Website was hacked

Your website was hacked. Do these things in this order.

Order matters more than speed. Most sites get reinfected within a week because the passwords were never changed or the hole was never closed.

Get help cleaning it up(330) 305-2750

Before you touch anything

  • Don't delete files yet. You need them to find how they got in.
  • Back up the site as it is now. It is evidence and your undo button.
  • Note when you first noticed and what you saw.
  • Stop logging in from any computer that might be infected.

The recovery sequence

Step 4 is the one people skip, and it decides whether the hack comes back.

  1. Confirm it is a hack

    An expired certificate or a DNS change can look alarming. Real signs: redirects to other sites, spam links in your page source, admin users you don't know, or a Security Issues message in Google Search Console.

  2. Contain it

    If it sends visitors to a scam, take it offline. Then change the hosting account password and turn on two-factor, because that account controls everything else.

  3. Restore or clean

    Restore from a backup made before the break-in whenever you can. It removes backdoors you would never find by hand. Export orders and form entries first.

  4. Change every password

    Hosting, FTP, database, every admin login, and connected API keys. On WordPress, regenerate the salts in wp-config.php to end every session, including the attacker's. Delete admin accounts you don't recognize.

  5. Close the hole

    Update everything. Delete unused plugins and themes, and any old copy of the site sitting in a subfolder.

  6. Clear the Google warning

    In Search Console, open Security Issues and request a review. It takes a few days. Asking while the site is still infected resets the clock.

  7. Watch it for two weeks

    Reinfection usually shows up within two weeks. If it comes back, the hole is still open.

How sites like yours get in

You probably weren't targeted. Almost all of this is automated scanning for known holes.

Out-of-date plugin or theme

Most common

Signs: Updates sitting for months, or a plugin nobody maintains anymore.

Fix: Update, and remove what you don't use. Deactivated code is still reachable.

Weak or shared password

Very common

Signs: A user named admin, a reused password, or a login a former employee still knows.

Fix: A password manager, two-factor, and one login per person.

Forgotten copy of the site

Common

Signs: Folders like /old, /dev, or /staging with their own WordPress install.

Fix: Delete them, or password-protect and update them like the real site.

Backdoor from the last cleanup

After a first hack

Signs: Cleaned, fine for a week, then infected again.

Fix: Restore from a clean backup instead of cleaning again, then change every password.

Stop and call someone if

  • Customer data may have been exposed. That is a legal question first.
  • The site takes payments.
  • It was cleaned once already and came back.
  • Your email is bouncing because the server was sending spam.

Questions

Should I clean the site or restore a backup?

Restore, if you have a backup from before the break-in. It is faster and removes backdoors. Clean only when there is no clean backup.

How do I know when the hack started?

Sort files by modified date and look for changes you didn't make. Check when unknown users were created. Pick a backup from before the earliest of those.

Is changing my WordPress password enough?

No. A backdoor file or a second admin account doesn't care about your password. Change every login and regenerate the WordPress salts.

Can you clean a site you don't host?

Usually, depending on the access the host allows. Sometimes moving it is faster than fighting the old account.

Rather not do this yourself?

Send the domain, what you noticed, and whether you have a backup. I will tell you if it is a restore or a cleanup before any money changes hands.

Get help with a hack(330) 305-2750