When a site is hacked, the first hours matter. Here is the order we use — the same one we apply for clients.
Signs you are hacked
- Strange ads, redirects to unknown sites
- A Google warning that the site may be dangerous
- Pages you never created (often in another language)
- Your host notifies you about spam from your account
- You cannot log into admin
What to do IMMEDIATELY (in order)
- 1. Do not delete everything in panic — first take a copy of the CURRENT state (needed to analyse how they got in)
- 2. Change the passwords — admin, cPanel/hosting, FTP, database, email. New, strong, different.
- 3. Put the site in maintenance mode if possible — so the damage does not spread to visitors
- 4. Call your host — if you are with us, we scan and immediately see where it came from
- 5. Restore from a CLEAN backup — one from BEFORE the infection; restoring an infected copy restores the hole too
- 6. Close the vulnerability — update everything: WordPress, theme, plugins, PHP. Otherwise next week — the same.
- 7. Request a Google review — in Search Console, so the warning drops
What you must not do
Ignore it (I will look tomorrow) — every hour means more spam in your name and more reputation damage. Pay someone promising a 10-euro cleanup over a chat message. Restore an old copy WITHOUT closing the hole.
How to prevent a repeat
90% of hacks come through OLD plugin and theme versions. Regular updates plus strong passwords plus two-factor login plus daily backups = calm sleep. That is exactly what our maintenance covers.