Smarter Marketing. Better Results.

Recover Your Hacked Business Website Fast: What To Do If Your Website is Hacked?

Website Hack Recovery

Websites are hacked every day. If your website is hacked, don’t panic. Put it into maintenance mode, change all passwords from a clean device, and call your host. Save a copy of the infected files first, since that copy is your evidence. Then scan and clean the site or restore a pre-hack backup, close the backdoor that let the attacker in, and request a security review in Google Search Console.

What To Do If Your Website Is Hacked In The First Hour

Speed matters, and sequence matters more. The most common mistake we see is a business owner logging in, deleting suspicious website files in a panic, and destroying the trail that would have shown how the attacker got in. The short version of what to do if your website is hacked goes: contain, preserve, clean, then tell Google.

Here is that first hour in order.

Take screenshots before you do anything

Capture the defaced pages, the odd redirects, any ransom message, and the Google search results showing your listing. Note the time. If you end up filing an insurance claim, talking to your card processor, or asking your host for logs, this is the record that makes those conversations short.

Reset passwords from a clean device

Reset hosting, CMS admin, SFTP, database, domain registrar, and the email address tied to those accounts. Use a device you trust, since some malware hops from an infected laptop into the FTP client you save credentials in. Turn on two-factor authentication while you are in there.

Put the site into maintenance mode

A hacked page that stays live can hand malware to your customers and deepen a Google penalty by the hour. Maintenance mode with a 503 response tells search engines the pause is temporary, which protects your rankings better than letting the infected pages keep serving.

Call your web host

Good hosts have server-level tools and access logs you cannot see from inside WordPress. Ask them three things: when suspicious activity started, which IP addresses and accounts were involved, and what clean backups they hold. Ask them to confirm no other sites on your account are affected.

Download a copy of the infected site

Pull down the files and export the database as they sit right now, infection included, and store that copy off the server. Cleanup often destroys the evidence you need later to answer how the attacker got in, which is the question that decides if this happens twice.

Audit who has access

Review admin users in your CMS, FTP and email accounts in your hosting panel, and verified owners in Google Search Console. Attackers routinely add a second admin account so they can return after you reset the first password. Remove anything you do not recognize.

Open Google Search Console

Check the Security Issues report in Google Search Console. Google flags hacked content, malware, and deceptive pages there, along with sample URLs. Those sample URLs tell your cleanup crew exactly where to start looking.

What To Do If Your Website Gets Hacked And You Cannot Log In

Being locked out feels like the worst version of this, and it is usually the most fixable. Attackers change the admin email so password reset links land in their inbox. Your way back in runs underneath the CMS:

Through your host.

Use cPanel or your hosting dashboard to reset the database user, then update the admin email directly in the users table.

Through your registrar.

Confirm your domain still points at your nameservers and that the registrar lock is on. DNS-level hijacking sends visitors elsewhere while your site sits untouched.

Through your email provider.

Secure the mailbox tied to the account first. A compromised inbox undoes any password you reset afterward.

Website Hack Or Ordinary Website Glitch? How To Tell The Difference

Plenty of the panicked calls we take turn out to be a plugin conflict or an expired SSL certificate. Both are unpleasant. Neither needs an incident response. This table sorts the symptoms we see most.

What you are seeing Likely a hack Likely something ordinary
Homepage shows content you did not publish Yes, almost always Rare
Google results show your brand with pharmacy or foreign-language titles Yes, classic SEO spam No
Site redirects somewhere else Yes, if it happens for visitors and not for you while logged in A misconfigured redirect plugin can do this too
Browser warns visitors the site is unsafe Yes An expired SSL certificate produces a similar warning
500 or 502 server error Possible Plugin conflict, PHP version change, or host issue
Site suddenly loads slowly Possible, if the server is being used to send spam Traffic spike, heavy plugin, or shared hosting neighbor
New admin users you did not create Yes Rare, and worth checking with your developer
Your host emails you about abuse complaints Yes Almost never harmless

A fast sanity check: open your site in a private browser window on mobile data rather than your office wifi. Many redirect hacks are written to leave logged-in administrators and local IP addresses alone, so the site looks perfect to you and broken to your customers. 

