Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

My website has been hacked — what should I do?

A calm, step-by-step response plan if your WordPress, Magento or other website has been hacked — contain, clean, patch and recover.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·7 min read
QUICK ANSWER

A calm, step-by-step response plan if your WordPress, Magento or other website has been hacked — contain, clean, patch and recover.

KEY TAKEAWAYS
✓Act quickly but don’t delete evidence before you understand the cause.
✓Change all passwords and keys after cleaning, not just before.
✓Find and fix the entry point or it will happen again.
STEP BY STEP
Hack response in 5 steps
1Back up for evidence
2Contain (maintenance mode)
3Clean files & database
4Patch & rotate credentials
5Monitor & request review

Signs you’ve been hacked

  • Google “This site may be hacked” warnings
  • Redirects to spam or scam sites
  • Unknown admin users
  • Japanese or pharma spam in search results
  • Hosting provider suspension notices
RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Hacked right now?Engineers start within hours — fixed-price cleanup.Get emergency help →

What to do now

Take a full backup for evidence, put the site in maintenance mode if customers are at risk, and bring in help if you handle payments.

After cleaning

Patch the platform and plugins, rotate all passwords and API keys, request Google review, and add monitoring and a WAF.

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get emergency help →Free · No obligation · Reply within 24 hours

Frequently asked questions

Can I just restore a backup?

Only if you know it is clean and you fix the vulnerability — otherwise reinfection is likely.

How fast can you help?

Priority cleanups start within 4 hours.

Do I need to tell customers?

If personal or payment data may be affected, take legal advice on notification duties.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINHow to stop spam and bot attacks on Adobe Commerce CloudRead →SECURITY · 9 MINWordPress security checklist: 15 steps to protect your site in 2026Read →SECURITY · 8 MINMagecart and card skimming: how to protect your checkoutRead →
FREE · NO OBLIGATION

Hacked right now?

Engineers start within hours — fixed-price cleanup.

Get emergency help →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.