Take the site offline or into maintenance, restore a clean backup if you have one, change every credential, find how they got in, and only then bring it back. Cleaning without closing the entry point means it happens again.

What it actually looks like

Almost never a defaced homepage announcing what happened.

What businesses actually find is subtler: pages redirecting to somewhere else, but only on phones. Links injected into the footer that are invisible unless you read the source. The server sending spam. New pages appearing that nobody created.

None of that is obvious from looking at the site, particularly from the machine you always use, where the redirect frequently does not trigger.

Which is why the average compromise runs for weeks before anybody notices, and why it is usually a customer or a search engine that tells you.

How they get in

The first two account for the large majority. Neither requires anybody to have targeted your business, because both are found by automated scanning.

A worked example

A retailer whose site began sending mobile visitors to a different domain, roughly one visit in four.

Desktop visitors were unaffected, which is why nobody in the business saw it.

They found out when a customer phoned to ask why the site sent her somewhere selling something else entirely.

The entry point was an image gallery plugin last updated in 2017. The attacker had added code to a theme file and created a second administrator account.

Recovery took four days: restoring a backup from before the compromise, updating everything, removing the extra account, changing every password, and asking Google to review the site because it had been flagged.

Traffic took about two months to recover, and the business estimates it lost a month of online orders.

The plugin had not been used on any page for two years.

The first hour

  1. Take the site into maintenance mode or offline.
  2. Change the hosting and admin passwords immediately.
  3. Change your email password, since that is how access is regained.
  4. Tell your host, who may already know and can help.
  5. Do not simply delete what you find before understanding it.
  6. Take a copy of the compromised site before changing anything.

The sixth is counterintuitive and useful. That copy is the only evidence of how they got in, and cleaning first frequently destroys it.

The first matters because a compromised site actively harms visitors, and leaving it running while you investigate extends the damage.

Restore, or clean

Two approaches, and the choice depends on your backups.

Restoring a clean backup is faster and more reliable, provided you have one from before the compromise. Which requires knowing when it started, and retention long enough to reach back.

Cleaning in place means finding and removing every modification, which is slower, requires expertise, and carries the risk of missing something.

Restoring is nearly always the better option when it is available, and the reason it frequently is not is retention: a compromise found after three weeks needs a backup older than three weeks.

Which is the strongest practical argument for keeping monthly copies rather than only a rolling week.

Closing the entry point

The step that decides whether this happens again next month.

Restoring a backup returns the site to its previous state, including the vulnerability that let them in.

So the sequence is: restore, then immediately update everything, change all credentials, and remove anything unused before bringing the site back.

Businesses that restore and go straight back live are frequently compromised again within days, and conclude that the cleaning failed when in fact the door was still open.

What else to change

More than the site, because credentials on a compromised server are assumed exposed.

Hosting, the site admin, database, FTP, and anything stored in configuration files.

Any account whose password was reused anywhere, which is why the password audit belongs here.

And email, particularly if the site sent mail through an account whose credentials were on the server.

Also check for accounts you did not create, which is a standard step attackers take and one that survives a partial cleanup.

The search consequences

Frequently the most expensive part and the slowest to resolve.

A compromised site may be flagged, which produces a browser warning that stops most visitors entering.

Injected pages and links can affect rankings, and removing them does not restore position immediately.

After cleaning, request a review through Search Console, which is how a flag gets removed. That takes days rather than hours.

Recovery in rankings takes longer, typically weeks to a couple of months, which is why the total cost is far more than the cleanup time suggests.

The counter-case

Where paying somebody is clearly right rather than doing it yourself.

Anything involving customer data, where there may be notification obligations and where getting the assessment wrong has consequences beyond the site.

A shop taking payments, where the scope is wider than the website.

And any situation where you cannot establish how they got in, because cleaning without that answer is guessing.

Specialist cleanup services are not expensive relative to the cost of getting it wrong twice, and most hosts can recommend one.

Telling people

A judgement that depends on what was actually affected.

Where the compromise only touched the site itself, with no customer data involved, there is usually nothing to notify and a quiet fix is appropriate.

Where customer information may have been accessible, that is a different situation with its own obligations, and it needs proper advice rather than a judgement call.

Where visitors were being redirected somewhere harmful, telling customers what happened is worth doing even without an obligation, because some of them experienced it and drew conclusions.

A short, factual note saying what happened, what you did, and that it is resolved does more good than silence, particularly for the customer who phoned about it.

Afterwards

The changes that prevent a repeat, made while the memory is fresh.

Update on a schedule. Remove everything unused. Unique passwords with two-factor on the important accounts. Monthly backups kept beyond the rolling window.

And a check that would have caught it sooner: looking at the site on a phone occasionally, and watching for unexplained changes in traffic.

Most of that is an afternoon, and all of it is cheaper than the four days plus two months this costs.

The backup that makes recovery possible is covered in backups nobody has tested.


Frequently asked questions

What does a compromise look like?

Rarely a defaced homepage. Usually redirects affecting only phones, invisible injected links, spam being sent, or new pages nobody created.

How do they get in?

Mostly an outdated component with a published vulnerability, or a weak reused password. Neither requires anybody to target your business specifically.

What should I do first?

Take the site offline, change hosting and admin passwords, change your email password, tell your host, and copy the compromised site before changing anything.

Should I restore or clean?

Restore where you have a backup from before the compromise. Cleaning in place is slower and risks missing something.

Why do sites get compromised again?

Because restoring returns the vulnerability along with everything else. Update and change credentials before bringing the site back.

What about search rankings?

A flagged site produces a browser warning that stops visitors. Removing it needs a review request, and ranking recovery takes weeks to a couple of months.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Site behaving oddly on phones but not desktops?

That pattern is worth checking properly, because it is what a compromise usually looks like.

Start a Conversation