Maybe a customer rang to say your site is redirecting somewhere dodgy. Maybe Chrome is showing a red warning screen, or Google results for your business are full of pages you never wrote. However you found out, discovering your website has been hacked is a horrible moment, and the next few hours matter.
The good news: almost every hacked website can be fully recovered, usually within days. This guide walks through the whole thing in order, what to do first, how a proper clean works, how to get Google's warnings lifted, and how to make sure it never happens again.
How do I know if my website has really been hacked?
The common tells are redirects to spam sites, browser warning screens, search results showing pages you never created, unknown admin users, and a sudden traffic collapse. Some infections hide from the site owner on purpose, so you cannot always trust what you see when you browse your own site.
If you are not certain yet, run through our checklist of the 12 signs your website has been hacked, or run the six free checks for a yes-or-no answer. If two or more come back bad, treat it as confirmed and keep reading.
What should I do first?
Stay calm and work in this order. The first moves are about containing the damage and protecting the evidence, not fixing anything yet.
- Do not delete anything. The infected files are the evidence of how the attacker got in. Wipe them too early and you may clean the symptoms while leaving the door wide open.
- Change every password, from a clean device. Hosting control panel, CMS admin, database, FTP/SFTP and the email tied to those accounts. Use a computer you trust, in case the breach started with malware on your own machine.
- Contact your hosting company. Hosts deal with this daily. They can confirm what they see in the server logs, tell you when it started, and say what backups exist from before the infection.
- Put the site into maintenance mode if visitors are at risk. If the site is actively redirecting people or serving malware, a temporary holding page protects your visitors and your reputation while the clean happens.
- Write down what you see. Screenshots, strange URLs, dates and times. It speeds up the clean and helps with Google's review later.
Should I take my website offline?
Put it into maintenance mode if it is actively harming visitors, but do not delete files or restore a backup over the top. A restore feels like a fix, but if the backup already contains the infection, or the security hole stays open, the site is usually reinfected within days.
Many infections sit quietly for weeks before they are noticed, which means recent backups often contain the same malware. Until someone has worked out when and how the attacker got in, the current state of the site is your best source of answers. Preserve it, contain it, then clean it.
How does a hacked website get cleaned properly?
A proper clean works at hosting level, through the files and the database, not through a plugin inside the compromised site. The method: take a forensic backup, scan everything, compare files against known-clean copies, remove injected code and rogue files, hunt down backdoors and hidden admin users, update all software, rotate every credential, then verify the site is clean.
The step people miss is the backdoor hunt. Attackers almost always leave a second way in, a small innocent-looking file, a hidden admin account, a scheduled task, so that even after the visible malware is removed they can walk straight back in. Automated scanners catch known malware signatures but routinely miss these, which is why sites "cleaned" by a scan alone so often get reinfected within the month.
If your site runs on WordPress, the mechanics are specific enough that we have covered them separately in our guide to WordPress malware removal. And if you would rather hand the whole thing over, our hacked website repair service covers the full clean, the backdoor hunt and the Google review, for any platform.
How do I get Google's warnings removed?
Browser warnings like "Deceptive site ahead" come from Google Safe Browsing, and they only lift after you request a security review through Google Search Console, once the site is verified clean. Reviews are usually processed within one to three days.
The order matters: clean first, then request. Reviews requested before the infection is fully removed get rejected, and repeated failed requests slow everything down. The full walkthrough is in our guide to fixing the "Deceptive site ahead" warning.
Will my SEO and traffic recover?
Yes, if the site is cleaned promptly and properly. Once the spam pages return 404s and the security review passes, the junk drops out of Google's index and rankings usually settle back over a few weeks. The faster the clean, the smaller the dent.
Keep Search Console open through the recovery: watch the spam URLs fall out of the index and impressions climb back. We walk the whole rankings side, clearing flags, deindexing spam, realistic timelines, in recovering your SEO after a hack. And if rankings that matter are slow to return, that is a fixable problem, our SEO service deals with exactly that kind of rebuild.
How do I stop this happening again?
Nearly every hack comes down to something unpatched, something weak, or something forgotten. Closing those three doors is most of the job:
- Update discipline. Core software, plugins and themes patched promptly, weekly at minimum. Most attacks exploit vulnerabilities that were fixed months earlier.
- Strong access control. Unique passwords, two-factor authentication on every admin account, and no shared logins. Remove old users who no longer need access.
- Off-site backups. Automatic, tested, and kept somewhere the attacker cannot reach from the site itself.
- Monitoring. Uptime and file-change monitoring means the next problem is spotted in hours, not weeks.
That is upkeep, and it has to keep happening, which is why most businesses put it on a maintenance and hosting plan rather than trusting themselves to remember. Our guide to website maintenance and hosting covers what good upkeep looks like. And if this is your second or third infection, it is worth asking whether the platform itself is the problem: a hand-coded site with no plugin ecosystem removes most of the attack surface outright.
How much does it cost to fix a hacked website?
A straightforward infection on a typical small business site usually costs a few hundred euro to clean properly. Larger sites, deep infections or multiple hacked sites on one hosting account cost more, because there is simply more to inspect and verify. Acting quickly keeps the bill down: infections spread, and warnings compound the business damage the longer they stay up. The full pricing picture, including what the cheap options actually buy, is in how much malware removal costs.
We price each clean individually after a quick look at the damage, and you get a fixed quote before any work starts. See our hacked website repair service or request a quote and we will come straight back to you.
Frequently asked questions
Can I just restore a backup instead of cleaning?
Only if the backup pre-dates the infection and the security hole gets closed at the same time. Many infections sit unnoticed for weeks, so recent backups often contain the same malware, and restoring without fixing the entry point just resets the clock until the next attack.
How long does recovery take?
Most sites are cleaned within 24 to 72 hours. Google security reviews typically clear in one to three days after that, and any rankings wobble usually settles within a few weeks. The overall timeline is days, not months, provided the clean is thorough.
Why was my small business website hacked?
It almost certainly was not personal. The overwhelming majority of hacks are automated: bots scan millions of sites for known vulnerabilities and break in wherever they find one. Small business sites get hit constantly because they are more likely to be running outdated software.
Do I need to tell anyone my site was hacked?
If personal data may have been accessed, for example on a store or a site with customer accounts, you may have GDPR obligations, including notifying the Data Protection Commission within 72 hours. For a brochure site with no customer data, there is usually nobody you are required to inform.
Will visitors be able to tell it was hacked afterwards?
No. Once the site is clean, the warnings are lifted and the spam pages are gone from search results, no visible trace remains. The faster the clean happens, the fewer people ever see anything wrong.
Dealing with a hacked site right now? We clean infected websites on any platform, lift the Google warnings and close the door behind the attackers. Get emergency help.