Most website hacks are not dramatic. There is no ransom note and no obvious defacement, just a site quietly doing things it should not: redirecting visitors, hosting spam pages, sending junk email. Which is why the owner is so often the last to know.
Here are the twelve signs we check for, roughly in order of how often they are the thing that gives an infection away.
How can you tell if your website has been hacked?
A hacked website usually misbehaves for visitors or for Google before it misbehaves for you. The giveaways are redirects, browser warnings, search listings you do not recognise, unknown admin accounts and unexplained traffic changes. Any one of them deserves a proper look; two or more together almost always means an infection.
The 12 warning signs
1. Your site redirects visitors somewhere else
You type your address, and end up on a gambling, pharmacy or "you have won a prize" page. Redirect malware often only fires for first-time visitors, mobile users or people arriving from Google, so test in a private browsing window, not just as yourself.
2. Browsers show a red warning before your site loads
"Deceptive site ahead" or "This site may harm your computer" means Google Safe Browsing has found phishing content or malware on your domain. It is one of the clearest signals there is, and it stops nearly all your traffic dead. We cover the fix in removing the "Deceptive site ahead" warning.
3. Google results show pages you never wrote
Search for site:yourdomain.ie in Google. If the results include pages for designer handbags, pills or Japanese text, an attacker is using your domain to rank spam. The Japanese variety is common enough to have its own name and its own fix, covered in our guide to the Japanese keyword hack. This is one of the most common infections and often invisible when you browse the site normally.
4. Your host suspends the site or sends an abuse warning
Hosting companies scan for malware and spam activity. An email saying your account has been limited, or a suspension page where your site used to be, means their systems found something concrete. Take it at face value and act.
5. There are admin users you do not recognise
Check the user list in your CMS. Attackers create their own admin accounts so they can get back in after a clean-up, often with plausible names like "admin_support" or "wp_service". An account nobody on your team created is close to proof on its own.
6. Files have changed or appeared out of nowhere
Files with odd names, PHP files inside your uploads or images folders, or modification dates on core files that nobody was working on. If your host provides file-change reports, they will usually pinpoint the exact moment the infection landed.
7. The site is suddenly slow or the server is working overtime
Malware puts your server to work: sending spam, mining, attacking other sites. If pages that used to load instantly now crawl, and nothing about the site changed, something else is consuming the resources.
8. Spam email is going out from your domain
Bounce-back messages for emails you never sent, or your own emails suddenly landing in customers' junk folders, suggest the server is being used as a spam cannon. Blacklisted domains take real effort to rehabilitate, so this one rewards fast action.
9. Your traffic collapses, or spikes, overnight
A collapse usually means warnings or a Google penalty are turning visitors away. A spike can mean thousands of spam pages have been indexed under your domain. Either way, an unexplained step-change in analytics is a prompt to investigate, not celebrate.
10. The homepage has been defaced
The rarest but most obvious sign: your homepage replaced with someone else's message. Defacement is usually the work of low-skill attackers showing off, but it proves the site is wide open and needs the same full clean as any other infection.
11. Popups and ads you never added
Injected ad malware shows popups, banners or fake virus alerts to your visitors, sometimes only on mobile. If a customer mentions ads on your site and you do not run ads, believe the customer.
12. Customers tell you something is wrong
The unglamorous sign that catches many infections: someone rings to say your site "did something weird". Because plenty of malware hides from logged-in owners and shows itself only to fresh visitors, reports like this are worth taking seriously every time.
What should you do if you spot one of these?
Change your passwords from a clean device, contact your host, and do not delete anything: the infected files are the evidence of how the attacker got in. Then work through the recovery in order, our pillar guide on what to do when your website is hacked walks through every step.
If you would rather have it handled, our hacked website repair service takes over from this exact moment: we confirm the infection, clean it at hosting level and get any warnings lifted.
Can a website be hacked with no visible signs?
Yes. Cloaked infections show spam to Google's crawler while serving your normal site to human visitors, so everything looks fine even while your search listings fill up with junk. The site: search above and the Security Issues report in Google Search Console catch what your eyes cannot, and we walk through the full toolkit in how to check if your website is hacked.
This is also the argument for monitoring rather than luck. A maintenance plan with security scanning and file-change alerts turns "months of quiet damage" into "an alert the same day".
Frequently asked questions
How do hackers get into small business websites?
Almost always automatically: bots scan for outdated software, vulnerable plugins and weak passwords, then break in wherever something matches. It is rarely personal and never requires your business to be "worth targeting". Being reachable and unpatched is enough.
Will Google tell me if my site is hacked?
Only if you have verified your site in Google Search Console, which emails you when security issues are found. Without it, your first warning is usually the red screen your visitors see. Setting up Search Console takes ten minutes and is worth doing today.
Is it safe to browse my own hacked website?
Be careful. Do not log into anything through it, and avoid clicking wherever it redirects you. Checking from a private browsing window briefly is generally fine; poking around a site that is actively serving malware is a job for someone with the right setup.
How do I check for hidden admin users?
Open the users section of your CMS and account for every entry, including ones marked inactive. On WordPress, also compare the user count the dashboard reports with what the database shows, because some backdoors hide accounts from the admin screen itself.
Seeing one of these signs on your site? We will confirm whether it is an infection and clean it properly if it is. Get emergency help.