What to Do If Your Website Has Been Hacked


If you visit your site and notice it’s scrambled, gone, or worse, it’s showing links to unsavory sites, there’s a good chance you’ve been hacked. In some ways, that’s the least unfortunate case, because at least you know immediately that something is wrong.
Other website compromises can be harder to spot. Unexpected redirects, unfamiliar pages, security warnings, sudden traffic changes, or unauthorized account activity can all signal that an attacker has gained access. Whatever the warning sign, acting quickly can help limit further damage and make recovery easier.
If you believe your website has been hacked, start by limiting access to the site, securing your accounts, and determining how far the issue has spread. Then remove any malware, restore clean files, fix the vulnerability, and address any related security warnings.
The exact steps vary by website and hosting setup, but the general recovery process is similar across most CMS platforms and custom-built sites.
What are the signs that your website has been hacked?
Some website hacks are obvious, while others can remain hidden as malicious code that operates in the background or appears only to certain visitors. Website owners should understand the warning signs that may indicate their site has been compromised, such as:
- Pages that look scrambled, defaced, or completely different
- Visitors being redirected to websites you do not recognize
- Spammy links or pages that you did not publish
- Security warnings appearing next to your pages in Google Search
- Browser warnings that block visitors from accessing the site
- Administrator passwords that suddenly stop working
- New administrator accounts you did not create
- Unfamiliar PHP, JavaScript, or other files appearing on the server
- Sudden traffic drops or unusual performance problems
- A hosting provider suspending your account or reporting malicious activity
- Customers reporting suspicious behavior before you notice it yourself
If you suspect your site has been hacked, check Google Search Console’s Security Issues report for detected malware, hacked pages, or other harmful activity. You can also search Google using site:yourdomain.com to spot unfamiliar pages that may have been added or indexed by an attacker.
Confirm the attack and determine its scope
Before you begin cleanup, determine how far the attack reached to understand the full scope of the compromise. Make sure to check:
- Website files and directories
- Database content
- Administrator and user accounts
- Login and server logs
- Customer or form data
- Checkout and payment functionality
- DNS and domain settings
- Other websites within the same hosting account
Review file modification dates and recent login activity for changes that do not match legitimate website work.
An external scanner can provide a useful first check. SiteLock's free website security scan looks for known malware, malicious code, and other externally visible security issues. However, a clean scan does not rule out compromise, since some threats require access to website files or the database to detect.
Steps to take if your website has been hacked
The first step is containment. Your goal is to protect visitors, prevent further unauthorized access, and get the right people involved.
1. Take the website offline or put it in maintenance mode
Temporarily restrict access if visitors could encounter malware, malicious redirects, compromised forms, or other dangerous content.
Avoid immediately deleting files or wiping the server. Doing so can destroy information that helps identify how the attack happened and what parts of the site were affected.
2. Document what happened
Record what you know about the attack before making major changes, including:
- Screenshots of suspicious pages
- Affected URLs
- Browser or search engine warnings
- Error messages
- Dates and timestamps
- Unfamiliar accounts
- Suspicious files or code
- Recent website changes
This information can help your hosting provider or security team investigate the issue and determine when it began. That can also help you choose the right backup if a restore is necessary.
3. Change all passwords and secure account access
An attacker who still has valid credentials can undo your cleanup. Change your passwords for:
- CMS administrator accounts
- Hosting accounts
- FTP/SFTP or SSH access
- Databases
- Domain registrar accounts
- Connected email accounts
Make the changes from a trusted device. Remove administrator accounts that you do not recognize and sign out of existing sessions when possible.
Turn on multi-factor authentication for administrator and hosting accounts wherever it is available. Strong authentication reduces the chance that a stolen password alone can provide access.
4. Contact the right providers
Who you need to contact depends on what the attack affected.
Start with your hosting provider. Ask them to review server logs, look for suspicious activity, and determine whether the issue affects other sites or accounts within the same hosting environment.
You may also want to contact:
- A website security provider when malware cleanup requires more technical knowledge
- Your domain registrar if DNS records or nameservers changed
- Payment processors or connected service providers if checkout systems or third-party connections were affected
- Customers if their personal information may have been exposed
- Legal counsel or a compliance professional if the incident may qualify as a data breach
Data breach notification requirements vary by location and the type of information involved, so seek appropriate legal or compliance guidance when necessary.
If you need help removing malware and restoring the site, SiteLock 911 provides hacked-site cleanup, including malware and backdoor removal, SEO spam cleanup, and blocklist assistance.
How to fix a hacked website
Once the attack is contained and account access is secured, focus on cleaning the site and fixing whatever allowed the attacker in. That may include removing malicious code, restoring clean files, and hardening weak points before the site goes live again.
Scan for malware and restore clean files
Run a malware scan across your website files and database to find malicious code, backdoors, redirects, spam, modified files, or unauthorized accounts. Remove infected files and code, replace altered CMS files with clean copies, and make sure any hidden backdoors are removed so attackers cannot regain access.
If the damage is extensive, restore a clean backup from before the infection. Use security alerts, server logs, and file modification dates to help identify a safe restore point.
If you are unsure what is malicious, use a professional malware removal service rather than risk deleting legitimate website files.
Fix the vulnerability that caused the hack
Removing malware is only part of the process. Identify how the attacker gained access and fix that specific weakness before bringing the site back online.
Update your CMS, plugins, themes, PHP, and other website software. Remove unused components, review file permissions and administrator access, and check DNS, nameserver, CDN, or hosting settings for unauthorized changes.
You should also scan computers used to manage the site for malware that could steal credentials or lead to reinfection.
WordPress users can find more platform-specific steps in our WordPress hacked site guide.
Verify the website is clean before bringing it back online
Before reopening the site, run another malware scan and test any pages that were affected. Check for redirects or spam content, review administrator accounts and server logs, and confirm that the vulnerability has been fixed.
Do not assume the site is secure just because it looks normal again. Complete the cleanup first. If Google flagged the site, return to the Security Issues report in Google Search Console and request a review once you are positive the problem has been fixed.
Strengthen your website after recovery with SiteLock
Once your site is clean and back online, ongoing protection can help reduce the risk of another attack. SiteLock website security plans combine monitoring, scanning, and security tools to help identify new threats and weaknesses before they become larger problems.
Site Health gives you a clear view of your website’s current security status, while Prioritized Tasks highlights top issues that need attention to keep your site secure. This makes it easier to spot remaining security gaps, prioritize the right fixes, and keep your website better protected moving forward.