Insights Security

Your website got hacked: what to do in the first 24 hours

Found spam pages, strange redirects or a Google warning on your site? Here are the calm steps for the first 24 hours after a hack and how to get Google to lift warnings.

AI-generated image

You search for your business and Google shows a warning under your name. Or a customer calls to say your site sent them to some pill shop. Or your host emails to say your account is suspended. Your stomach drops. That's normal. What you do in the next day matters more than how you found out.

If your website got hacked, slow down before you delete anything. Save a copy of the site as it is, change every password, call your host, then restore from a backup made before the hack and find how they got in so it doesn't happen again. Once it's clean, ask Google to review the site so the warnings come off.

Signs your site has been hacked

Some hacks are loud. Most are quiet, because the people behind them want your site to keep running for their purposes. Google's own guide notes that "Hacks are often invisible to users, yet remain harmful to anyone viewing the page, including the site owner." Watch for these:

  • Pages you never made, often selling pills, knockoffs or gambling, sometimes in another language.
  • Visitors, especially on phones or coming from Google, get sent to a different site.
  • Google search results show strange titles or descriptions for your pages.
  • Browsers show a red warning page before your site loads.
  • Google Search Console, Google's free tool for site owners, flags a security issue.
  • Your host suspends your account or emails about malware, which is harmful code slipped onto a site.
  • Admin users you don't recognize, or your own login suddenly stops working.

The first hour: stop, save, lock down

1. Don't panic delete

The urge is to delete the bad pages and move on. Resist it. Deleting files by hand usually removes the visible damage and leaves the hidden part, like a back door that lets them walk right back in. It also destroys the clues that show how they got in.

Hacked website recovery steps Seven steps for the first day after a website hack, in two phases. The first hour, stop, save and lock down: 1 Don't panic delete, because deleting files by hand leaves the hidden back door and destroys the clues. 2 Take a snapshot of the files and database as they are, labeled as the hacked copy. 3 Change every password, including hosting, FTP, database, CMS, domain registrar and email. 4 Call your host, who can take the site offline safely and show you server logs. The next day, restore, close the hole and ask for review: 5 Restore a clean backup from before the first sign of trouble, then apply every update. 6 Find how they got in, starting with compromised passwords, missed updates and insecure themes and plugins. 7 Fix everything first, then use Request Review in Google Search Console. Google says most reconsideration reviews can take several days or weeks. Hacked? The first day, step by step Slow down before you delete anything THE FIRST HOUR Stop, save, lock down 1 Don't panic delete Hand deletes leave the back door and destroy the clues 2 Take a snapshot Copy files and database as is Label it the hacked copy 3 Change every password Hosting, FTP, database, CMS, registrar and email 4 Call your host They can take it offline safely and show you server logs THE NEXT DAY Restore, fix, review 5 Restore a clean backup From before the first sign then apply every update 6 Find how they got in Passwords, missed updates, insecure themes and plugins 7 Request a Google review Fix everything first, then use Request Review in Search Console Reviews take time Google says most can take several days or weeks
Seven steps for the first day after a hack, from saving a copy of the damage to asking Google to lift its warnings.

2. Take a snapshot

Make a full copy of the site as it is now, files and database. The database is where your pages, posts and form entries live. Label it clearly as the hacked copy and keep it apart from your good backups. You'll want it for figuring out what happened, and you never want to restore from it by mistake.

3. Change every password

Google's recovery guide is specific: "Change the passwords for all site users and accounts. This includes logins for FTP, database access, system administrators, and content management system (CMS) accounts." FTP is the file transfer login your developer may use. Add your hosting account, your domain registrar and the email account tied to them. Use new, unique passwords, and turn on two step login where you can.

While you're in there, look at your admin users. The same guide advises writing down any accounts you don't recognize before you delete them, because those names help with the investigation.

