Website hacked? What to do in the first hour

A practical checklist for NZ small businesses, in the order we'd do it. Most of it applies to any website, and the clean-up section assumes WordPress.

Signs your site has been hacked

signs.log5 entries
  • Visitors get redirected to another site, often only on mobile or only from Google
  • Google shows 'This site may be hacked' under your listing
  • Pages you didn't create appear in search results, often in another language
  • New admin users or files you don't recognise
  • Your host suspends the site or emails you about malware

The first hour, step by step

  1. Don't delete anything yet

    It's tempting to delete strange files straight away. Take a full backup of the site's files and database first, exactly as they are. You'll need it to work out how the attacker got in, and to recover anything the clean-up breaks.

  2. Change your passwords from a clean device

    Hosting account, WordPress admin users, SFTP or FTP, the database and the email accounts tied to the site. Use a device you trust, and turn on two-factor login wherever it's offered.

  3. Protect your visitors

    If the site is redirecting people or serving malware, put it into maintenance mode or ask your host to take it offline for now. A few hours offline does less damage than sending customers to a scam site.

  4. Tell your host

    Most hosts have seen it many times. They can confirm what they've detected, restore a backup and tell you whether other sites on your account are affected.

  5. Check Google Search Console

    Open the Security issues report. It shows whether Google has flagged the site and gives examples of the affected pages.

  6. Work out whether customer data was exposed

    If customer information may have been accessed and that's likely to cause serious harm, the Privacy Act 2020 requires you to notify the Privacy Commissioner and the affected people as soon as practicable. The Privacy Commissioner's breach guidance explains how to decide.

  7. Pause your ads if the site is unsafe

    Google Ads disapproves ads that point to compromised sites, and can suspend the account. Pausing the campaigns while you clean up stops you paying to send people to a hacked page.

  8. Clean it up properly

    Find the way in, usually an outdated plugin or theme or a stolen password, and close it. Then restore from a clean backup or clean the files by hand, update everything, remove admin users you don't recognise and reset security keys. A security plugin on its own often misses backdoors.

  9. Ask Google to review the site

    Once it's clean, request a review in Search Console, and in Google Ads and Merchant Center if either suspended you.

If you'd rather hand it over, we clean up hacked sites, find how the attacker got in and deal with the Google review requests. See hacked website repair.

Want us to take a look?

Book the free 30-minute review, or tell us what's happening and we'll reply as soon as we can.