What to do if your website is hacked: the first 24 hours

Found out your website has been hacked? Here is what to do in the first 24 hours, in order, who can do each step, and what comes after.

Here is what to do if your website is hacked, in the order that limits the damage. Write down what you see, and ask your host to take the site offline. Keep a copy of the hacked site before anything is deleted. Change every password from a computer you trust, and remove logins you didn’t create. Then find out when and how the hacker got in, clean the site or rebuild it, close the way in, and ask Google to lift any warning.

Most of that fits into the first day; the clean-up and Google’s review can take longer. You are not the only one this happens to: as at 2 October 2026, Google’s Safe Browsing site status page says Google finds thousands of new unsafe sites every day, many of them legitimate websites that have been compromised.

Your first 24 hours at a glance

WhenWhat to doWho can do it
Straight awayWrite down what you see and when you noticed itYou
First hourTake the site offline, or put up a holding pageYour host
First hourTell your host the site has been hackedYou
First hourHave a copy of the site made, labelled infectedYour host or developer
First few hoursScan the computers used to log in, then change every passwordYou, with your host
First few hoursRemove logins you didn’t create, on the site and in Search ConsoleYou or your developer
Same dayCheck Google’s warnings and the Security Issues reportYou
Same dayWork out when it started, what it did and how the hacker got inWhoever cleans the site
After thatRestore, clean or rebuild; close the way in; change the passwords againYour developer, or us
LastBring the site back and ask Google for a reviewYour developer, or us
The first 24 hours after a hack, and who can do each step

How do you know your website has been hacked?

Usually from a warning rather than from the site itself: a label on your Google listing, a browser warning, a Search Console alert, or a customer telling you. Google’s FAQ for hacked sites lists other common signs: unusual traffic spikes from unrelated search terms, visitors reporting malware, new administrator accounts, and suspicious new pages.

The wording of the warning tells you the kind of hack. Google’s guide to sites hacked with malware says that a site with malware typically shows “This site may harm your computer” in search results or on a warning page in the browser, while a site hacked with spam shows “This site may be hacked” in search results. The same guide says Search Console warns you when it detects many types of malware and other hacks.

You may not see a warning yourself. Google’s help page for the Security Issues report says browser warnings depend on the browsing context, so you may not be able to reproduce them, and that you should rely on the report as the source of truth. Three ways to check:

  • Search Console, Google’s reporting tool for site owners. If your site is verified there, the Security Issues report shows what Google found, with sample pages and the date each issue was first detected.
  • A site: search. Search Google for site: followed by your address, with no space (site:yourbusiness.co.za). The same help page suggests this on a small site, to spot pages you didn’t create.
  • Google’s Safe Browsing site status page. The page linked above lets anyone check whether a website is currently dangerous to visit.

Don’t click through suspect pages in your own browser: the help page warns that malware often spreads through browser weaknesses, so opening an infected page may damage your computer. If visitors are being sent to casino or other spam sites, how casino redirects and other SEO-spam hacks work explains what you are seeing.

The first hour: contain it

Write it down

WordPress.org’s guide for hacked sites starts with staying calm, and calls documentation the first actionable step: what makes you think the site is hacked, what time you noticed, and what you changed recently, such as installing a plugin or changing the theme. That note becomes the incident report, useful whoever does the clean-up. Add screenshots of any warnings.

Take the site offline

Ask your host to take the site offline, or to show a holding page served from outside the hacked site. Google’s guide to quarantining a hacked site says a site taken completely offline can be worked on with less interference from the hacker, while its harmful code and spam are kept away from visitors. It adds that taking a site offline for a while during recovery is unlikely to affect how it ranks later. A holding page can still tell customers how to reach you.

Tell your host

Google’s advice on building a support team says that your host can make sure its other customers weren’t affected, and may be able to help recover your site. WordPress.org’s guide adds that a hack may reach beyond your site, especially on shared hosting, and that your host may be able to tell a real hack from a loss of service.

Keep a copy before anything is deleted

Don’t start deleting strange files yet. Have a full copy made of the site as it is now, files and database, and label it infected. WordPress.org’s guide recommends one more snapshot before cleaning, even an infected one, and Google’s guide to cleaning a hacked site says an extra copy helps you recover content deleted by accident, or go back and try again.

