Signs your site has been hacked
- Visitors get redirected to another site, often only on mobile or only from Google
- Google shows 'This site may be hacked' under your listing
- Pages you didn't create appear in search results, often in another language
- New admin users or files you don't recognise
- Your host suspends the site or emails you about malware
The first hour, step by step
Don't delete anything yet
It's tempting to delete strange files straight away. Take a full backup of the site's files and database first, exactly as they are. You'll need it to work out how the attacker got in, and to recover anything the clean-up breaks.
Change your passwords from a clean device
Hosting account, WordPress admin users, SFTP or FTP, the database and the email accounts tied to the site. Use a device you trust, and turn on two-factor login wherever it's offered.
Protect your visitors
If the site is redirecting people or serving malware, put it into maintenance mode or ask your host to take it offline for now. A few hours offline does less damage than sending customers to a scam site.
Tell your host
Most hosts have seen it many times. They can confirm what they've detected, restore a backup and tell you whether other sites on your account are affected.
Check Google Search Console
Open the Security issues report. It shows whether Google has flagged the site and gives examples of the affected pages.
Work out whether customer data was exposed
If customer information may have been accessed and that's likely to cause serious harm, the Privacy Act 2020 requires you to notify the Privacy Commissioner and the affected people as soon as practicable. The Privacy Commissioner's breach guidance explains how to decide.
Pause your ads if the site is unsafe
Google Ads disapproves ads that point to compromised sites, and can suspend the account. Pausing the campaigns while you clean up stops you paying to send people to a hacked page.
Clean it up properly
Find the way in, usually an outdated plugin or theme or a stolen password, and close it. Then restore from a clean backup or clean the files by hand, update everything, remove admin users you don't recognise and reset security keys. A security plugin on its own often misses backdoors.
Ask Google to review the site
Once it's clean, request a review in Search Console, and in Google Ads and Merchant Center if either suspended you.
If you'd rather hand it over, we clean up hacked sites, find how the attacker got in and deal with the Google review requests. See hacked website repair.