Your website has been hacked — step by step
A hacked site is repaired in a fixed order. Anyone who starts cleaning up without first knowing where the hole was is back in the same place within days.
1. Stop working on it
Do not work on the site any more and install nothing new. First gather what you know: exactly what you see, since when, and what changed last. That last point above all decides how quickly this gets solved.
2. Change your passwords
All of the ones that give access: your CMS administrators, your FTP account, your database and your customer portal. Do it from a computer you are sure is clean. Switch on two-factor authentication wherever you can.
3. Restore a backup from before the problem
The most important detail is when it was still working. The more precisely you know that, the more targeted the restore can be. Do not simply restore the most recent backup: it may already contain the break-in.
4. Find the hole before you go back online
This is the step most often skipped, and the reason sites get hacked twice. In practice it is nearly always one of these three:
- An outdated plugin or extension. By far the most common way in, found by an automated scan.
- A weak or reused password on an administrator account.
- An outdated CMS version that no longer receives security updates.
5. Update everything and clean up
Update your CMS, your theme and all your extensions. Remove what you do not use — a plugin that is not there cannot be abused. Check whether administrator accounts you do not recognise have appeared.
6. Check what went out
If spam was sent from your site, your domain may be on a blocklist and your ordinary mail will no longer arrive. If personal data was touched, you may have a duty to report it — have that checked.
What we can do
Get in touch with your domain name, what you are seeing and the time it was still working. We check what is visible from our side and help with the restore. Cleaning the site itself and closing the hole happens inside the site — we help with that, but it needs the access you manage.
Prevention is a good deal cheaper: see securing WordPress.
Does it behave differently than described above, or are you stuck anyway? Get in touch with your domain name or customer number at hand and we will take a look with you.
Contact support