Incident response

Your website has been hacked — what to do now

Defaced home page, strange redirects, a Google warning or an email from your host saying your account is suspended. Here is what to do, in order, so the problem is fixed once and does not return.

Free, passive check — no sign-up. Results in about 20 seconds.

The first hour

  1. Do not delete everything. Take a full copy of files and database first. It is evidence, and it shows how the attacker got in.
  2. Change passwords for hosting, FTP/SFTP, database, CMS admins and the email accounts tied to them — from a clean device.
  3. Put up a maintenance page if visitors are being redirected or served malware.
  4. Check who else has access: unknown admin users, SSH keys, Search Console owners, DNS changes.

Common signs

Not sure? Our free website security check looks for the public signs in about 20 seconds.

Cleaning and closing the hole

A lasting fix has three parts: remove all malicious code and backdoors, find the entry point (outdated plugin, weak or reused password, vulnerable upload form, compromised server) and harden the site so the same route does not work again. Skipping the second part is the most common reason sites are re-hacked within a week.

After the cleanup

Frequently asked questions

Should I just reinstall the site?

A clean reinstall works only if you also change every credential and close the vulnerability. Restoring infected uploads or a compromised database brings the attacker back.

Do I have to tell my customers?

If personal data may have been accessed, data protection law such as UK GDPR or US state breach laws may require notification. Get advice on your specific case.

How long does a cleanup take?

Most single-site infections are cleaned within one to two working days, including root-cause analysis. Server-level compromises take longer.

Need it fixed?

We clean compromised websites, close the entry point and give you a written report of what we found and changed.