If your website got hacked and you are wondering what to do, start here, in this order. Take screenshots and write down the time you noticed. Ask your host to take the site offline or put up a maintenance page, but do not delete anything yet. Change your hosting, email, website and domain passwords from a computer you trust. Then open the Security Issues report in Google Search Console. In many cases a hacked site can be cleaned and kept, and there is time to make that call once it is contained. If a customer told you about it and the site looks fine from your own computer, keep going. That is common, and the steps below explain why.
Key Takeaways
The FTC's breach guidance says to take affected equipment offline immediately, but not to turn machines off. For a website, that means a maintenance page or host suspension, not deleting files.
Google warns that attacks can vary by device and browsing context, so a redirect may only show on phones or to visitors arriving from Google.
Its Security Issues report lists what Google found, and a review request should explain the issue, describe the fix and document the outcome.
Clean files, a verified clean backup and patched software can save a supported site. A rebuild becomes safer when the platform is unsupported or the damage cannot be scoped.
Stop the damage in the first hour
The order matters more than speed, and the sources on the first page of search results disagree about it. Some say take the site offline first. Others say copy everything before touching anything. The FTC's data breach response guide settles it: "Take all affected equipment offline immediately, but don't turn any machines off until the forensic experts arrive." For a small business website, that translates into five steps.
- Record what you see: Screenshot the spam pages, the redirect, the browser warning and any email from your host. Note the time, the address you visited and anything that changed recently, such as a new plugin, a new user or a developer's last visit. The WordPress hacked-site FAQ calls documentation the first actionable step.
- Contain it: Ask your host, through the link in your account dashboard, to suspend the site or put up a maintenance page. That stops customers reaching whatever the attacker put there, without erasing the trail.
- Change access from a clean device: Change passwords for hosting, the website admin, email, FTP or SFTP, the database, and your domain registrar. Use a computer you trust, and turn on two-factor sign-in wherever it is offered.
- Scope it: Open Search Console's Security Issues report and your host's logs. Look for users, files and settings you do not recognize, but do not delete them yet.
- Hold off on the rest: Do not restore a backup, request a Google review or start a rebuild until you know what happened and how the attacker got in.
One exception changes the order. If your server shows signs of ransomware, your files are encrypted, or customer or payment data may have been taken, stop cleaning and get professional incident help to preserve evidence first. That is no longer a routine website problem.
Know what kind of hack you are dealing with
What you are seeing tells you a lot about what to do next. It will usually fit one of a handful of kinds:
- Defacement: Your pages show a message, image or language you did not put there. Somebody had publishing access, but it does not prove the rest of the server is clean.
- Injected spam: Unfamiliar pharmacy, casino, adult or finance pages or links appear, often only in Google results or at odd addresses. Google labels these as content or URL injection in Search Console.
- Malicious redirect: Some visitors are sent to a different, often dangerous, site. It can depend on device, on where the visitor came from, or on whether they are logged in, which is why you may not see it yourself.
- Stolen access: Unfamiliar admin users, password-reset emails you did not request, new FTP accounts or changed domain settings.
- Unexplained server load: Sustained high resource use with little traffic can point to a cryptominer or other hidden process, though it is a clue rather than a diagnosis.
- Ransomware on the host: Files are encrypted or inaccessible and there is a ransom note. This needs containment and professional help, not a quick restore.
If your site only misbehaves for other people, test it the way they see it: from a phone on mobile data, from a private browser window, or by clicking through from a Google search. Google's own guidance on hacked sites says to treat its report as the source of truth even when you cannot reproduce a warning yourself.
Get Google's warning removed the right way
When Google finds malware, deceptive pages or hacked content, it may show a warning next to your search results, and Chrome may show a red page before visitors reach your site. That can cut your traffic sharply. It is not the same as a manual penalty, and it does not mean your site has been removed from Google.
The Security Issues report in Search Console shows the type of issue, when it was first detected, a description and sample URLs. The samples are examples, not a complete list, so cleaning only those pages is rarely enough.