How Websites Get Hacked?

Suffering a hack to your website is an extremely frustrating setback any business owner can experience. Some hacks are more difficult to recover from than others. While they can be scary to deal with, understanding how hacks happen is a great first step to ensuring that your business website is secure from hackers.

As a digital marketing agency that specializes in creating high quality websites for small businesses, we’ve worked with businesses in multiple industries to help them clean up their site after a hack. While it’s usually possible to recover what is ruined, it can take a lot of time, and money, to recover from a hack.

More often than not, websites are hacked due to one of six reasons.

  • Weak Login Credentials: You should never leave your username as “admin” and your unique password must be secure. This means that using your dog’s name or spouse’s birthday is not a good way to secure your website. Make a strong and complex password that no one would be able to figure out. 
  • Out Of Date Plugins and Themes: If you’re using a site such as WordPress, be sure to stay up-to-date on all updates that they recommend. Having an outdated site is one of the quickest ways to allow hackers into your site. 
  • Comments Turned On: Most of the comments that we see on sites are spammers who are looking to redirect your customers, or you, to sites that are there to capture your information and expose you to malware. 
  • Not Paying Attention To Vulnerabilities: Most inexperienced and lower cost hosting services are not watching for vulnerabilities, which, in turn, puts your site at risk.
  • Nulled or abandoned add-ons. A pirated premium plugin frequently arrives with a backdoor already inside it. Same story with a free plugin that the developer stopped supporting three years ago and still sits active on your site.
  • Passwords reused from a breached account. If the password on your website matches one from a service that leaked its user list, attackers will try that combination on your login page. Automated tools do this at scale, and it costs them nothing to keep trying.

95.5% is the share of infections in Sucuri’s cleanup and scanning data that involved WordPress sites, according to their 2023 Hacked Website and Malware Threat Report. The same report found SEO spam on 42.22% of infected websites, which is why a hack so often shows up first as strange search listings rather than a broken homepage.

What To Look For When Checking Your Website Security

While each hack has its own individual fingerprint, there are ways to check your own site security to ensure that everything is working properly.

First and foremost, check your site often. Not only should you go directly to your website and click all of the links, but search your business online and click the links that show up on search results, and check all of the links that you’re driving to from your paid ads or marketing ventures.

While it’s easy to assume that if the link is working from one site to another, many times, hackers will attack the places that the owner is least likely to check, which could mean that it could be months before you notice a hack and by then, it could be so bad that it takes months and a large amount of money to correct everything that was ruined.

Three free checks take under five minutes between them:

A remote scanner.

Sucuri SiteCheck reads your site the way a visitor's browser does and flags injected scripts, spam, and blocklist warnings.

Google Search Console.

The Security Issues report and the Coverage report together will show hacked pages Google has found that you have not.

A branded search.

Search your business name plus a few of your service keywords. Spam injections show up in titles and descriptions long before they change anything visible on the page.

Want a second set of eyes before something goes wrong? Our website performance self assessment walks you through the same checks we run on a new client site.

A Few Website Hacking Stories

In order to truly understand the effects that a hack can have on your small business website, and what to do if your website gets hacked, here are a few stories of clients that we’ve had who had their website hacked and reached out to our team for help.

1. WordPress Site Inappropriate Content Hack

Years ago we had a WordPress client discover that her website had been hacked and reached out to us asking for help. Turns out, her site was compromised due to a weak password.

Once the hackers gained access they replaced her site content with inappropriate content not suitable for her audience (or any audience for that matter). She was shocked and embarrassed after one of her customers brought it to her attention.

Not only can a hack like this negatively affect her reputation but it can also have other less than ideal impacts on her business. She reached out to us pleading for our help and we came to the rescue.

We immediately helped change her password, remove the source of the hack, and lock down the site moving forward so it couldn’t happen again. Later in this article we’ll share other steps we took that anyone with a WordPress website can take to protect their site from hacks. Let’s move on to another scary website hacking story.

2. WordPress Site Redirect Hack

Our second story arrived as a complaint about somebody else. A service business came to us convinced their SEO agency had broken something. Traffic had fallen off a cliff, the phone had gone quiet, and their site looked perfect when they checked it.

