How to Recognise a Website Hack
Website hacks don't always announce themselves dramatically. Attackers frequently prefer to remain undetected - inserting malicious code that runs invisibly in the background, redirecting visitors to spam sites, or harvesting contact form data. Signs your site may have been compromised include:
- Google Search Console warning: "This site may be hacked"
- Google Safe Browsing flagging your domain as unsafe
- Unusual content appearing on your pages (spam links, foreign language text, adult content)
- Visitors being redirected to unfamiliar third-party websites
- Your hosting account suspended for "malicious activity" or "abuse"
- Dramatically increased server resource usage with no obvious cause
- Contact form submissions or login attempts spiking unexpectedly
- New admin users appearing in your CMS that you didn't create
- Files modified at unexpected times in your hosting file manager
- Antivirus software warnings when colleagues visit the site
Step One: Don't Panic - But Do Act Immediately
The first instinct for many business owners is to delete everything and start again. Resist this. Deleting files before properly documenting the attack destroys your ability to understand how the breach occurred - and that understanding is essential to prevent it happening again.
Your first actions should be:
- Take your site offline if it is actively serving malicious content or redirecting visitors. Put up a maintenance page. Continuing to serve a compromised site damages visitor trust, harms your Google rankings, and may create legal liability if personal data is being exfiltrated.
- Change all passwords immediately - your CMS admin, hosting panel, FTP accounts, database access, and any connected third-party services. Use strong, unique passwords generated by a password manager.
- Revoke API keys and integrations - anything that connects external services to your site should be considered potentially compromised until proven otherwise.
- Document what you can see - screenshots, URLs of affected pages, any error messages, timestamps of when anomalies first appeared.
- Do not restore from backup yet - unless you are certain the backup predates the compromise and you understand the attack vector. Restoring into a still-vulnerable environment will simply result in re-infection.
Understanding How It Happened
Before recovery can truly begin, the entry point must be identified. Common attack vectors for small business websites include:
- Outdated CMS or plugin versions - The vast majority of hacked websites were running known-vulnerable versions of software at the time of attack. WordPress, in particular, is a frequent target because its popularity makes it worth writing automated exploitation tools for.
- Weak or reused passwords - Brute-force and credential-stuffing attacks are automated and relentless. A weak admin password is an open door.
- Compromised third-party plugins or themes - Not all plugins are written with security in mind. Some are abandoned by their developers, leaving known vulnerabilities permanently unpatched.
- Unsecured file upload functionality - Contact forms, portfolio upload features, or e-commerce file submissions that don't properly validate content can be used to upload malicious scripts.
- Shared hosting environments - On poorly-configured shared hosting, a compromise on one site can spread laterally to neighbouring accounts.
- Supply chain attacks - A plugin or theme that was previously legitimate may have been acquired by malicious actors, or a developer's account may have been compromised, causing a malicious update to be pushed.
The Google Safe Browsing list is updated continuously. If your site is flagged, it will display warnings in Chrome, Firefox, and Safari - and your Google search traffic will collapse within hours. Recovery from a Google blacklisting can take days even after the malware has been removed. Speed matters.
The Recovery Process
Professional website hack recovery typically follows this sequence:
- Forensic scan - A thorough file-by-file scan of the hosting environment to identify all malicious files, injected code, and backdoors. Simply removing visible malware while leaving backdoors in place guarantees re-infection.
- Identify the attack vector - Understand precisely how the attacker gained access. This is non-optional: without it, you cannot prevent a recurrence.
- Clean or restore - Either manually clean affected files or restore from a pre-compromise backup. In most cases, a combination of both is required.
- Patch and harden - Update all software to current versions, remove unused plugins and themes, implement a Web Application Firewall (WAF), and lock down file permissions.
- Submit for Google review - If your site was flagged by Google Safe Browsing, a reinclusion request must be submitted through Google Search Console once the site is clean.
- Monitor for recurrence - Implement ongoing malware scanning and alerting so that any future compromise is detected in minutes, not weeks.
Do You Have an Obligation to Report It?
If your website processes, stores, or transmits personal data - contact form submissions, customer accounts, payment information - a security breach may trigger legal obligations under UK GDPR. Specifically, if the breach is likely to result in a risk to individuals' rights and freedoms, you must notify the ICO within 72 hours of becoming aware of it.
This is not an area to guess at. If there is any possibility that personal data has been exposed, seek legal advice alongside your technical recovery efforts.
Why DIY Hack Recovery Often Fails
Many business owners attempt to recover a hacked site by restoring from a backup and hoping for the best. This approach fails for three reasons: the backup may itself be compromised; the underlying vulnerability remains; and backdoors left by the attacker will allow re-infection within hours or days. Professional emergency remediation addresses all three simultaneously.