My Website Got Hacked: What Should I Do Now?
Finding out your website is hacked is stressful. This guide tells you what to do first, what not to do, and how to get the site clean and safe again, in plain language.
My website is hacked. What should I do first?
If your website is hacked, here is what to do first: stay calm, take a full backup of the hacked site as evidence, put the site in maintenance mode, and change all passwords (hosting, admin, FTP, database, email). Then clean the files and database, close the weak point that let the attacker in, and ask Google to review the site.
Key takeaways
- Do not delete everything in panic; save a copy of the hacked site first.
- Change every password from a clean device, not the infected one.
- Cleaning is not enough; you must find and fix how the attacker got in.
- Check Google Search Console for security warnings and request a review.
- Tell customers if their personal data may have been exposed.
- After recovery, add a firewall, monitoring and tested off-site backups.
How do I know if my website is hacked?
Your website is probably hacked if it shows content you did not add, sends visitors to other sites, or if Google, your browser or your host warns you. Some hacks are hidden, so look for small signs too.
Common signs of a hacked website
- Visitors from Google are redirected to gambling, pharmacy or adult sites
- Google shows Japanese or spam keywords under your site name
- A red "Deceptive site ahead" or "This site may be hacked" warning appears
- New admin users you did not create
- Unknown files in your hosting, often with random names
- Your host suspends the account for malware or sending spam
- Emails from your domain land in spam or bounce
- Sudden slowness, high CPU use or very high bandwidth
- Payment page changes or customers report card fraud after shopping
What to do in the first hour after a website hack
In the first hour, the goal is to stop more damage and save evidence. Do not start deleting files at random, because that destroys clues and often leaves the backdoor in place.
- 1
Stay calm and note the time
Write down when you noticed the problem, what you saw and who reported it. Take screenshots of warnings, spam pages and redirects.
- 2
Take a backup of the hacked site
Download all files and export the database as they are now. Label it clearly as infected. This copy is evidence and helps find the entry point.
- 3
Put the site in maintenance mode
Show a simple holding page or ask your host to block public access for a short time, so visitors and customers are not harmed.
- 4
Change passwords from a clean device
Use a phone or computer you trust. Change hosting, control panel, website admin, FTP or SFTP, database and domain email passwords. Turn on two-factor login.
- 5
Tell your host
Your host can share logs, check other sites on the same account and confirm if the server itself is affected.
- 6
Call for help if you are unsure
If you sell online, store customer data or the site is your main lead source, get a specialist involved early. Our malware removal team offers 24x7 emergency support.
What should you NOT do when your site is hacked?
Do not pay anyone who claims to be the hacker, do not just restore an old backup without checking it, and do not log in from the device you think is infected. These mistakes cause most repeat hacks.
- Do not only delete the spam pages you can see. Hidden backdoors stay and the spam comes back in days.
- Do not restore a backup blindly. The backup may already contain the malware, or the same weak plugin will be hacked again.
- Do not reuse old passwords or share new ones on WhatsApp groups or email.
- Do not ignore the problem because the homepage looks fine. Many hacks only show to Google or to new visitors.
- Do not install random "free malware cleaner" plugins from unknown sources. Some are malware themselves.
- Do not hide a data leak from customers if their personal or payment details may be exposed.
How is a hacked website cleaned properly?
Proper hacked website recovery means removing all malicious code from files and the database, removing backdoors and fake users, then closing the hole that let the attacker in. A clean scan alone is not proof that the site is clean.
What a full cleanup covers
| Area | What is checked | Why it matters |
|---|---|---|
| Core files | Compare with clean official copies of WordPress, Shopify theme files, Laravel or other code | Attackers change core files because owners rarely look there |
| Plugins, themes, packages | Reinstall from official sources, remove nulled or unused ones | Old and pirated extensions are the most common entry point |
| Uploads and media folders | Look for script files hiding among images | Backdoors often sit in folders that should only hold images |
| Database | Search posts, options and settings for injected scripts and spam links | Spam and redirects are often stored in the database, not files |
| User accounts | Remove unknown admins and reset all passwords and keys | A hidden admin user lets the attacker walk back in |
| Server and scheduled jobs | Check cron jobs, .htaccess rules and server config | Hidden tasks can re-infect the site every few hours |
| Email and DNS | Check mail forwarding rules and DNS records | Attackers may redirect mail or add records to send spam |
After cleanup, we rescan, test the site on desktop and mobile, and compare search results again. You can read more on our website malware protection page about how we stop malware from returning.
How did the hacker get in? Finding the root cause
Most website hacks come from an outdated plugin or theme, a stolen or weak password, pirated software, or a badly set up server. Finding the real entry point is the most important step, because fixing it stops the hack from returning.
Outdated software
A plugin, theme, app or framework with a known security bug that was never updated.
Weak or reused passwords
A password leaked in another breach and reused on your hosting or admin panel.
Nulled themes and plugins
Pirated premium extensions that come with a hidden backdoor from day one.
Shared hosting spread
Another old site on the same hosting account gets hacked and infects yours.
Insecure file upload
A contact or upload form that accepts script files instead of only images or PDFs.
Infected staff device
Malware on a computer steals saved passwords for FTP or the admin panel.
We read the server access logs and file change dates around the time of the hack to find the path the attacker took. This is part of every cleanup and also part of a full security audit.
How do I remove the Google hacked warning?