The catch was that it looked perfect to them specifically. Injected code in the theme files sent visitors arriving from Google to a third-party page, while logged-in administrators and anyone on the office IP address saw the normal site.

We cleaned the theme files, removed a backdoor sitting in the uploads folder, reset access, and submitted a review request to Google. Rankings came back as the flagged pages were recrawled.

3. Shopify Website Hacked. How One Hacker Stole Over $3,000

A newer client reached out to let us know their Shopify website had been hacked. This was an ecommerce business, and the owner woke up to some startling news. The hacker got into their Shopify back office through a weak and easy to guess password. Hint: do not make your Shopify login, or any login, easy to guess.

Once inside, the hacker had free rein. They updated the payment gateway information to an Amazon Pay account they owned, switched off the other payment options for the site owner, and changed the admin email to one they controlled. Sales revenue from the website landed in THEIR bank account.

By the time the owner noticed, $3,000 in sales had been diverted, and that figure sits on top of the cost of the products sold and the shipping paid to send them out. We locked the store down with a much stronger username and password, restored the payment gateway settings, and turned on two-factor authentication.

Shopify owners in the same position should follow Shopify’s own steps for securing a compromised account.

How to Clean Your Website After It's Been Hacked and Recovered

Most guides on what to do if your website is hacked stop once the malware is gone. That is roughly halfway. A cleanup that leaves the backdoor in place produces a reinfection within days, and a second infection while Google is still watching costs you far more ranking ground than the first one did.

Step 1: Restore your website from a clean backup if one exists

Restoring a known-good copy is faster than picking malware out of files and database line by line. Two conditions apply. The backup has to predate the infection, and it has to be verified clean before it goes live. For an ecommerce site, weigh that against the orders placed since the backup was taken, since those will be lost in a restore.

Step 2: Replace core files with fresh copies

Download the same version of WordPress, Joomla, or your platform from the official source and swap in the core files. Any modification to a core file that is not from an update is a strong signal of infection.

Step 3: Clean the database

Injected spam posts, malicious links inside post content, and altered site options live in database tables rather than files. Sucuri's research found that 55% of sites infected with database malware also carried at least one malicious admin user, which is how attackers walk straight back in after a file cleanup.

Step 4: Find the backdoors

This is the step that decides if the hack returns. Backdoors hide in uploads folders, in files named to resemble legitimate ones, and inside obfuscated code that reads as gibberish. Finding them takes pattern recognition and patience, and it is the main reason a professional cleanup beats a plugin scan on a serious infection.

Step 5: Reset access and reduce it

Change passwords for your website again after the site is clean, since credentials reset during an active infection can be captured. Then trim the user accounts. One administrator is usually enough, and the rest of your team can work fine as editors or authors.

Step 6: Update, then verify

Bring the CMS, plugins, themes, and PHP version current. Reinstall plugins rather than updating them, so residual malicious code goes out with the old copy. Rescan, click through the site on a device outside your network, and confirm search results look normal before you take the maintenance page down.

If several sites share one hosting account, scan all of them. Cross-site contamination is a leading cause of reinfection, and a clean site sitting next to an infected one rarely stays clean for long. Isolating sites into separate accounts is one of the quiet wins in our website maintenance plans.

Getting Your Google Rankings Back After A Hack

Here is the part that gets skipped, and it is the part that decides how much a hack costs you. Cleaning the site removes the malware. Telling Google the site is clean removes the warning label, and those are two separate jobs.

Google keeps a hacked-content flag on your property until a human or an automated review clears it. While it sits there, your listings can carry a “this site may be hacked” note, browsers can show an interstitial, and your click-through rate falls through the floor even for keywords you still rank for.

Search is the second half of what to do if your website is hacked, and it runs like this:

  • Confirm the flagged URLs are clean. Search Console shows sample URLs. Load a few from a device outside your network and confirm the injected content is gone.
  • Request a review. In the Security Issues report, tick the confirmation box and submit. Google’s guidance on how to request a review asks you to describe the problem, the steps you took, and the outcome. Detail speeds this up. Google notes a review can take from a few days to a few weeks.
  • Remove hacked URLs from the index. If the attacker created hundreds of spam pages, use the Removals tool for a temporary block while Google recrawls and drops them naturally.
  • Resubmit your sitemap. This nudges recrawling of the pages that matter to your business.
  • Watch impressions rather than rankings. Impressions recover first. Positions follow over the next few weeks as trust signals settle.