Once the malicious content and the way in are both fixed, request a review from the same report. Google says a good request does three things: explains the exact issue on your site, describes the steps you have taken to fix it, and documents the outcome. Reviews take time. Google's documentation says malware reviews usually take a few days and hacked-spam reviews can take several weeks, and warnings clear within a few days of a successful review, allowing for some delay across Google's systems. Do not send the request while the problem remains, and do not send it repeatedly; Google says that can slow things down.
If spam pages are showing in search while you clean, Search Console's removals tool can hide them temporarily. It does not remove anything from your server, so it is a stopgap, not a fix.
The route back, in order
- 1
Hour 1
Record, contain through your host, change passwords from a clean device.
- 2
Hours 2 to 6
Check Search Console's Security Issues report, your host's logs, and every user account for anything unfamiliar.
- 3
Day 1
Remove the malicious content, fix the way in, restore clean files or a verified clean backup, update everything, change passwords again.
- 4
Day 1 to 2
Test as a logged-out visitor on desktop and mobile, then request Google's review with the issue, the fix and the outcome.
- 5
Days to weeks
Wait for the review. Malware reviews usually take days; hacked-spam reviews can take weeks.
Save the site you have, when you can
A site does not need to be rebuilt just because it was hacked. Google itself lists replacing affected files with the last good backup, or removing the malicious content, as ways to recover. WordPress's official documentation says its core folders can be replaced with clean copies of the matching version while you review the parts that are unique to your site.
Cleaning and keeping the site is usually the right call when:
- The platform is still supported: The software, theme and extensions still receive security updates.
- A clean recovery point exists: A backup from before the compromise, or clean copies of the software files.
- The way in can be closed: The outdated plugin, weak password or exposed account can be fixed.
- The damage has edges: You can see what was changed and nothing suggests the whole server was taken over.
A rebuild or move to another platform becomes the safer choice when the software is no longer supported, when nobody can say how far the damage goes, when no clean recovery point exists, when the site depends on abandoned extensions, or when the infection keeps coming back after passwords, files and software have all been fixed. NIST's incident response guide treats restoring from clean backups, replacing files and rebuilding as different options for different situations, not as steps you must climb.
A word on backups. "Just restore the backup" is incomplete advice. A backup can bring the attacker's hidden access back with it if it was taken after the break-in, and restoring it without fixing the weakness leaves the door open. Check the date against when the problem likely started.
Shut every door the attacker used
Changing one password is rarely enough. Attackers often create extra ways back in before anyone notices them. After the cleanup, change every credential again, not just the website login: hosting, email, FTP or SFTP, database, domain registrar, and any API keys connected to the site. Then remove any accounts you do not recognize and turn on two-factor sign-in.
The weak point is not always on the server. WordPress's documentation and Hostinger's hacked-site guidance both point out that an infected office computer can be how passwords were stolen in the first place. Run a security scan on any computer used to manage the site before you type new passwords into it.
Finally, update everything: the core software, the theme, every plugin or extension, and anything the host runs underneath. Remove plugins and themes you no longer use, since a switched-off plugin can still be a way in.
Check where you stand in ten minutes, for free
These checks cost nothing and need no technical background:
- Search Console Security Issues: Screenshot every issue, its first-detected date and the sample URLs. While you are there, check that no unknown owners have been added to the property.
- A public scanner: Run your home page through VirusTotal or a similar service. Remember that remote scanners only see what a visitor sees, so a clean result is not proof. Never enter an admin address or password into a public tool.
- Other devices: Visit your site from a phone on mobile data and from a private window, and click through from a Google search.
- Your host's records: Photograph recent file changes, logins and resource use. List every admin, hosting, FTP, database and registrar user.
- Your own computer: Run your operating system's security scan and check browser extensions you do not recognize.
When you contact your host or anyone helping you, send one short incident note: the domain, when you noticed, screenshots, what Search Console shows, the suspect URLs, what platform the site runs on, what access you still have, and whether any customer information or payments pass through the site.