4. Call your host

Google's guide says to "contact your hoster to make them aware of the situation." Your host can often take the site offline safely, show you server logs and tell you if other sites on the account are affected. If they suspended you, ask exactly what they found and what they need to lift it. Taking the site offline for a while during cleanup is fine. Google says it's unlikely to affect your future search rankings.

The next day: restore, close the hole, ask for review

5. Restore from a clean backup

A clean backup is one made before the hack started. That can be harder to pin down than it sounds, since hacks often sit quietly for weeks. Pick a backup from before the first sign of trouble, restore it, then apply every update right away. Anything added since that backup, like new blog posts or form entries, may need to be put back by hand.

No clean backup? Then the site needs to be cleaned file by file, which is slow, specialized work. This is the moment most owners wish they'd had tested backups.

6. Find how they got in

If you restore without fixing the entry point, you've just rebuilt the same unlocked house. Google's guide on common causes lists compromised passwords, missed security updates and insecure themes and plugins near the top. It also warns that "Because there may be multiple, independent hacks in place, even if you're able to find and fix one vulnerability, we recommend continuing to search for others." A vulnerability is a known weak spot in software. Check for outdated plugins, old admin accounts and anything installed from an untrusted source.

7. Check Search Console and request a review

If Google flagged your site, open the Security Issues report in Google Search Console. According to Google, "If a Google evaluation determines that your site was hacked, or that it exhibits behavior that could potentially harm a visitor or their computer, the Security issues report will show Google's findings."

Fix everything first. Google is clear that "Fixing the issue on just some pages will not earn you a partial return to search results." When it's all clean, select Request Review and describe what you fixed. Google says "Most reconsideration reviews can take several days or weeks," so the sooner the site is truly clean, the sooner the clock starts.

If customer data was involved, tell people

If your site stores customer information, like form submissions, account logins or order details, assume it may have been seen until you know otherwise. Figure out what was stored and for how long. Then talk to your insurance carrier and a lawyer about what you owe customers, since the rules depend on what data it was and where your customers live. I'm not giving legal advice here. My advice is simpler: when people's information may be exposed, telling them plainly and early usually protects trust better than silence.

Handling a hack yourself: what it takes

You can recover a hacked site on your own. Google publishes a step by step guide, and plenty of owners have worked through it. Be honest with yourself about the cost.

  • Time. A simple case can take an afternoon. A messy one, with no clean backup and several back doors, can eat days.
  • Skills. You'll be comparing files, reading server logs, working in a database and knowing which code belongs and which doesn't.
  • Tools. Hosting access, a file manager or FTP, database access and a malware scanner you trust.
  • The risk. The common DIY failure is a site that looks clean and gets reinfected a week later because one hidden file was missed. Each round with Google's warnings up costs you visitors.

If you're technical and patient, it's doable. If you're running a business at the same time, that's a lot to take on under pressure.

After it's fixed: make the next one less likely

Once you're clean, the goal is fewer open doors and a faster recovery if it happens again. The security basics checklist covers the day to day habits. The short version:

  1. Keep WordPress, themes and plugins updated, and delete what you don't use.
  2. Remove old admin accounts and keep passwords unique.
  3. Keep daily backups off the server, and test a restore.
  4. Watch Search Console and your site's uptime so you hear about problems first.
  5. Make sure your domain and hosting are in your name.

This is what our care plan is built around. We handle updates and security patches, keep daily backups with restores we actually test and monitor for downtime and broken forms. Our hosting puts your site on servers we manage, so one team knows both your site and the machine it runs on. No one can promise you'll never be hacked. We can make sure you're not alone figuring it out. For the full list of what upkeep should cover, see what website maintenance should include.

If you'd like someone watching your site before the next scare, ask us about a care plan.

Find out what your website is leaking.

Send us your site. We’ll check your forms, your phone speed and how Google sees you, then tell you plainly what’s worth fixing. If the answer is “nothing much”, we’ll say that too.

Get my free Lead Leak Check

No cost. No obligation. A real person replies within one business day.