Skip to content
All articles
July 06, 2026·7 min read

Your site got hacked: what to do in the first hours and how to bring it back without losing clients

A step-by-step crisis plan for a hacked site: how to isolate, clean, restore, and what to tell clients so you don't lose their trust.

It's 9 a.m., you open your site to show it to a client and, instead of your page, up comes text in another language, an ad for pills, or a red Google warning: "This site may harm your computer." The first reaction is panic. The second, and wrong one, is to delete everything at random. A hacked site isn't the end of your business — but the first hours matter enormously, because every hour it stays infected means lost clients and lost trust.

Below is the exact plan, in the order we apply it when a frightened client calls.

The signs your site really is hacked

Not every problem is an attack. But some signs don't lie:

  • Strange redirects — someone visits your site and is sent to a betting or pharmacy page
  • New pages you never made — in foreign languages, full of links
  • A warning in Google or the browser ("deceptive site", "dangerous")
  • An email from your host saying they've suspended your account for spam or malware
  • Suddenly slow site, or one sending emails in your name without your knowledge

If you see even one, treat it as an emergency, not a glitch.

Step 1: Isolate, don't delete

The instinct is to delete the suspicious file. Resist it. First you isolate, so it doesn't spread and so you keep the evidence:

  • Put the site into maintenance mode (a simple "Back soon" page), so visitors stop seeing the infected content and Google doesn't penalize you further
  • Change all passwords: admin, hosting, FTP, database, email. From a different, clean device
  • Don't delete anything yet — a hacked site is a "crime scene". You need the files to understand how they got in

Step 2: Find how they got in

If you don't find the cause, you clean in vain — they're back the next day. The way in is usually one of:

  • An outdated plugin or theme with a known hole
  • A weak password or one reused from another already-compromised account
  • A form or an upload that let a file slip through
  • An old account belonging to someone who no longer works with you

Look at the modified dates of the files: the ones touched on the very day of the attack show you the path.

Step 3: Clean thoroughly

Here's the difference between "looks clean" and "is clean":

  • Delete the foreign files and injected code, not just the visible symptom
  • Reinstall the platform core, themes, and plugins from official, clean sources
  • Check the admin accounts — hackers often leave a hidden account as a "back door"
  • Scan the database for injected links and scripts

The rule we work by: we don't declare a site clean until the cause is fully gone, not just the effect.

Step 4: Restore from a backup — if you have a clean one

A backup is the fastest way back — on one condition: it must be from a moment before the infection. If you restore an already-infected backup, you bring the hacker right back with it. That's why an automatic, daily backup kept separately is the cheapest insurance you can have. If you have no backup, manual cleaning is the only option — slower and more expensive.

Step 5: Clear the "dangerous" flag

Once the site is clean, you tell the outside world too:

  • Ask Google for a review in Search Console, so it removes the red warning
  • Ask your host to lift the suspension
  • Bring the site back online and check it from your phone and your computer, like an ordinary visitor

What to tell your clients — the part many miss

Silence scares people more than the truth. If you had an incident and your clients have data with you, a short, honest note is worth more than ten late apologies: what happened, what you fixed, and what they should do (for example, change their password). Honesty here is a business strategy, not just good manners.

How to avoid a repeat

A site hacked once will be hacked again if you change nothing. The basics:

  • Up-to-date updates for the platform, themes, and plugins
  • Daily automatic backups, kept separately from the site
  • Unique, strong passwords, plus two-step authentication
  • Fewer plugins — each extra one is an extra door

This is exactly what we cover in our maintenance, from 29 €/month: updates, backups, and someone who picks up the phone when something creaks. It's far cheaper to prevent than to repair a crisis.

Conclusion

A hacked site is an emergency, but it has a clear plan: isolate, find the cause, clean thoroughly, restore from a clean backup, clear the warnings, and communicate honestly with your clients. If you're right in the middle of a situation like this — or you want to make sure you never get there — write to us on WhatsApp and we'll build you a free demo site that's clean, fast, and properly set up: wa.me/40750257140.

Frequently asked questions

How do I tell if my site is hacked and not just down?+

A site that's down simply won't load. A hacked site loads but shows something else: redirects to betting or pharmacy pages, new pages in foreign languages, a red warning in Google or the browser, or an email from your host about spam or malware. If you see any of these, treat it as an attack.

It's the first time — do I delete everything and start over?+

Not at random. First you isolate: put the site into maintenance and change all passwords from a different, clean device. Don't delete the files right away, because you need them to find how the attackers got in. If you clean without finding the cause, the hacker is back the next day.

Can I just restore a backup and be done?+

Only if the backup is from a safe moment, before the infection. A backup made after the attack already contains the malicious code and brings the problem right back. That's why an automatic, daily backup kept separately matters — you always have a clean version to return to.

How long and how much does it cost to fix a hacked site?+

It depends on how deep the attack went and whether you have a clean backup. With a backup, restoring is a matter of hours. Without one, manual cleaning is slower and more expensive. Prevention — maintenance from 29 €/month — costs far less than a crisis.

Do I have to tell my clients I was hacked?+

If the attack could have affected their data, yes. A short, honest note — what happened, what you fixed, what they should do — keeps trust better than silence. Clients forgive a problem handled transparently; they forgive far less easily finding out from somewhere else.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
Free · no obligation

Want to see what your business's website could look like?

Message us on WhatsApp and we'll prepare a FREE demo website with your business name. See it first — decide after.

Request a free demo websiteWe reply on WhatsApp within minutes