unnecessary downtime. It’s to stop the compromised site from harming users while it is being repaired.

Get Help With a Hacked Website

Step 7: Investigate Files, Database, Users and Scheduled Tasks

A proper investigation needs to go beyond the most obvious malicious file.

Depending on the site, check:

  • CMS core files
  • plugins and extensions
  • themes and templates
  • upload directories
  • database tables
  • administrator accounts
  • configuration files
  • server rules such as .htaccess
  • cron jobs and scheduled tasks
  • recently installed software

Look for recently modified files, injected scripts, spam links, unfamiliar PHP files, backdoors, hidden administrator accounts and tasks that may recreate malware after it is removed.

This is where many rushed DIY cleanups fail. Removing what you can see doesn’t necessarily remove what is maintaining access.

Step 8: Remove the Malware and Restore Clean Files

Once the compromise has been identified, remove malicious code, spam pages, rogue files, injected database content and unauthorised accounts.

Modified WordPress core files should generally be replaced with known clean versions rather than manually trying to edit malicious code out of them.

If you have a verified clean backup from before the attack, restoring it may form part of the recovery process.

But don’t simply restore yesterday’s backup and consider the job finished.

If the same vulnerable plugin, stolen credential or backdoor remains available, the restored website can be compromised again.

When the incident involves database injections, multiple backdoors, server-level malware or repeated reinfection, professional hacked website repair can be considerably safer than trying to identify every malicious component by trial and error. eCBD handles compromised WordPress and MODX websites and focuses on both cleaning the infection and identifying the route back in.

Step 9: Fix the Vulnerability That Allowed the Hack

A website isn’t properly fixed until the entry point is closed.

Common causes include:

  • outdated plugins or themes
  • abandoned software
  • weak or reused passwords
  • compromised administrator accounts
  • poor hosting security
  • stolen credentials
  • unsafe custom code
  • incorrect file permissions

Update supported software, remove anything that is no longer needed, replace abandoned plugins or themes and review user permissions.

A reputable WordPress security plugin can add useful monitoring and protection after cleanup, but it shouldn’t be used as a substitute for finding the original vulnerability.

Step 10: Check Google, SEO and Indexed Pages

Cleaning the website doesn’t necessarily clean up Google immediately.

A hack may have generated spam URLs, changed page titles, injected hidden links or triggered browser and search warnings.

After the technical cleanup:

  • check Google Search Console’s Security Issues report
  • check Manual Actions separately
  • review indexing reports for unexpected URLs
  • look for unfamiliar titles and descriptions in search
  • remove hacked URLs from XML sitemaps
  • make sure legitimate pages still return the correct status codes

Hacked URLs that no longer exist should normally return an appropriate 404 or 410 rather than all being redirected to your homepage or another important page.

If Google reports a security issue and offers a review process, request the review only after the site has been fully cleaned and the vulnerability has been fixed.

The wider relationship between compromised content, Google warnings and lost search visibility is covered naturally in how website hacks affect SEO.

Step 11: Assess Whether Customer Data Was Affected

If the website processes customer accounts, forms, orders, personal information or payment-related data, establish whether any of that information may have been exposed.

Don’t make assumptions either way until the incident has been properly investigated.

Depending on the nature of the information and where your business operates, you may need legal, privacy or cyber-security advice about notification obligations.

If customers need to be contacted, explain what is known, what action has been taken and what they should do next without speculating beyond the evidence.

Step 12: Put Prevention in Place After Recovery

Once the website is clean, the job shifts from incident response to preventing a repeat.

At minimum:

  • keep your CMS, plugins and themes current
  • use unique passwords and MFA
  • limit administrator access
  • remove software you no longer need
  • maintain off-site backups
  • test that important backups can actually be restored
  • monitor uptime and suspicious changes
  • review users and logs periodically

A managed website maintenance plan can take care of recurring updates, backups and monitoring, which is particularly useful when the website is an important source of enquiries or revenue.

When Does a Hacked Website Need Professional Help?

Not every security problem requires a specialist.

If you have a clean backup, understand the cause and are comfortable working with the underlying files and database, you may be able to handle a straightforward incident internally.

Professional help makes more sense when:

  • malware keeps returning after cleanup
  • you find multiple backdoors
  • the database contains injected content
  • server files or scheduled tasks have been compromised
  • Google or browsers are warning visitors away
  • customer information may have been exposed
  • you don’t know how the attacker gained access
  • the website is business-critical and downtime is costly

The aim isn’t simply to get the homepage looking normal again. It’s to be confident that the site is clean, the access route has been closed and the same infection isn’t going to return a few days later.

If you’re dealing with an active incident and aren’t sure how deep the compromise goes, contact eCBD and we can assess what is happening before unnecessary changes make the recovery harder.

Get Help With a Hacked Website

Frequently Asked Questions

What Should I Do First If My Website Has Been Hacked?

Confirm the problem, document what you’re seeing, contact your host and secure important administrator accounts. Preserve a copy of the affected site before starting a major cleanup so useful evidence isn’t destroyed.

Is Restoring a Backup Enough to Fix a Hacked Website?

Usually not. A clean backup can restore files and data, but if the vulnerability that allowed the hack remains open, the site can simply be compromised again. The cause of the breach also needs to be identified and fixed.

Should I Take a Hacked Website Offline?

Take it offline or restrict access when it is actively serving malware, phishing content, malicious redirects or compromised forms. If users aren’t at immediate risk, a developer may be able to clean the site while it remains available.

How Do I Remove a Google Security Warning?

Clean the website thoroughly, remove the harmful content and fix the vulnerability first. Then use the Security Issues report in Google Search Console to request a review where Google provides that option.

Can a Website Hack Affect SEO?

Yes. Hacked sites can generate spam pages, hidden links, malicious redirects, browser warnings and indexing problems. Those issues can reduce organic visibility, clicks and enquiries even after the visible infection has been removed.

How Do I Stop My Website Being Hacked Again?

Keep supported software updated, use strong unique credentials and MFA, limit administrator access, maintain off-site backups and monitor the site for unusual behaviour. Most importantly, make sure the vulnerability responsible for the original compromise has actually been closed.

Connect with us

Keep in the loop or engage with us via

Acknowledgement of Country

We respectfully acknowledge the people of the Yugambeh language region, the traditional owners of the land on which we stand, and pay our respect to their elders past and present, and all Aboriginal and Torres Strait Islander Peoples who now live in the local area.

Go to top