Speed counts, but the first reflex: erasing everything: often makes things worse.
For a hacked website, first take the site offline or into maintenance mode, change all passwords, restore from a backup from before the breach, and close the hole before going live again. Restoring without finding the cause means being hacked again within days.
STEP BY STEP
This is how you approach it
- Take the site offline or into maintenance modeAs long as it is online, visitors can become infected and Google can mark you as unsafe. The latter takes weeks to reverse.
- Change all passwordsHosting, management environment, database, FTP and the email accounts linked to it. Assume that everything that was accessible has been viewed.
- Save evidence before you clean upMake a copy of the infected files and logs. Without that information, you won't be able to determine later how they got in.
- Find the holeUsually an outdated plugin, a weak password or a leak in the CMS. Restoring without finding this will result in the same burglary within days.
- Restore from a clean backupFrom before the burglary. If you don't know when it was, look in the logbooks for the first unusual moment.
- Submit your site for reassessmentIf there is a warning in Google, you can request a new review via Search Console as soon as it has been resolved.
PITFALLS
What you do next
Enable two-factor authentication on everything that allows access, and check whether your backups can actually be restored. This incident is the moment when that became apparent.
And consider whether your platform is worth the risk. Most intrusions are through outdated extensions: less software means less attack surface.
- Do not erase first — keep evidence and logs.
- Do not restore without cause — then it happens again.
- Directly offline — prevents contamination and a Google warning.
- All passwords — also email.
- Well, two-factor in hindsight — the most effective measure.
- Do test backups — now you know if they work.
FREQUENTLY ASKED QUESTIONS
More about security
How do I know if I have been hacked?
Signals: unexpected redirects, strange texts or links in your pages, a warning in Search Console, or visitors reporting that their browser is warning. Also trust your feeling when something is not right.
Can I solve it myself?
With a simple infection and a good backup, often yes. If you don't know how they got in, get help: a half-cleaned site gets hacked again.
How do I prevent it?
Keep software up to date, as few extensions as possible, strong passwords and two-factor authentication, and tested backups. We build without plugins, which significantly reduces the attack surface.
CONTINUE READING
Of course, continue reading about this subject.
Weather safe online?
We help with recovery and ensure that the hole is closed before you go live again.