Website Security

My Website Got Hacked — How to Tell, and What to Do Next

September 15, 2026 · 1 views

A hacked website rarely announces itself with a dramatic warning. Most of the time it's quieter than that: a strange redirect, a slow page, an odd file you don't remember uploading. By the time it's obvious — a Google "This site may be hacked" warning, or your hosting provider suspending your account — the damage has usually been sitting there for days or weeks.

Signs your website has been hacked

  • Unexpected redirects. Visitors land on your site and get bounced to an unrelated page — often ads, spam, or something obviously malicious.
  • A Google Safe Browsing or blacklist warning. If Chrome, Firefox or Google Search shows a "dangerous site" warning for your own domain, that's Google's crawler already having found something.
  • Unfamiliar admin users or files. An extra WordPress admin account you didn't create, or PHP files with random names sitting in your uploads folder, are classic signs of a backdoor.
  • A sudden traffic or ranking drop. Hacked sites frequently get de-indexed or demoted by Google once flagged, which shows up as a cliff-edge drop in organic traffic.
  • Your host emails you. Hosting providers routinely scan for malware and will suspend an account that's actively sending spam or hosting malicious files.

What to do first

Resist the urge to just delete files and hope for the best — that's how backdoors get missed and the site gets reinfected within days. Instead:

  • Change every password — hosting/cPanel, CMS admin, FTP/SFTP and database — assuming all of them may already be compromised.
  • Take the site offline or into maintenance mode if it's actively serving malicious content to visitors, to limit further damage to your reputation and rankings.
  • Don't just restore an old backup without knowing how the attacker got in — if the entry point (an outdated plugin, a weak password, a vulnerable theme) isn't fixed, the same backup or a fresh install gets hacked again just as fast.
  • Check for backdoors, not just the obvious symptom. The redirect or defaced page you can see is usually the least important part — the actual backdoor giving the attacker ongoing access is usually hidden elsewhere in the file system.

If any of this sounds like more than you want to untangle yourself, that's exactly what our hack & virus removal service handles — full malware and backdoor cleanup, blacklist-removal requests, and hardening so it doesn't happen again, all under a fixed price you only pay once the site is confirmed clean.

Is your website having a similar issue?

We diagnose and fix it within 24 hours — you only pay after the fix is confirmed.

Get a Free Diagnosis

More from the blog