Protect your customers if their data was involved
If your site collects personal information or takes payments, a hack can become a data breach, and different rules apply. The FTC's guide says not to destroy evidence, to secure your operations, to work out what data and which people were affected, and to understand your notification duties. Every U.S. state has its own breach-notification law, and the triggers and deadlines vary, so this is the point to get legal advice. If card data may be involved, tell your payment provider; the PCI Security Standards Council's guidance explains that a suspected card breach may require an independent forensic investigator.
If ransomware is involved, CISA's ransomware guide is the reference, and it notes that paying does not guarantee your data comes back. This is general information, not legal advice.
Would you take these steps in the right order?
Pick an answer to begin.
1. You find spam pages on your site at 10 p.m. What comes first?
2. The redirect does not happen when you visit your own site. What does that mean?
3. When should you request Google's security review?
Frequently Asked Questions About my website got hacked what do i do
Should I take a hacked website offline?
Limit what visitors can reach, but save screenshots and records first. Ask your host to suspend the site or show a maintenance page rather than deleting files, which can destroy the evidence of how the attacker got in.
Can a hacked website be recovered?
Often, yes. A supported site with a clean backup or clean software files, a fixable way in and bounded damage can usually be cleaned and kept. A rebuild is safer when the software is unsupported, the damage cannot be scoped or the infection keeps coming back.
Can I just restore my website from a backup?
Only if the backup predates the break-in, and only if you also fix the weakness and change every password. A backup taken after the attacker got in can bring their access back with it.
How long does it take Google to remove a hacked-site warning?
After you request a review, Google says malware reviews usually take a few days and hacked-spam reviews can take several weeks. Warnings clear within a few days of a successful review.
Why can't I see the redirect on my own computer?
Hacks can be set to show only on mobile, only to visitors arriving from Google, or only to people who are not logged in. Test from a phone on mobile data and by clicking through from a search result.
Which passwords should I change after a website hack?
All of them connected to the site: hosting, website admin, email, FTP or SFTP, database, domain registrar and any API keys. Change them from a computer you have scanned, and again after the cleanup.
Moving Forward
When your website gets hacked, the first hour is about order, not speed: record what you see, contain the site through your host without deleting anything, change passwords from a clean device, and check Search Console's Security Issues report. After that comes the cleanup, closing the way in, and a review request that explains the issue, the fix and the outcome. Many hacked sites can be cleaned and kept, and a rebuild is the answer only when the platform or the damage makes cleaning unsafe.
Handled this way, you come out with more than a working site. You know how the attacker got in, the door is closed, your accounts are in your control, and you have a record you can point to if a customer or your payment provider asks what happened.
If the checks turn up unfamiliar accounts, changed files you cannot explain, or no clean backup, that is the point where a second pair of hands saves you from irreversible mistakes. At Web Leveling, our website security audit work traces how the attacker got in and what was touched, and when a cleanup is enough we will tell you so rather than quoting a rebuild. Once the site is clean, our website maintenance work keeps the software patched so the same door stays shut. We work with small and medium businesses across the country and overseas, wherever they are. Send us your screenshots and tell us what you found through our contact form, and we will tell you what we would check first.
Terms
Words you will meet while cleaning up
Tap a term to see what it means.
Security Issues report. The part of Google Search Console that lists malware, hacked content and deceptive pages Google has found on your site.
Security review. The request you send from that report once your site is clean, asking Google to remove its warnings.
Content injection. Pages, links or text an attacker adds to your site, often spam aimed at search results.
Malicious redirect. Code that sends some visitors to another site, often only on certain devices or from certain sources.
Clean backup. A copy of your site taken before the break-in, verified to be free of the attacker's changes.
Two-factor sign-in. A second step at login, such as a code on your phone, so a stolen password alone is not enough.
Incident note. A one-page summary of what you saw, when, and what access you have, to hand to your host or responder.

