What should you do first when your website is hacked?
Stay calm and preserve evidence. Do not delete files or restore an old backup yet. Change your hosting, SSH, database and admin passwords from a device you trust, take a full snapshot of the site and database, write down what you saw and when, and contact a specialist. Deleting first often destroys the clues needed to find the entry point.
- Do not panic-delete. Removing files hides the evidence and rarely removes the backdoor.
- Change passwords from a clean device. Hosting panel, SSH, SFTP, database and CMS admin.
- Take a snapshot. Use your host's backup tool or download files and database for forensics.
- Note what you saw. Screenshots, times, error messages and any emails from your host or Google.
- Get help. Call 01932 593642 or start emergency triage.
Why restoring a backup does not fix a hacked website
A backup restores your files, but not your security. If the backup was taken after the attacker got in, it contains the backdoor. If it was taken before, the vulnerability they used is still there, and backdoors outside the site, such as cron jobs or rogue server users, are untouched. Either way, re-infection is likely.
Backups are valuable during recovery as a source of clean content, and we use them. But the repair has to include finding the entry point, removing server-level persistence and hardening. We cover this in detail in why malware keeps coming back.
Tip: keep at least one backup from before the incident and one from after it. The difference between them is often the quickest route to finding what the attacker changed.
How we repair and recover a hacked website
We repair a hacked website in a fixed order: contain, investigate, clean, restore, harden and verify. Investigating before cleaning is what lets us remove the whole compromise in one pass rather than chasing symptoms. Every action is recorded in the Activity log so you have a complete audit trail.
A common case is a fake "maintenance" page combined with an overwritten wp-config.php that points the site at an attacker-controlled database or breaks the connection entirely:
// found during forensic scan
define( 'DB_HOST', '203.0.113.77' );
@include( '/tmp/.sess_cache/loader.php' );
// restored
define( 'DB_HOST', 'localhost' );
We restore the correct configuration, remove the injected include and its payload, and then trace how the file was written. On a shared server or VPS, the answer is often another site or an exposed service, which is why we scan everything on the server. Learn more about our Forensic scan.
Can you help if my host has suspended my site?
Yes. Hosts suspend accounts that are sending spam, hosting malware or attacking other servers. We clean the account, remove the cause and give you a report listing what was found and removed, with file hashes, which you can send to your host to request reinstatement. The decision to lift a suspension rests with the host.
If your host has restricted access, we can often work from a downloaded copy or through temporary access your host grants for clean-up. We work regularly with AWS Lightsail, cPanel, CloudPanel and GoDaddy environments.
Do you need to report a hacked website?
If personal data may have been accessed, such as customer details, form submissions or order information, UK GDPR can require you to report the breach to the ICO within 72 hours of becoming aware of it, and in some cases to tell the people affected. Not every hack is reportable, so assess it quickly.
Our reports include a technical timeline and a list of what the attacker could access, which helps you and your advisers make that decision. See our guide to GDPR breach reporting after a website hack. We are not lawyers, so take legal advice where you are unsure.
What do you receive after a hacked website repair?
You receive a verified, working website and a report that explains what happened. The report has a plain-English summary for decision-makers and a full technical section with findings, a timeline, everything removed or restored, and any remaining risks. It is written so you can share it with clients, your host, insurers or the ICO.
- Executive summary: what happened, what was affected and what has been fixed, in plain English
- Technical findings: every malicious file, database entry, account and persistence mechanism found
- Timeline: when the attacker got in, what they did and when it was removed
- Evidence vault: file hashes of quarantined malware, kept for reference
- Before and after verification: scan results showing the site is clean
- Remaining risks: anything we recommend you address, such as an outdated server or shared credentials
Reports are available as a clickable HTML report and a ZIP package. Every action is also recorded in the Activity log, so there is a complete audit trail of what we changed. Learn more about Reports, or see an anonymised example in our root compromise case study.