Website hacked: what now?
If your website has been hacked, what counts above all is a calm, orderly approach: taking the site offline for a while, changing passwords, restoring a clean backup and closing the underlying vulnerability.
How do you recognise a hack?
An infection is by no means always visible as a classic “hacked” message. Common signs:
- Your browser or Google shows a warning that the site is unsafe.
- There are strange texts, links or adverts on pages that you did not put there.
- Visitors are redirected to an unknown website.
- The site is suddenly much slower or shows error messages.
- Spam is being sent from your domain, or your email no longer arrives.
- You can no longer log in yourself, or there are administrator accounts that you do not recognise.
What do you do straight away?
- Stay calm and do not delete anything yet. Throwing files away in haste makes it harder to investigate the cause.
- Take the site offline temporarily or put it in maintenance mode. That protects visitors and prevents further damage to your reputation.
- Change every password: hosting and control panel, the CMS, FTP/SFTP, the database and the email accounts. Use new, unique passwords.
- Alert your hosting provider. They can often see from the log files when and by what route it happened, and can help out.
- First make a copy of the current situation before you start cleaning up, so that you can still investigate later what has happened.
Restoring the site
- Restore a clean backup from before the infection. Watch the date: the most recent backup may already be affected. See backups explained.
- Scan and clean up. With WordPress or Joomla, files are often modified or extra files left behind. Also check for unknown administrator accounts and scheduled tasks.
- Update everything: the core of the CMS, all themes and all extensions. Remove what you do not use.
- Check the result in a private window: are there no strange redirects left, and does everything work as it should?
- Put the site back online and, if a warning was showing, request a review from Google where necessary.
Find the cause
Restoring without finding the cause usually means the problem will come back. In practice it is almost always an outdated extension or CMS version, a weak or reused password, or a vulnerability in third-party software. If you are not certain how they got in, have it looked at before you go any further.
Need help with recovery?
We help with cleaning up and restoring an infected WordPress website or a broken Joomla website. If you are right in the middle of it and want to act quickly, feel free to get in Contact us with us straight away.
And afterwards?
As soon as the site is running again, it is time to prevent a repeat: keeping up with updates, checking backups and reducing the attack surface. Those measures are set out in preventing a hacked website. You run structurally less risk with a site without a CMS, simply because there is far less to attack.