My website has been hacked — what should I do?
A calm, step-by-step response plan if your WordPress, Magento or other website has been hacked — contain, clean, patch and recover.
A calm, step-by-step response plan if your WordPress, Magento or other website has been hacked — contain, clean, patch and recover.
Signs you’ve been hacked
- Google “This site may be hacked” warnings
- Redirects to spam or scam sites
- Unknown admin users
- Japanese or pharma spam in search results
- Hosting provider suspension notices
What to do now
Take a full backup for evidence, put the site in maintenance mode if customers are at risk, and bring in help if you handle payments.
After cleaning
Patch the platform and plugins, rotate all passwords and API keys, request Google review, and add monitoring and a WAF.
Common mistakes to avoid
How we help with security
Frequently asked questions
Can I just restore a backup?
Only if you know it is clean and you fix the vulnerability — otherwise reinfection is likely.
How fast can you help?
Priority cleanups start within 4 hours.
Do I need to tell customers?
If personal or payment data may be affected, take legal advice on notification duties.