The first hour
- Do not delete everything. Take a full copy of files and database first. It is evidence, and it shows how the attacker got in.
- Change passwords for hosting, FTP/SFTP, database, CMS admins and the email accounts tied to them — from a clean device.
- Put up a maintenance page if visitors are being redirected or served malware.
- Check who else has access: unknown admin users, SSH keys, Search Console owners, DNS changes.
Common signs
- Redirects to casino, betting, adult or pharma sites.
- “This site may be hacked” or “Deceptive site ahead” warnings in Google or Chrome.
- Spam pages or foreign-language results under your domain.
- Your hosting provider suspending the account for sending spam or hosting phishing.
- Unknown files, admin users or scheduled tasks.
Not sure? Our free website security check looks for the public signs in about 20 seconds.
Cleaning and closing the hole
A lasting fix has three parts: remove all malicious code and backdoors, find the entry point (outdated plugin, weak or reused password, vulnerable upload form, compromised server) and harden the site so the same route does not work again. Skipping the second part is the most common reason sites are re-hacked within a week.
After the cleanup
- Request a review in Google Search Console if the site was flagged.
- Check blocklists and your mail domain reputation.
- Turn on automatic updates, limit admin accounts and enable two-factor authentication.
- Set up monitoring so the next incident is spotted in hours, not weeks.
Frequently asked questions
Should I just reinstall the site?
A clean reinstall works only if you also change every credential and close the vulnerability. Restoring infected uploads or a compromised database brings the attacker back.
Do I have to tell my customers?
If personal data may have been accessed, data protection law such as UK GDPR or US state breach laws may require notification. Get advice on your specific case.
How long does a cleanup take?
Most single-site infections are cleaned within one to two working days, including root-cause analysis. Server-level compromises take longer.