The next few hours: lock the hacker out

Check the computers you log in from

Hacks don’t always start on the server. Google’s guide to finding the vulnerability lists an administrator’s virus-infected computer among the possible ways in, since spyware on it may record what is typed, and recommends running reputable antivirus scanners on every computer used to sign in to the site. Do this before you type any new passwords.

Change every password

Change the password on everything that touches the site, for every user, not only yours. Google’s quarantine guide lists the logins for file transfer (FTP), the database, system administrators and the content management system, such as WordPress; WordPress.org’s guide adds your host’s control panel, and everyone with access. Make each password long and unique, and turn on two-step login (two-factor authentication) where you can, as WordPress.org’s guide recommends. WordPress.org’s guide and Google’s cleaning guide both say to change them again once the site is clean.

Remove logins you didn’t create

Go through the site’s list of users. Google’s quarantine guide says to check whether the hacker created accounts, write down their names for the investigation, then delete them so the hacker can’t log in with them again. Do the same in Search Console: Google’s guide to using Search Console after a hack warns that a hacker may already have verified ownership there and changed settings, so check that every user and owner listed is authorised.

If the hacker has taken over your administrator account, WordPress.org’s guide says that is not a reason to panic, and sets out ways to regain control. If you can’t get in because whoever built the site holds the logins and has stopped answering, taking over a website when your developer has disappeared deals with that.

Later that day: work out what happened

Before anyone cleans anything, get three answers: when the hack started, what it did, and how the hacker got in.

When it started

The start date decides which backup you can trust. Google’s vulnerability guide says understanding when the hack first took place helps determine which backups might still be clean. Compare your notes with the Security Issues report, which shows the date Google first detected each issue, and ask your host what its logs show and how far back its backups go.

What it did

Google’s help page for the report sorts security issues into hacked content, malware and unwanted software, and social engineering, such as content that tricks visitors into revealing confidential information.

If the site holds customer details, from enquiry forms, accounts or orders, find out whether they could have been reached. Google’s cleaning guide says that if confidential user information was obtained, you may want to consider any business, regulatory or legal responsibilities before you begin cleaning the site or deleting any files.

Check your email too. WordPress.org’s guide warns that when a hacked site is used to send spam, the server’s address can be blacklisted, and that the same server is often used for email. If customers say your emails aren’t arriving, tell your host.

How the hacker got in

Google’s FAQ lists software vulnerabilities, leaked or guessed passwords, administrator pages with no login, and social engineering such as phishing among the ways in. Finding it matters. Google Search Help on the “This site may be hacked” message says to fix the security issue that let the site be infected; otherwise the site is likely to be reinfected. Google’s vulnerability guide adds that there may be several independent hacks in place, so keep looking after you find one.

WordPress.org’s guide says that working out how attackers got in is, in many cases, very difficult for site owners.

You don’t have to find it yourself, but you do have to make sure someone does. Ask whoever cleans the site to tell you, in writing, how the hacker got in and what closed it, and for the list of plugins and themes that were out of date. Out-of-date plugins and themes are a common answer; the last section says why.

Should you restore a backup, clean the site or rebuild it?

Restore a backup if you have one from before the hack started. Clean the site if you don’t, and it is worth keeping. Rebuild it if it is too old or too damaged to be worth saving. Whichever you choose, update everything, close the way in and change the passwords again before it goes back online.

Restore a backupClean the siteRebuild it clean
When it fitsYou have a backup made before the hack startedThere is no clean backup, and the site is worth keepingThe site isn’t worth saving
What it involvesRestoring the backup, then checking nothing from the hack survives in itRemoving every hacked file, page and database entryA fresh install, with only content known to be clean brought across
What to watchA backup made after the hack began may contain itAn infected file left behind makes another hack more likelyOur price starts higher than for a clean-up
Three ways to recover a hacked website

Google’s cleaning guide says to check first that a backup was made before the site was hacked. Whichever route you take, it recommends a clean installation of the software rather than an upgrade, because upgrades can leave old files behind, and an infected file left on the server makes the site more likely to be hacked again. It also suggests removing software the site no longer uses, and restoring only files known to be clean. Our hosting takes daily off-site backups, and a restore from backup is included.

We took the rebuild route for Xscape4u, a tourism and accommodation site that was referred to us after a compromise: links to offshore casino sites were being injected into it. The developers who had been helping could not fix the compromise, and Xscape4u chose to move to us. We rebuilt the entire platform, extracted the site’s data, left the hacked content out, and delivered it clean, with encryption and Wordfence.