To remove a Google hacked warning, first clean the site fully, then open Google Search Console, check the Security Issues report, and request a review. Google usually reviews within a few days once the site is clean.
- Verify your site in Google Search Console if it is not done yet.
- Open the Security Issues and Manual Actions reports and read the sample URLs.
- Make sure every listed URL is clean or returns a 404 or 410 status.
- Remove spam URLs from your sitemap and submit a fresh sitemap.
- Click Request Review and explain what you cleaned and how you fixed the entry point.
- Check your domain on other blocklists and with your antivirus vendor if visitors still see warnings.
Spam pages may stay in search results for some weeks after cleanup. You can use the removals tool in Search Console to hide the worst ones faster. Official help is at Google Search Central.
Do I need to tell customers or authorities?
If personal data like names, phone numbers, addresses or payment details may have been exposed, you should inform affected customers and, in India, check whether you must report the incident to CERT-In. Take legal advice for your exact case.
In India, CERT-In issued directions in 2022 that require many organisations to report certain cyber incidents within six hours of noticing them. The official site is CERT-In. India's Digital Personal Data Protection Act also puts duties on businesses that handle personal data. If you serve customers in the UK, EU or USA, their rules may also apply.
What a simple customer message should say
- What happened, in plain words, and when you found it
- What data may be affected and what is not affected
- What you have done to fix it
- What customers should do, such as changing a password or watching for fake calls
- How to contact you with questions
Keep it honest and short. Customers trust a business more when it explains a problem quickly. Our data security service helps you reduce what data you store, so future leaks expose less.
How to stop your website from being hacked again
After a hack, add layers: keep everything updated, use strong passwords with two-factor login, put a firewall in front of the site, watch for file changes, and keep tested off-site backups. One layer is never enough.
| Layer | What it does | Where to learn more |
|---|---|---|
| Updates | Closes known security bugs in core, plugins and themes | Monthly care plan |
| Strong logins | Two-factor login and unique passwords stop stolen-password attacks | Password security policy |
| Firewall | Blocks bad bots and common attacks before they reach your site | Website firewall |
| Monitoring | Alerts you about file changes, downtime and blocklists | Security monitoring |
| Backups | Lets you restore a clean copy quickly | Backup and disaster recovery |
| HTTPS | Protects data between visitor and site | SSL certificate setup |
Fix it yourself
- Fine for a simple site with a clean recent backup
- No outside cost
- Good if you have technical staff
Use a specialist
- Better for online stores and lead-heavy sites
- Root cause found from logs, not guesswork
- Hardening and monitoring done in the same job
If you want a full list of protections, see our website security services page.
How long does hacked website recovery take and what affects cost?
A simple hacked site can often be cleaned and back online within the same day, while a large store or a heavily infected server may take a few days. Cost depends on site size, how deep the infection is, and how much hardening is needed.
- Size of the site and number of plugins, apps or custom code files
- Whether the database and email are also affected
- Whether you have a clean, recent backup
- Hosting type: shared hosting, VPS, cloud server or Shopify
- Need for urgent out-of-hours work
- Extra work after cleanup, like a firewall, monitoring and a care plan
You get a clear quote after a free call. Our parent team, Shivah Web Tech, has 11+ years of experience and a 25+ person in-house team, and offers 24x7 emergency support for urgent hacked site issues. Contact us to start.
Related Pages
Frequently Asked Questions
Can a hacked website be fully recovered?
Yes, in most cases a hacked website can be fully recovered. The files and database are cleaned, backdoors and fake users are removed, and passwords and keys are reset. The important part is fixing the weak point that let the attacker in, otherwise the site may be hacked again within days or weeks.
Should I just restore my last backup after a hack?
Only if you are sure the backup was taken before the hack and you also fix the entry point. Many backups already contain hidden malware because attackers often wait weeks before acting. After restoring, update all software, change every password and scan the site again before you make it public.
How do I know which plugin caused the hack?
Check which plugins and themes were out of date, then compare server access logs and file change dates with the time of the hack. Look for requests to unusual files or plugin folders. This needs some technical skill, so many owners ask a security team to read the logs for them.
Will my Google rankings come back after a hack?
Rankings usually recover after the site is cleaned, spam pages are removed and Google reviews the site. It can take some weeks for the spam URLs to drop out of the index. Submitting a clean sitemap and fixing the Search Console security issue helps recovery go faster.
Is my hosting company responsible for cleaning my hacked site?
Usually not. Most hosting plans make the website owner responsible for the security of their own website code, plugins and passwords. Some managed hosts offer cleanup as a paid add-on. Your host can still help by sharing logs and checking whether other sites on the account are affected.
What should I do if hackers are asking for money?
Do not pay and do not reply with sensitive details. Paying does not promise that data will be deleted or returned. Save the messages as evidence, report the incident to the police cyber cell or the national cybercrime portal in India, and get your systems cleaned and restored from safe backups.
How much does it cost to fix a hacked website in India?
There is no fixed price. Cost depends on the size of the site, the type of platform, how deep the infection goes, whether there is a clean backup and how urgent the work is. You get a clear quote after a free call, with the cleanup and hardening steps listed separately.
Can a small business website really be a target?
Yes. Most attacks are run by bots that scan the internet for any site with an old plugin or weak password. They do not care about the size of the business. Small sites are often easier targets because updates and backups are not checked regularly.
Talk to our team today
Call or WhatsApp +91 85808 92163. We reply fast, Monday to Friday.