Work in order: take the site offline or into maintenance, preserve a copy before changing anything, restore from a backup predating the compromise, then find and close the entry point. Cleaning the visible damage first feels productive and is the step that guarantees a repeat, because the way in is still open.

Confirming it actually happened

Not everything that looks like a compromise is one. A blank page is usually an error, and unexpected changes are sometimes a plugin update.

The signals that genuinely indicate a break-in: content you did not write, redirects sending visitors elsewhere, a browser or search warning about the site, unfamiliar administrator accounts, files with recent modification dates nobody can account for, or a sudden volume of outbound mail from the server.

Where the site looks normal to you and a warning appears in search results, check on a phone from a different network. Some compromises show the altered version only to visitors arriving from search, which is why the owner is frequently the last to see it.

The order of operations

1. Take it out of public view

A maintenance page or a temporary block. This stops visitors being served malicious content, stops search engines recording more of it, and stops the server being used to send mail in your name.

It also removes the pressure to rush the rest, which is where most recovery mistakes come from.

2. Copy everything before touching it

Files and database, exactly as they are. This is the step people skip because the instinct is to clean.

You need it for two reasons: it is the only evidence of how the compromise happened, and if the restore turns out to be incomplete or the backup is older than you thought, it is the only copy of recent content.

3. Change credentials from a clean device

Hosting, control panel, database, all administrator accounts, and the registrar. From a machine you are confident about, since changing passwords from a compromised computer achieves nothing.

Remove any administrator accounts you do not recognise rather than only changing their passwords.

4. Restore from before it happened

The difficulty is knowing when it happened, which is usually earlier than the day you noticed. File modification dates and server logs help, and where the timeline is unclear, going further back is safer than restoring a copy that already contains the problem.

This is where multiple restore points matter. A single overnight backup can only return you to yesterday, which is no help for something that started three weeks ago.

5. Find how they got in

The step that determines whether this is over. Common routes are an outdated plugin or theme with a known vulnerability, a weak or reused administrator password, credentials taken from a compromised computer, or an abandoned installation in a subfolder nobody remembered.

If this is not answered, the same route is still open and the site will be back in the same state shortly.

Then, before going live again

The cleanup mistake

The natural response is to find the injected code and delete it, then carry on.

It is unreliable because compromises typically leave several things: the visible payload, one or more backdoors in unrelated files, sometimes a modified core file, and occasionally an administrator account. Finding four of five is the same as finding none, since the remaining one restores the rest within days.

Restoring from a clean backup and rebuilding forward is more reliable than cleaning, precisely because it does not depend on finding everything.

What it costs beyond the fix

Worth understanding because it shapes how seriously to take prevention.

A search warning suppresses traffic until reviewed. Mail sent from the server can get your domain listed, which affects invoices and quotes for weeks afterwards. Customers who saw the warning may not return. And if customer data was involved, there may be notification obligations, which is a question for someone qualified rather than a judgement call.

What actually prevents a repeat

Updates applied promptly rather than eventually, unused plugins and themes removed rather than deactivated, unique passwords with a second factor on every administrator account, and backups with multiple restore points held somewhere other than the same server.

None of that is exotic and all of it is the difference between an incident that takes an afternoon and one that takes a fortnight. The account protection half of it is covered in two-factor authentication on the accounts that matter.


Frequently asked questions

What should I do first if my website is hacked?

Take it out of public view with a maintenance page, then copy the files and database before changing anything. The copy is the only evidence of how it happened and the only record of recent content.

Should I just delete the malicious code?

Cleaning is unreliable, because compromises typically leave several backdoors in unrelated files. Finding four of five is the same as finding none. Restoring from a clean backup is more dependable.

How do I know which backup to restore?

Look at file modification dates and server logs to estimate when it started, which is usually earlier than the day you noticed. Where the timeline is unclear, going further back is safer.

How do sites usually get compromised?

An outdated plugin or theme with a known vulnerability, a weak or reused administrator password, credentials taken from an infected computer, or an abandoned installation in a subfolder nobody remembered.

Why does my site look normal but search shows a warning?

Some compromises serve the altered version only to visitors arriving from search, which is why the owner is often the last to see it. Check on a phone from a different network.

What does a compromise cost beyond fixing it?

A search warning suppresses traffic until reviewed, mail sent from the server can get your domain listed and affect invoices for weeks, and customers who saw a warning may not return.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Site compromised, or worried it could be?

We handle the recovery in the right order and close the entry point, so it does not happen again a fortnight later.

Start a Conversation