Xscape4u home page, rebuilt by Fyre after the site was compromised

How do you get Google’s warning removed?

Once the site is clean and back online, request a review in Search Console’s Security Issues report, saying what you fixed. Google Search Help says the “This site may be hacked” message stays until the site’s owner takes action. A review takes from about a day to several weeks, depending on the hack.

As at 2 October 2026, Google’s guide to requesting a review says reviews for sites hacked with spam can take up to several weeks, malware reviews a few days, and phishing reviews about a day. If Google finds the site clean, warnings in browsers and search results are removed within 72 hours. Ask too early and you lose time: the guide warns that requesting a review while the problem still exists only prolongs the time the site is flagged as dangerous. The request has to come from a verified owner in Search Console.

Fix the issue on every page first: Google’s help page for the Security Issues report says fixing only some pages won’t earn a partial return to search results.

Can you fix a hacked website yourself?

Some owners can. Google’s advice on building a support team says fixing a hacked site yourself takes the ability to read and understand code, use command-line server tools and possibly change the web server’s configuration, and suggests a qualified professional if you feel ill-equipped. The first-hour steps above are yours to take either way.

If you hand it over, your options are your host, whoever built the site, or a website rescue service. Our website rescue clean-up starts at R5,200 incl. VAT. It covers a response within 24 to 48 hours, malware removal, hardening (making the site harder to break into), Wordfence set-up and, if Google has flagged the site, a request for Google to review it. On top of that, the site goes onto one of our care plans for at least three months, from R975 a month incl. VAT.

If the site isn’t worth saving, we rebuild it instead: a clean install, rebuilt better, with your content brought across. A rebuild starts at R15,000 incl. VAT, quoted after an assessment of R2,220 incl. VAT that is credited against the work. On a care plan, a site that is down gets a response within four business hours.

How do you stop it happening again?

Keep WordPress, its plugins and its theme updated, remove what the site doesn’t use, use strong, unique passwords with two-step login, keep the computers you log in from secure, and take regular automated backups. Google’s cleaning guide sets out most of these as the long-term plan after a hack.

Google’s page on the top ways sites get hacked calls outdated or unpatched themes and plugins a major source of vulnerabilities, and warns that attackers commonly add malicious code to free versions of paid plugins and themes.

Our care plans do the upkeep: core, plugin and theme updates tested on a staging copy of your site first, daily off-site backups (at least seven days kept, restore included), Wordfence monitoring and uptime alerts, from R975 a month incl. VAT with our hosting included. The plans are on our website maintenance page, and what Wordfence does, and what it cannot do on its own explains where a security plugin stops.

If your site has been hacked and you would rather hand it over, start with our website rescue service. Get a quote: tell us what you are seeing, and we will reply on the same business day.

Frequently asked questions

What happens if my website gets hacked?

A hacker uses it for their own ends, such as spam links, redirects, malware or stealing customer data, as Google’s FAQ for hacked sites sets out. Google’s Security Issues help says it may then show a warning in search results or in browsers. WordPress.org’s guide lists a host disabling the site among the signs of a hack, and warns that email from the same server can be blacklisted.

Can a hacked website be recovered?

Yes. WordPress.org’s guide for hacked sites says you might lose some money and take a hit to your brand, but that you will recover. There are three routes: restore a backup from before the hack, clean the site, or rebuild it and bring only clean content across, as we did for Xscape4u. Which fits depends on your backups and the state of the site.

How to fix a hacked website?

Take it offline, keep a copy, and change every password from a clean computer. Then find out when and how the hacker got in, and restore a clean backup, clean the site or rebuild it. Update everything, close the way in, change the passwords again, bring the site back online, and request a review in Search Console if Google flagged it.

What is the first thing you do when you get hacked?

Stay calm, and write down what you are seeing and when you noticed it: WordPress.org’s guide calls documentation the first actionable step after a hack. Then ask your host to take the site offline, keep a copy of it as it is, and change your passwords from a computer you have scanned for viruses.

Tell us what you need built

A few lines about your project are enough to start. We'll reply with questions, a sensible next step and, where the job allows, a fixed price.

Great service deliverables - Supportive, patient, reachable at all times and responsive

Samantha M. · Xscape4u · Google review