How to Fix a Hacked Website: Step by Step Recovery Guide
Website hacked? Follow this step by step recovery guide to confirm the hack, contain the damage, clean files, restore Google trust and stop it happening again.

Discovering your website has been hacked is stressful. Maybe customers told you it redirects to a dodgy pharmacy page. Maybe Google is showing a red "This site may be hacked" warning. Maybe your host has suspended the account. Whatever the trigger, the good news is that most small business site hacks are recoverable, often within a day or two, if you work through the steps in the right order.
This guide covers exactly that order: confirm, contain, clean, harden and recover your reputation with Google. It is written mainly with WordPress in mind because it is the platform most often targeted, but the principles apply to any site.
Signs your website has been hacked
- Visitors are redirected to spam, gambling, adult or fake shop sites, sometimes only on mobile or only when arriving from Google.
- Google search results show strange titles or foreign language text under your domain.
- A browser or Google warning appears when visiting the site.
- Your host emails you about malware, high resource usage or spam sending.
- New admin users you did not create appear in your dashboard.
- Your homepage has been defaced or replaced.
- Emails from your domain start bouncing or landing in spam.
Some hacks are deliberately hidden from logged in admins, so check the site from a private browser window and on your phone using mobile data.
Step 1: Stay calm and document everything
Before you change anything, take screenshots of what you see, note the date and time, and save any warning emails from your host or Google. This helps whoever cleans the site understand what happened and when.
Step 2: Contain the damage
- Put the site into maintenance mode or ask your host to temporarily restrict it if it is actively harming visitors.
- Change every password: hosting control panel, FTP or SFTP, database, website admin accounts, and the email account linked to them. Use long, unique passwords.
- Enable two factor authentication on your host and admin accounts if available.
- Remove unknown admin users but note their usernames first.
- Tell your host. Many hosts have a security team and can share logs showing how the attacker got in.
Step 3: Take a backup of the hacked site
It sounds odd, but back up the infected site before cleaning it. If something goes wrong during the cleanup, you can return to this point rather than lose content. Label it clearly so nobody restores it by accident.
Step 4: Decide whether to restore or clean
If you have a clean backup from before the hack, restoring can be the fastest route. The catch is that you must know when the hack started, and you must fix the hole that let the attacker in, otherwise you will be reinfected within days.
| Approach | When it suits | Risks |
|---|---|---|
| Restore a backup | You have a recent backup clearly from before the infection | Losing recent content; reinfection if the weakness remains |
| Manual cleanup | No clean backup, or infection date unknown | Time consuming; easy to miss hidden backdoors |
| Rebuild | Site is old, badly infected or built on abandoned plugins | Takes longer upfront, but removes years of technical debt |
Step 5: Clean the files
For a WordPress site, a typical manual cleanup looks like this:
- Scan the site with a reputable security plugin or your host's malware scanner to get a list of suspicious files.
- Replace WordPress core files with fresh copies of the same version from the official source, leaving your wp-content folder and wp-config.php in place.
- Reinstall plugins and themes from official sources rather than trying to clean them. Delete any you do not use.
- Inspect wp-content/uploads for PHP files. The uploads folder should normally contain images and documents, not code.
- Check wp-config.php and .htaccess for unfamiliar code, especially long strings of scrambled text or redirect rules you did not add.
- Look for recently modified files using your host's file manager or command line. Attackers often leave backdoors with innocent looking names.
Clean the database
- Search posts and pages for injected scripts or hidden spam links.
- Check the options table for suspicious entries, particularly the site URL and home URL.
- Review the users table for accounts you do not recognise.
Step 6: Find and fix how they got in
Cleaning without fixing the cause is like mopping the floor with the tap still running. The most common entry points for small business sites are:
- Outdated plugins or themes with known vulnerabilities.
- Nulled or pirated premium plugins, which often come with malware built in.
- Weak or reused passwords on admin, hosting or FTP accounts.
- Old, forgotten installations in subfolders, such as a test site from years ago.
- Cheap shared hosting where one infected account can affect neighbours.
Update everything, remove what you do not need, and ask your host for access logs around the infection date.
Step 7: Recover your reputation with Google
- Verify the site in Google Search Console if you have not already.
- Check the Security Issues report to see what Google has flagged and on which URLs.
- Remove spam pages the attacker created, and let them return a 404 or 410 status.
- Request a review from the Security Issues report once you are confident the site is clean. Explain what you fixed.
- Monitor search results using a site: search for your domain to spot leftover spam pages.
Reviews are often processed within a few days, though it can take longer. Spam pages in search results typically fade over the following weeks as Google recrawls the site.
Step 8: Check your email and blacklists
If the hack sent spam from your domain, your email reputation may have suffered. Check your domain and server IP on public blacklist lookup tools, ask your host about delisting, and make sure your domain has SPF, DKIM and DMARC records set up.
Prevention checklist
- Update core, plugins and themes regularly, ideally weekly.
