Website was hacked
Your website was hacked. Do these things in this order.
Order matters more than speed. Most sites get reinfected within a week because the passwords were never changed or the hole was never closed.
Before you touch anything
- Don't delete files yet. You need them to find how they got in.
- Back up the site as it is now. It is evidence and your undo button.
- Note when you first noticed and what you saw.
- Stop logging in from any computer that might be infected.
The recovery sequence
Step 4 is the one people skip, and it decides whether the hack comes back.
Confirm it is a hack
An expired certificate or a DNS change can look alarming. Real signs: redirects to other sites, spam links in your page source, admin users you don't know, or a Security Issues message in Google Search Console.
Contain it
If it sends visitors to a scam, take it offline. Then change the hosting account password and turn on two-factor, because that account controls everything else.
Restore or clean
Restore from a backup made before the break-in whenever you can. It removes backdoors you would never find by hand. Export orders and form entries first.
Change every password
Hosting, FTP, database, every admin login, and connected API keys. On WordPress, regenerate the salts in wp-config.php to end every session, including the attacker's. Delete admin accounts you don't recognize.
Close the hole
Update everything. Delete unused plugins and themes, and any old copy of the site sitting in a subfolder.
Clear the Google warning
In Search Console, open Security Issues and request a review. It takes a few days. Asking while the site is still infected resets the clock.
Watch it for two weeks
Reinfection usually shows up within two weeks. If it comes back, the hole is still open.
How sites like yours get in
You probably weren't targeted. Almost all of this is automated scanning for known holes.
Out-of-date plugin or theme
Most commonSigns: Updates sitting for months, or a plugin nobody maintains anymore.
Fix: Update, and remove what you don't use. Deactivated code is still reachable.
Weak or shared password
Very commonSigns: A user named admin, a reused password, or a login a former employee still knows.
Fix: A password manager, two-factor, and one login per person.
Forgotten copy of the site
CommonSigns: Folders like /old, /dev, or /staging with their own WordPress install.
Fix: Delete them, or password-protect and update them like the real site.
Backdoor from the last cleanup
After a first hackSigns: Cleaned, fine for a week, then infected again.
Fix: Restore from a clean backup instead of cleaning again, then change every password.
Stop and call someone if
- Customer data may have been exposed. That is a legal question first.
- The site takes payments.
- It was cleaned once already and came back.
- Your email is bouncing because the server was sending spam.
Questions
Should I clean the site or restore a backup?
Restore, if you have a backup from before the break-in. It is faster and removes backdoors. Clean only when there is no clean backup.
How do I know when the hack started?
Sort files by modified date and look for changes you didn't make. Check when unknown users were created. Pick a backup from before the earliest of those.
Is changing my WordPress password enough?
No. A backdoor file or a second admin account doesn't care about your password. Change every login and regenerate the WordPress salts.
Can you clean a site you don't host?
Usually, depending on the access the host allows. Sometimes moving it is faster than fighting the old account.
Rather not do this yourself?
Send the domain, what you noticed, and whether you have a backup. I will tell you if it is a restore or a cleanup before any money changes hands.