One more thing worth doing in 2026: check how AI assistants describe your business. ChatGPT, Perplexity, and Google AI Overviews pull from the same index and reputation signals Google uses, so a site flagged for hacked content can disappear from AI answers as well as from blue links. 

Rebuilding lost positions afterward is standard search work, and we walk through the full approach in our guide on how to rank on page one. If the hack cost you meaningful traffic, our local SEO services and traffic services handle the recovery side.

What To Do If Your Website Has Been Hacked On Shopify, Squarespace, Or Wix

Hosted platforms change the job. You have no server access, so file-level cleanup is off the table, and the attack surface shifts to your account credentials, connected apps, and payment settings. The recovery work moves with it.

PlatformWhere attacks usually landYour first three moves
ShopifyAdmin credentials, payment gateway settings, staff accounts, third-party apps with wide permissions.Reset the password and enable two-step verification, check payment settings and payout bank details, review staff accounts and installed apps.
SquarespaceAccount credentials, contributor permissions, connected domains and forms.Reset the password and turn on two-factor authentication, remove unknown contributors, confirm domain and DNS settings.
WixAccount credentials, collaborator roles, embedded third-party code.Reset the password and enable two-factor authentication, review collaborators, audit custom code and apps you added.
WooCommerce on WordPressPlugin and theme vulnerabilities plus admin credentials, with card skimmers at checkout.Follow the full WordPress sequence above, then scan checkout pages specifically and notify your payment processor.

On any hosted platform, check payout destinations before you check anything else. The Shopify story above cost $3,000 because the payment gateway pointed somewhere new and the storefront looked completely normal the whole time.

If Customer Data Was Part Of The Hack

A defaced homepage is a marketing problem. A compromised checkout is a legal one, and the two need different responses.

  • Call your payment processor the same day. They can flag transactions, watch for fraud patterns, and tell you if card data was exposed at the point of entry.
  • Preserve logs. PCI DSS asks merchants to maintain an incident response plan, and part of that involves preserving evidence rather than wiping the server clean.
  • Check your state notification law. All fifty states have breach notification statutes, and the timelines and thresholds differ. A quick call with your attorney is worth more than an hour of reading.
  • Tell your customers plainly. Say what happened, what you did, and what they should watch for. Businesses that communicate early hold onto trust. Silence is what damages your reputation.

This is not legal advice, and for anything involving stored customer records it is worth getting some.

Is your business site compromised right now?

Our team has cleaned up hacks across WordPress, WooCommerce, and Shopify for small businesses since 2012. Tell us what you are seeing and we will tell you what it takes to fix it.

Tips For Protecting Against Hackers and How to Protect Form Hacking

Preventing future attacks of hacking and phishing is not a topic many small business owners think about but they should. The costs, hassle, and issues associated with website hacking can be extensive so avoiding getting hacked is well worth thinking about up front when you get your website designed or redesigned. Here are some tips that can help to lock down your site and protect it against hackers.

Change Your WordPress Login Username From “Admin” To Something More Secure

Many people who build their website leave the username as admin and if you do this you are just making it easier for the hackers. Take a few seconds to change this username to something harder for the hackers to guess.

Have A Strong WordPress Password

Length beats complexity. A passphrase of four unrelated words held in a password manager is stronger than a short string of symbols, and it is never reused anywhere else.

Update The Core WordPress Theme On A Regular Basis

This is a big mistake we see small businesses make with their WordPress sites. Once they have their site built they never update the Theme and this eventually leads to issues. As mentioned earlier, this can lead to vulnerabilities that can leave an open door for potential hacking attempts. For our website maintenance clients we take care of updating the Core WordPress theme on a regular basis.

Update Plugins Regularly

Plugins, just like your WordPress theme, need to be updated on a regular basis to ensure your site stays secure. Not updating plugins on a regular basis can lead to your site getting hacked. Out of date WordPress plugins open up vulnerabilities in the defenses of your compromised website.

