Emergency guide for website owners
Your website's been hacked. Do these things, in this order.
The first hour decides whether this costs you an afternoon or a month. Most owners lose that hour deleting the evidence they need. Here's what to do instead, step by step.
Recovery from $1,750, price fixed in writing first. Updated October 8, 2026
First, breathe. Then stop clicking "delete".
It's a horrible feeling. Maybe a customer emailed you a screenshot. Maybe Google put a red warning in front of your homepage. Maybe your host just suspended the account.
Your instinct is to make it go away. Delete the strange files. Restore last night's backup. Get the site back up before anyone else notices.
That instinct is how one break-in becomes three.
Every file you delete is a clue about how they got in. And if you don't find how they got in, they come back through the same door, usually within days. Often with a better hiding place.
So go slower for one hour. Follow the steps below in order. If you get stuck, or you'd rather hand it to someone who does this every week, tell us what you're seeing.
Not sure yet?
Eight signs your website has been hacked.
Any one of these is worth taking seriously. Two or more, and you can stop wondering.
- Browsers or Google show a warning before anyone reaches your site.
- Visitors, especially on phones, get sent to scam, pill or casino pages.
- Searching
site:yourdomain.comshows pages you never wrote, often in Japanese or full of product names. - There's an admin account you don't recognize, or a familiar one with a new email address.
- Your host suspended the account for malware, phishing or sending spam.
- Customers report card fraud soon after buying from you.
- New or changed files you can't explain, often in the uploads folder or
.htaccess. - Email from your domain suddenly bounces or lands in spam.
The recovery plan
Nine steps. Do them in order.
Steps 1 to 3 are for the first hour. The rest can take a day or two to do properly. Rushing them is how sites get hacked twice.
-
First hour
Save a copy of everything before you change anything.
Download the site's files, export the database, and save the server and access logs. Ask your host for their copies too, because they may only keep logs for a few days. This copy is your evidence and your map of what the attacker changed. Keep it offline, and don't open it on the site itself.
-
First hour
Change the keys, from a clean computer.
If your own computer is infected, new passwords leak straight back to the attacker. Use a different device if you can. Then change, in this order:
- Your email account (it can reset everything else).
- Your domain registrar and DNS provider.
- Your hosting panel, SFTP or SSH, and the database password.
- Every admin login on the website itself.
Turn on two-step login wherever it's offered. Delete admin accounts you don't recognize, and cancel API keys and app passwords you didn't create.
-
First hour
Stop the damage to your visitors.
If the site is redirecting visitors, serving malware or stealing card details, put it into maintenance mode or take it offline now. A few hours of downtime is better than a few hours of infecting your customers. If you take payments, tell your payment provider. Tell your host what's happening, too. They often have tools and logs you don't.
-
Day one
Find the door they came in through.
This is the step most cleanups skip, and the reason so many sites get re-infected. Look at your logs around the time the first strange file appeared. Check every plugin, theme and piece of server software for versions with known holes. Ask who else had access: a past developer, an agency, a contractor. Until you know the way in, any cleanup is temporary.
-
Day one
Clean up, or rebuild from known-good parts.
The safest route is to restore from a backup you know was made before the break-in. If there isn't one, replace the core software, plugins and themes with fresh copies from their makers, then hunt for what's left:
- Script files in folders that should only hold images and uploads.
- Changes to
.htaccess, configuration files and scheduled tasks. - Injected links, scripts and new admin users in the database.
- Hidden users or keys on the server itself.
-
Day one
Update everything, and remove what you don't use.
Bring the CMS, every plugin and theme, PHP and the server software up to supported versions. Delete inactive plugins and themes rather than switching them off, because switched-off code can still be attacked. Close the door you found in step 4 for good.
-
Day two
Ask Google to lift the warning.
Verify your site in Google Search Console and open the Security issues report. Once the site is clean and the hole is closed, request a review and explain what you fixed. Google says phishing reviews take about a day, malware reviews a few days, and spam-hack reviews can take several weeks. Once it's confirmed clean, the warnings usually go within 72 hours. Google's guidance.
-
Day two
Work out who you have to tell.
If customer data may have been seen or copied, the law may require you to tell people. Every US state has a breach notification law. The GDPR gives organizations 72 hours to notify the regulator once they know about a qualifying breach. Card data has its own rules through your payment provider. We're not lawyers, so take your evidence from step 1 to one.
-
Next 30 days
Watch closely for a month.
Attackers often leave a second way back in. For the next 30 days, check for new admin users, changed files and new pages in Search Console. If anything comes back, the entry point is still open, and it's time to get help.
Common mistakes
Four things that make it worse.
Restoring last night's backup and moving on.
It may already contain the attacker's files. Even if it doesn't, the hole is still there.
Trusting one "all clear" from a scanner.
Scanners find known malware. A fresh backdoor written for your site often looks like ordinary code.
Changing passwords on an infected computer.
If the attacker is on your machine, they get the new password the moment you type it.
- Mistake 4: going quiet. Customers forgive a break-in handled honestly. They rarely forgive finding out from someone else.
Hacked website recovery
Rather hand it to someone who does this every week?
Tell us what you're seeing. A person reads it, looks at your site from the outside, and replies in writing within one business day with what we think happened and a fixed price to put it right. No sales calls.
Malware out
We remove the malicious code, injected content, rogue users and backdoors, on the server and in the database.
Door closed
We find how they got in and close it, so you're not doing this again next month.
Clean and current
We restore clean files and bring the software that let them in up to date.
Warnings cleared
We help you request the Google review and clear browser and search warnings.
Once it's clean, make sure there's no next time.
A site that's been hacked once is a site attackers know works. Their tools keep the address.
That's why our recovery work ends with a list of what else we noticed along the way. And it's why many owners follow it with a Readiness Review or a full Certification Audit, built on ISO/IEC 27001, so every door gets checked rather than just the one that was open.
Or start on your own with one of our free self-checks. The OWASP Top 10 guide covers the website itself. The CIS Controls guide covers the server, domain, email and backups behind it.
Nobody ever wished they'd asked for help later.
Questions
About hacked websites.
How do I know if my website has been hacked?
Common signs are a browser or Google warning in front of your site, visitors being redirected to spam or scam pages, strange pages or foreign-language results when you search site:yourdomain.com, admin accounts you didn't create, your host suspending the account for malware or spam, and customers reporting card fraud after buying from you.
Should I just restore my latest backup?
Not on its own. The latest backup may already contain the attacker's changes, and even a clean backup still has the weakness they used to get in. Restore from a copy you know is from before the break-in, then update everything and close the entry point before the site goes back online.
How long does Google take to remove a hacked site warning?
After you clean the site and request a review in Google Search Console, Google says phishing reviews take about a day, malware reviews a few days, and reviews for sites hacked with spam can take several weeks. Once Google confirms the site is clean, warnings are normally removed within 72 hours.
Do I have to tell my customers?
Possibly. Every US state has a data breach notification law, and the GDPR gives organizations 72 hours to notify the regulator once they're aware of a qualifying breach. Whether they apply depends on what data was exposed and where your customers live. Preserve evidence and get advice from a lawyer before you decide.
My host says they cleaned it. Am I done?
Ask them one question: how did the attacker get in? If the answer is "we're not sure", the cleanup may not last. Many hosts remove the infected files they can see but don't look for the entry point, the database or hidden admin users.
How much does hacked website recovery cost?
Our recovery starts at $1,750, with the price fixed in writing before work starts. It covers removing malicious code, finding and closing the hole the attacker used, restoring clean files, and helping clear search engine and browser warnings. Full pricing.