Security

Site hacked? The first hour decides everything

Site hacked? The first hour decides everything

The moment you realise your site has been taken over is nasty. The first reflex is panic and the urge to "fix everything fast". That is exactly the moment when it is easiest to make things worse, delete evidence, overwrite a clean backup with an infected one, or spook the attacker into burrowing deeper.

This article is about what to do in order once you know (or strongly suspect) the site is hacked. If you are still looking for symptoms, we have a separate piece on how to tell a site has a virus. Here we assume the diagnosis is already made.

First: stay calm and delete nothing

It sounds trivial, but it is the most important rule. Do not delete files in a panic. Infected files are also evidence, they show how the attacker got in. If you delete them, you close the door but never learn whether they left a second one. And then the site gets reinfected within a few days.

Step 1: Make a copy of the "as is" state (first 10 minutes)

Before you change anything, make a full copy of the site and database in their current, infected state. This is not a copy to restore from, it is preserving the material. It lets you later establish what happened and be sure the cleanup was complete.

Step 2: Change all passwords (from a clean device)

Change the passwords to:

  • the site's admin panel (WordPress, Joomla, etc.),
  • the hosting account and panel (cPanel, DirectAdmin),
  • FTP / SFTP,
  • the database,
  • the email account linked to the domain.

Do this from a device you are sure is clean. If your computer may also be infected, changing passwords from it does little good.

Step 3: Limit external damage

If the site sends spam or redirects visitors to dangerous places, time is against you, Google may blacklist it and the host may block the account. A sensible move is often to temporarily take the site down (maintenance mode or a blank "technical break" page) to stop further damage and protect visitors until you clean up.

Taking a site down for an hour or two is far less costly than landing on Google's blacklist, which takes weeks to get off.

Step 4: Find the way in, not just the symptoms

This is the stage where DIY cleanups most often go wrong. Removing the visible malicious code is not enough if you do not close the flaw the attacker used. The most common routes are an outdated plugin or extension, a weak password, an outdated CMS version, or a hidden administrator or back door left in the files after the attack.

Only after finding and closing the source does cleaning make sense: removing malicious files, checking user accounts, reviewing scheduled tasks and database entries.

Step 5: Restore from a clean copy, if you have one

If you have a backup from before the infection, restoring the site is often the fastest route. The condition: you must know when the infection began, otherwise you restore a backup that was already infected. And either way you have to close the flaw the break-in came through, or the story repeats.

Step 6: Ask Google to re-check

Once the site is clean and secured, if it was blacklisted or got a warning, submit it for re-verification through Google Search Console. The "this site may be dangerous" warning usually disappears within a day or two after approval.

What NOT to do

  • Do not pay any "ransom" or contact the attacker, it gives no guarantee and often makes things worse.
  • Do not delete everything blindly hoping "something will help".
  • Do not leave the matter "for later": the infection will not vanish, and with each hour the risk of a blacklist and lost customer trust grows.
  • Do not assume that removing one file means it is clean: back doors can multiply.

When to ask for help

If at any stage you feel it is too much, that is normal. Cleaning a hacked site and, more importantly, making sure it does not come back, is a job for someone who does it every day. We handle this routinely: we find the way in, clean the site thoroughly, close the flaw and help remove warnings. If your site went down, get in touch, the sooner, the smaller the damage.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.