Shut Off Comments On Your WordPress Website

Comments are not helpful on most WordPress websites these days and even if you have a blog on your site the majority of the comments are Spam. This can be another way hackers can break into your site so don’t take the risk and shut off comments.

Have Daily Back Ups On Your Site Done

When our agency hosts websites for clients, we do daily back ups on our clients’ sites just in case something breaks (or the client breaks something) we can revert back to a recent back up that was working and fix the site. Not every web host does this and you get what you pay for.

Cheap shared hosting accounts through Godaddy or Hostgator do NOT do daily back ups. Most cheap hosting providers do not do daily back ups and this can leave you in a very vulnerable position with your business website. If something goes wrong, and you lose your website, without a back up you could be forced to start over completely.

Have A Good Website Host That Monitors For Vulnerabilities And Hacking Attempts

By then, the damage is done and they may have some challenges ahead fixing the hack and solving their problems. When our agency hosts a website we monitor all our client sites for vulnerabilities and hacking attempts.

Cheap website hosts will not tell you when something goes wrong on your site and this is a prime reason why hackers can get away with hacking a site. It may take multiple months for a small business owner to discover that their website has been hacked.

Use Two-Factor Authentication Whenever Possible

Two-factor authentication is an additional layer of security for your website. WordPress currently doesn’t offer this by default however there are some plugins that can enable this functionality on your site. Some site platforms like Shopify do offer this and you should absolutely turn this feature on to protect your website.

I would also recommend turning on two factor authentication on your email account and even your Facebook business account as well. I heard a recent story of a small business who had their Facebook Ads account hacked and before they knew it hackers had racked ups. $10,000 ad spend on their associated credit card before they caught it.

Fix It Yourself Or Bring In Professional Help

Knowing what to do if your website is hacked is one thing. Having a free afternoon and a comfortable relationship with SSH is another. Here is a straight read on which side you fall on.

Handle it yourself if

  • You have a verified backup from before the infection.
  • The site takes no payments and stores no customer records.
  • The infection looks contained to obvious injected files.
  • You are comfortable in cPanel, SFTP, and your database admin panel.
  • Google has not flagged the site.

Bring in help if

  • The site takes payments or holds customer data.
  • Google has already applied a warning label.
  • The hack returned after you cleaned it, which means a backdoor is still open.
  • You cannot work out how the attacker got in.
  • The site generates revenue and hours of downtime cost more than the cleanup would.

That last point is the one owners underweight. If your site brings in leads worth several hundred dollars a day, a two-day DIY attempt is rarely the cheaper option.

What To Do If Your Website Is Hacked

If your site has been hacked, or if you want to ensure that your site doesn’t get hacked in the future, book a time to chat with a member of our team. Our team of digital marketing experts are here to help you have a great quality, and secure website for your small business.

Questions We Get Asked About Hacked Websites

Q: What is the first thing to do if your website is hacked?

Take screenshots of what you are seeing, then change your hosting and admin passwords from a device you trust. Put the site into maintenance mode and download a copy of the infected files before anyone deletes anything. Evidence comes before cleanup, because that copy shows how the attacker got in.

Q: Can a hacked website be fully recovered?

Yes, in the large majority of cases. A site with a clean backup can be restored in hours. A site without one can be cleaned file by file and brought back. Full recovery means three things: malware removed, backdoors closed, and Google’s warning label lifted.

Q: How long does it take to fix a hacked website?

A straightforward infection with a usable backup takes a few hours. A deeper case with multiple backdoors and no clean backup runs one to three days of skilled work. If Google has flagged the site, add the review queue on top, which Google says can take from a few days to a few weeks.

Q: Will a hack hurt my Google rankings?

Yes, and how much depends on how fast you respond. Google can apply a hacked-content flag, show a warning next to your listings, and drop infected pages from results. Sites cleaned and reviewed within days usually recover positions within weeks. Infections left running for months take longer to climb back.

Q: How do I remove the “this site may be hacked” warning from Google?

Clean the site completely, then open the Security Issues report in Google Search Console, confirm you have fixed the issues, and request a review. Describe the problem, the steps you took, and the result. Google reviews the site and lifts the label once it confirms the content is clean.

In This Article