My Website Was Hacked: What to Do in the First Hour
Strange pages, spam redirects or a red warning on your site? What to do in the first hour, in order, and how to know when to call for help.
By DPI Web Studio team · · 6 min read
Key takeaways
- Before you touch anything, write down what you see and when, and take screenshots.
- Call your hosting company first, then change every password, starting with the email account your site uses.
- Check Google's Safe Browsing status and the Security Issues report in Search Console to see what Google sees.
- A real cleanup also finds how they got in. Otherwise the same hole lets them back.
- If customer information may have been exposed, talk to a lawyer about notice rules. This article is not legal advice.
Your phone buzzes. A customer says your website sent them to a casino page. Or Chrome shows a red warning when you open your own site. Or your hosting company emailed to say your account is suspended.
First, take a breath. A hacked site is stressful, but it’s fixable. The first hour is about stopping the harm, locking the doors and collecting the facts. The full cleanup comes after.
Here’s what to do, in order.
Is it really a hack?
Not every broken site is a hack. A site can go down because the domain expired, the hosting bill bounced, or a plugin update broke something. Those are problems for website repair, not a security cleanup.
These signs point to a real hack:
- Your site sends visitors to spam, gambling, pharmacy or adult pages.
- Google shows pages in your results that you never made, sometimes in another language.
- Chrome or another browser shows a red warning before your site opens.
- Your host suspends the account for malware or for sending spam.
- You find admin users you don’t recognize.
- Customers say their antivirus blocks your site.
The WordPress.org guide for hacked sites lists similar warning signs, and they apply to other website platforms too.
One tricky part: some hacks hide from you. Google warns that hackers try to make a page look gone or fixed when it’s still hacked, showing spam to search engines while you see a normal homepage. So “it looks fine to me” doesn’t prove the site is clean.
Minutes 0–10: write down what you see
Before you change anything, make a short record. The WordPress guide calls this the first step, and it’s good advice on any platform.
- Take screenshots of what’s wrong, with the page address showing.
- Note the time you first noticed and who told you.
- Write down any recent changes: a new plugin, a theme update, a new staff login, a new designer.
- Save any emails from your host or from Google.
This takes ten minutes, and it saves hours later. Whoever cleans the site will ask for exactly this.
Don’t start deleting files you don’t recognize. You might remove evidence, or something your site needs to run.
Minutes 10–20: call your hosting company
Your hosting company is your first call. Google’s guide for hacked sites says to tell your host your site has been compromised. They can see things you can’t, check whether other sites on the same server are affected, and they often keep backups.
Ask them three things:
- Can you see how the site was changed, and when?
- Do you have a clean backup from before the problem started?
- Can you put up a maintenance page while we clean up?
That last one matters. If your site is sending people to harmful pages, Google recommends you take the site offline so it stops serving content to visitors. Google also notes that blocking only search engines isn’t enough, since real people would still land on the bad pages.
If you don’t know who hosts your site, look at your last web hosting bill, or ask whoever built it. That’s also a sign to get your accounts written down in one place, in your own name.
Minutes 20–40: lock the doors
Now change passwords. Do it in this order, because each account can be used to break into the next:
- The email account your site and host send to. Password resets go there. If someone controls it, they can reset everything else.
- Your hosting account and its control panel.
- Your domain registrar, where you pay for your domain name.
- Your website admin, for every user, not just yours.
- FTP, SFTP and database passwords. Your host can help with these.
Use long, unique passwords, and turn on two-step verification wherever it’s offered. Google’s guide also says to review every user account, note any accounts the attacker created, and remove them.
Change these passwords from a computer you trust. The WordPress guide points out that some attacks start on the owner’s own laptop, so run a full virus scan on the computers used to log in to the site.
You’ll change the passwords again after the cleanup. That’s normal.
Minutes 40–60: see what Google sees
Three free checks show how bad things look from the outside.
Google Safe Browsing status. Enter your address in Google’s Safe Browsing site status tool. It shows whether Google currently marks your site as unsafe.
Search Console’s Security Issues report. If your site is set up in Google Search Console, open the Security Issues report. It lists hacked content, malware or deceptive pages Google has found. While you’re there, check the list of users and owners. Google says to make sure every user and owner is authorized, because attackers sometimes add themselves.
If your site isn’t in Search Console yet, set it up now. You’ll need it to ask Google to remove the warning later.
A remote scan. Sucuri SiteCheck scans any public page for malware and checks a few blocklists. It’s a useful quick look. Sucuri itself notes that a remote scanner can’t see files on the server, so a clean result doesn’t mean the site is clean.
What not to do
Don’t restore a backup and walk away. A backup brings back your old site, including the weak spot the hacker used. Restoring is often part of the fix, but it’s not the whole fix.
Don’t ask Google for a review too early. Google says to fix every issue before you request a review. Asking too soon can make the review take longer.
Don’t pay for “instant removal” from Google. Only Google decides when a warning comes off, after you clean the site and request a review.
Don’t ignore it because the homepage looks normal. As above, many hacks hide from the owner.
After the first hour: the real cleanup
The first hour stops the bleeding. The cleanup is what actually fixes it. Whether you do it yourself or hire help, it should cover these steps:
- Make a copy of the hacked site. Even an infected copy helps if something goes wrong, the WordPress guide notes.
- Remove the bad code and files, and any admin users the attacker added. Sucuri publishes a step-by-step cleanup guide for WordPress.
- Find how they got in. Google lists common ways sites get hacked, including outdated software and weak or leaked passwords.
- Update everything: the platform, every plugin and theme. Delete the ones you don’t use.
- Change every password again, now that the site is clean.
- Request a review from Google in the Security Issues report. Google says a review can take from a few days to a few weeks.
- Set up backups and updates so you’re not here again next year. A maintenance plan covers this if you don’t want to do it yourself.
If customer information was involved
Most hacks are about spam or redirects. Some reach customer data: contact forms, customer accounts, or anything stored in your site’s database.
If that’s possible, slow down and get advice. New York’s SHIELD Act covers more than card numbers. Online logins, such as a username or email address with a password, count too, and businesses must notify affected people after a breach. Your payment processor and your insurance company may also want to hear from you.
This is not legal advice. Talk to a lawyer about what applies to you.
When to call for help
You can do the first hour yourself. The cleanup is harder. It means reading code, comparing files and knowing where attackers like to hide things.
If you’d rather hand it off, our hacked website repair service covers the cleanup, closing the hole, and the request to Google. We work inside your accounts, and they stay in your name.
Once the site is clean, keep it that way. Regular updates, backups and someone watching for trouble cost far less than another bad week like this one.