Website hacked, defaced or serving malware: what to do first
A compromised website can quietly redirect visitors, mine their browsers, harvest payment details or simply display a defaced page — and every hour it stays live can add to a search-engine blocklist entry or a hosting suspension.
This page sets out a safe order of work for a hacked CMS, plugin or hosting account, what to preserve before you touch anything, and where Cyber Crisis Desk turns those steps into a tracked plan.
Signs your host, CMS or plugins are compromised
- A defacement page, ransom note or unfamiliar redirect replacing your content.
- Browser or search-engine warnings such as "this site may be hacked" or "deceptive site ahead".
- Unexpected pop-ups, pharmaceutical or gambling spam pages appearing under your domain.
- Unfamiliar admin users, editors or API keys in your CMS that nobody on your team created.
- Files with recent modified dates you did not touch, or new files in upload or theme folders.
- A sudden spike in outbound traffic, CPU usage or emails your server did not normally send.
- Customers reporting odd checkout behaviour, card errors or being redirected elsewhere.
- A plugin, theme or CMS core that you know has been out of date for some time.
Safe immediate actions, in order
- Take the site offline or into maintenance mode rather than deleting anything — a holding page stops further harm to visitors while you investigate.
- Preserve server and access logs before you change anything. Export web server logs, FTP/SFTP logs, CMS audit logs and hosting control-panel activity logs, since some providers rotate or purge these quickly.
- Take a full backup of the site as it currently stands — files and database — even though it is compromised. This preserves evidence and gives you a fallback if the rebuild goes wrong.
- Rotate every credential connected to the site: CMS admin accounts, FTP/SFTP, database, hosting control panel, DNS registrar and any third-party API keys (payment gateway, email sending, analytics).
- Review admin and editor accounts in the CMS and hosting panel, and remove any you cannot account for.
- Check for injected or unfamiliar files, especially in theme, plugin, upload and temporary directories, and compare against a known-good backup or a fresh install where possible.
- Rebuild from a known-good source rather than patching the infected copy: a clean CMS core, official plugin/theme files and only your genuine content and data restored back in.
- Update everything before going live again — CMS core, plugins, themes and server software — and remove anything unused or unsupported.
Evidence worth preserving
- Web server access and error logs covering the period before and after you noticed the issue.
- FTP/SFTP and hosting control-panel login history, with IP addresses and timestamps.
- CMS audit or activity logs, including user creation, plugin installs and file edits.
- A copy of the defaced or infected files, and screenshots of what visitors saw.
- A list of admin, editor and API accounts as they existed at the time you noticed the problem.
- Any notice from your host, search engine or browser vendor about the compromise.
What to avoid
- Do not simply delete the infected files without a backup — you may remove the only evidence of how the attacker got in.
- Do not restore from an old backup without checking how far back the compromise goes; you may reintroduce the same weakness.
- Do not leave the site live "to keep sales going" once you know it is serving malware or redirecting visitors.
- Do not attempt to identify, trace or retaliate against whoever is responsible. Cyber Crisis Desk is strictly defensive: no hack-back, no tracing.
- Do not reuse any of the old credentials, even slightly modified.
Who else may need to be involved
- Your hosting provider — many can confirm suspicious activity, provide raw logs, or may have already suspended the account for abuse.
- Your developer or agency — if someone else manages the CMS, plugins or server, they need to be part of the rebuild.
- Search engines and browser vendors — once cleaned, request a review through their webmaster tools so any "hacked site" or blocklist warning is lifted.
- Your payment provider — if the site handles card payments and could have been skimming details.
- Your data-protection regulator — if customer personal data was likely accessed. In the UK that is the ICO; other countries have their own authority.
- National reporting channels — for example Action Fraud and the NCSC in the UK, and the equivalent body where you operate.
Cyber Crisis Desk is not a law-enforcement, legal or forensic service and does not report on your behalf. It prepares the structured information you need to do so.
How Cyber Crisis Desk helps
A free emergency triage takes a few questions about what you are seeing, whether the site is still live and whether customer data is involved. From that, the platform selects a website-compromise playbook and builds an Immediate Rescue Plan grouped by urgency.
- Client Next Action gives you one clear step at a time instead of a wall of advice.
- Evidence requests tell you exactly which logs and files to capture before a rebuild, and store them in your private case.
- Recovery tracks record which credentials have been rotated and which components rebuilt, so nothing is half-finished.
- Structured reports assemble the timeline and evidence into a document for your host, insurer or regulator.
- Monitoring and closure keeps the case open until follow-up checks actually pass.
See how the guided workflow fits together or compare the plans and the one-time Emergency Pass.
Clear limitations
- We cannot access, rebuild or administer your hosting account or CMS for you — only you or your developer can perform those changes.
- We do not perform in-depth forensic malware analysis or reverse engineering, and we do not guarantee any outcome.
- This is guided response, not a substitute for a qualified developer or incident-response specialist where the compromise is severe or ongoing.
- We do not provide legal advice or make legal determinations for you.
Common questions
- Should I take the site down straight away?
- Usually yes — a maintenance page or temporary offline state stops further harm to visitors and buys you time, without destroying the evidence a full deletion would.
- Can I just restore yesterday's backup?
- Only once you know the compromise did not exist in that backup too. Check logs to establish roughly when the attacker got in, and restore from before that point where possible.
- How do search engines find out the site is clean again?
- After removing the malicious content and closing the entry point, submit a review request through the relevant webmaster or search-console tool. Warnings are usually lifted once the review confirms the site is clean.
- Do I need to tell customers?
- If customer personal data or payment details could have been accessed, most jurisdictions expect notification within a set timeframe. Check your national data-protection authority's rules early.
Related incident help
- Ransomware responseIsolate, protect backups, assess scope and decide next steps calmly.
- Data breach concernsWork out what data was exposed, who to tell and what to document.
- Small-business incident responseCoordinate a response when you have no internal security team.
- How Cyber Crisis Desk worksTriage, playbooks, rescue plan, evidence, recovery, reporting and closure.
Work through it with a plan
Emergency triage is free and takes a couple of minutes.