My website has been hacked: the first things to do

Work in this order. The instinct is to delete the bad files and carry on, which is exactly how sites get reinfected within days.

1. Take a copy before you change anything

Even a compromised site is evidence. Take a full backup now, and keep it separate from your clean backups. Without it you cannot work out how they got in.

2. Change every password

cPanel, FTP, all database users, the site's own administrator accounts, and any account that shares that password elsewhere. Do this before cleaning, or you will clean a site the attacker can still walk back into.

3. Find out how they got in

Nearly always one of: an out-of-date plugin, theme or extension; a weak or reused password; or a password stolen from an infected computer. The access logs and the modification dates on the changed files will usually tell you when it started, which points at what changed around then.

4. Clean, or restore

Restoring a known-good backup from before the compromise is usually faster and safer than trying to pick out changed files, provided you then close whatever hole let them in. If you restore without fixing the cause, you will be back here shortly.

5. Update everything, then re-check

Bring the core software, plugins, themes and extensions fully up to date. Then look again for anything left behind, particularly unexpected administrator accounts, scheduled tasks and files in upload folders.

Tell us

Open a ticket. We can see things you cannot – what was being served, when it started, and whether anything is still running – and if the site is sending spam we need to know before it affects mail delivery for everybody.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Recognising a phishing email that claims to be from us

Hosting customers are a standard target for phishing, because an attacker who gets your control...

File and folder permissions, and why 777 is never the answer

Every file and folder has permissions controlling who may read, write and run it. When something...

Turning on two-factor authentication

Two-factor authentication means that knowing your password is not enough to get in. It is the...

Why we block IP addresses, and how to get unblocked

Our servers block addresses automatically when they behave like an attack. This is not a...

Choosing and managing passwords

Most compromises we see come down to a password that was weak, reused, or stolen from somewhere...