- Delete unused plugins, themes and old test sites.
- Never install pirated premium plugins.
- Use unique passwords and two factor authentication.
- Keep automatic offsite backups, and test restoring one occasionally.
- Use a security plugin or firewall service.
- Limit admin accounts to people who genuinely need them.
- Choose a host with malware scanning and isolation between accounts.
When to call in help
If you have followed the steps and the site keeps getting reinfected, the redirects only happen for some visitors, or you simply do not have the time, get professional help. Hidden backdoors are designed to survive amateur cleanups, and every day the site stays infected can cost you customers and search rankings.
SiteDrum's hacked site cleanup is a fixed $149: we remove the malware, close the hole, request the Google review and harden the site. For broken but not hacked sites, our Website Rescue is $99 fixed. Afterwards, an optional care plan at $15 per month keeps updates, backups and monitoring ticking over. If your old site is beyond saving, we can rebuild it on a plan from $99 setup, live in 7 days; see our pricing. We help businesses everywhere from New York to Singapore and Amsterdam.
A simple recovery timeline
| When | What to do |
|---|---|
| First hour | Document, restrict the site, change passwords, contact your host |
| Same day | Back up the infected site, scan, decide restore or clean |
| Day one to two | Clean files and database, update everything, close the entry point |
| Once clean | Request Google review, check email blacklists, rescan |
| Following weeks | Monitor search results, keep scanning, set up ongoing maintenance |
What about Wix, Squarespace or Shopify sites?
Hosted platforms manage server security for you, so file level malware infections are much rarer. When these sites are "hacked", it usually means someone gained access to the account itself, often through a reused password or a phishing email. The fix is different:
- Use the platform's account recovery process to regain access.
- Change the password and turn on two factor authentication.
- Remove unknown collaborators or staff accounts.
- Check domain settings to make sure nothing was pointed elsewhere.
- Review payment and payout details on any shop.
- Contact platform support and explain what happened.
Should you tell customers?
If the hack only defaced pages or added spam, a public announcement is rarely necessary. If customer data, such as contact form submissions, accounts or orders, may have been accessed, you may have legal obligations to notify people and sometimes a regulator, depending on where you operate. Get proper advice in that situation, and be honest with customers. Handled well, transparency usually protects trust better than silence.
Hacked site warning signs to check monthly
- Run a site: search for your domain and scan for pages you did not create.
- Check Google Search Console for security or manual action messages.
- Review the list of admin users and remove anyone who no longer needs access.
- Confirm backups are running and stored away from the main server.
- Visit the site on a phone using mobile data, arriving from a Google search.
- Look at your hosting resource usage for unexplained spikes.
Ten minutes a month is usually enough to catch problems early, when they are cheaper and faster to fix.
The bottom line
A hacked website is fixable. Contain it quickly, back up the infected version, clean or restore carefully, close the entry point, and ask Google to review the site. Then put simple prevention habits in place so you never have to do it again.
Frequently asked questions
How long does it take to fix a hacked website?
A straightforward infection can often be cleaned within a day. Google review of a security warning typically takes a few days, and spam pages can take a few weeks to drop out of search results.
Will my Google rankings recover after a hack?
Usually yes, once the site is clean and Google has reviewed it. Acting quickly helps, because the longer spam pages and warnings stay live, the more ranking damage they tend to cause.
Can I just restore a backup?
Only if you are confident the backup predates the infection, and only if you also fix the weakness that let the attacker in. Otherwise the site is often reinfected quickly.
Why was my small business website hacked?
Most attacks are automated, not personal. Bots scan the web for outdated plugins, weak passwords and abandoned installations, so small sites are targeted just as often as large ones.
Want a website that brings you customers?
Tell us what you do on WhatsApp and we will send a fixed quote and a free mockup.
Get my free mockupWebsite design in New York · Website design in London · Website design in Amsterdam · Website design in Singapore · Website design in Melbourne
More guides
- Website for Hair Salons and Barbers: What Actually Brings Bookings
- Restaurant Website Essentials: Menus, Bookings and Google in 2026
- Websites for Plumbers, Electricians and Builders: How to Win Local Jobs
- Local SEO for Small Business: The Complete 2026 Guide
- How to Optimise Your Google Business Profile (and Get More Calls)
- Wix vs Squarespace vs a Web Designer: Which Is Right for Your Business?
- Why Website Speed Matters (and How to Fix a Slow Site)
- How to Get More Google Reviews for Your Small Business
- Starting an Online Shop: Ecommerce Website Guide for Small Businesses
- How Much Does a Small Business Website Cost in 2026?
- Do I Need a Website If I Have Instagram?
- How to Get Your Business on Google Maps (Step by Step)
- WhatsApp or Website: Which Is Better for My Business?
- How Much Does a Domain Name Cost? A Plain-English Guide
- Free Website for My Business: Is It Worth It?
- What to Put on a Small Business Website: The Complete Checklist
- Why Is My Website Not Showing on Google? (And How to Fix It)