Care
Your website was hacked: what to do in the first hour
Spam pages, odd redirects or a browser warning? Here is the order of steps that limits the damage, from passwords and backups to getting the warning lifted.
SummaryUnder a minute
The short version
A hacked website usually shows itself through spam pages, redirects or a browser warning, and rushed fixes often make it worse. In the first hour, keep the evidence, change passwords from a clean device starting with email, call your host, clear out unknown admin users, restore a clean backup if one exists, then ask search engines to review the site so the warnings come down.
Key takeaways
- Most lasting damage after a hack comes from panic, so don't delete files before you or your host can see how the attacker got in.
- Change passwords from a device you trust, starting with the email account linked to your hosting and domain, and turn on two-step verification as you go.
- Your host can see which files changed and which backups exist, and the admin user list often holds accounts nobody remembers.
- Restore from a backup taken before the first sign of trouble, then update everything, because the original weakness usually comes back with it.
- Search warnings stay up until you ask Google to review the site, so send a short note that says exactly what you fixed.

You open your own website and something is off. There are pages selling pills that you never wrote, or a customer texts to say your site sent them to a gambling page, or the browser shows a red warning before anyone reaches your homepage, or emails to customers start bouncing. For a pool service in Boca Raton or a plumber in Stockport, that warning is often the first thing a new customer sees after searching on their phone, and in Florida it tends to surface at the worst moment, during hurricane season when people are searching for someone to fix storm damage or get a generator running after a power cut. If your website was hacked, what to do in the first hour matters more than anything you do the following week, because the lasting damage usually comes from panic. Owners start deleting files that look strange, or they log in again from the same laptop that leaked the password. In our experience both moves make the cleanup longer and leave less evidence to work from.
Here is the order we follow, written so you can do most of it yourself.
How to tell your site has been hacked
Hacks rarely announce themselves on the homepage. Attackers want your site's standing with Google and your visitors' clicks, so they hide their work where you're least likely to look. These are the signs we see most often:
- Pages you never made. Search Google for "site:yourbusiness.com" (with your own domain) and scroll through the results. Titles in another language or pages for pills and casinos mean someone has added content.
- Visitors sent somewhere else. Many redirects only fire on phones, or only for people who arrive from a search result, so the site looks normal to you while customers land on a scam page.
- A warning from the browser or Google. A full red screen that says "Deceptive site ahead", or a line under your listing in search results that says "This site may be hacked".
- Changes behind the scenes. Admin users you don't recognize, a password reset email you didn't request, a note from your host about unusual activity, or business email that suddenly lands in spam because your server is being used to send junk.
To see what a customer sees, check from wherever you'd normally be standing when a customer calls, whether that's your van in Hialeah or the counter of your shop in Altrincham. Switch your phone to mobile data instead of the office Wi-Fi, search for your business by name and tap your own result. If that path ends somewhere strange, the site is compromised even if it looks fine when you type the address directly.

Website hacked: what to do first
Don't delete anything yet. The instinct is to rip out the bad pages, but those files and the server logs are how you or your host will find out how the attacker got in. If the way in stays open, they come back, often within days of the cleanup. Take screenshots of what you see and keep a simple list of the strange web addresses with the time you first noticed each one, because that list will matter again at the end.
Change the main passwords from a clean device. If the computer you normally use for the business is what leaked the password, typing a new one on it hands the new one over too. Use a device you trust and haven't used for that work, such as your personal phone or a family computer that's kept up to date, and go through the accounts in this order:
- Start with the email account that's linked to your hosting and domain, since it can be used to reset everything else.
- Next, change the password for your hosting account, which is where you pay for the server your site lives on.
- Then change the website's own admin login, the one you use to edit pages and add posts.
- Finish with your domain registrar, the company you pay each year for the web address, which for a .co.uk name in Greater Manchester or a .com in Miami is often a different company from your host.
Turn on two-step verification for each one as you go, so a password alone is no longer enough to get in. Use a new password for every account, because attackers routinely try a stolen password on everything else you own.
Leave the computer you suspect alone for now, and have it checked before you use it for business logins again.
Call your host, then check who has admin access
Your host can see things you can't, such as which files changed and where logins came from. Call or open a support ticket and say plainly that you believe the site is compromised. If your host is in a different time zone, which happens a lot when a Manchester business uses a US host, put it in writing so the ticket is waiting for them when their day starts. Send the screenshots and times you collected, then ask them four things: whether they can see when the files changed, whether they can scan the account, what backups they hold and from which dates, and whether they can put the site behind a maintenance page while it's cleaned. Some hosts will suspend the site on their own if it's sending spam. That feels alarming, but it protects your email reputation and your customers, so don't fight it.

While you wait, look at who can get into your site. Log into the website admin, open the Users page and filter by the administrator role. Every name on that list should be someone you can name and reach today. In our experience the usual surprises are a web designer from years ago, an old marketing agency, a former employee, or an account called "admin" that nobody remembers creating. Screenshot the list first (it's evidence), then remove anyone who shouldn't be there and reset the password for anyone who stays. Do the same check in your hosting account and at your domain registrar, since both let people add extra users.
Good looks like a short list, each person with their own login, and nobody sharing a single account.
Restore from a clean backup, if you have one
A clean backup is a copy of the site from before the attacker got in. That's usually earlier than the day you noticed, because hacks often sit quietly for weeks before the spam pages or redirects appear. Ask your host for the list of available backup dates and pick one from before the first sign you wrote down. If you aren't sure, go further back, since losing a few recent edits is easier to fix than restoring the infection.
After the restore, two things need doing straight away. First, the backup brings back the old user list and old passwords, so repeat the admin check and reset those passwords again. Second, the weakness that let them in is usually still there, most often outdated site software or an add-on that hasn't been updated. Update the core software and every add-on, and remove add-ons you don't use, because an unused add-on still counts as a way in.
If there's no backup, or every backup you have is already infected, this is the point to bring in a professional cleanup, either through your host or a specialist. Deleting suspicious files one by one rarely finds everything, and a half-cleaned site tends to get reinfected and flagged again.

Ask search engines to look again
Warnings don't lift on their own the moment the site is clean. Google keeps showing them until it checks again, and you have to ask.
In Google's free dashboard for site owners, open the security issues report, which lists what Google found on your site. Fix each item, then click the button to request a review and explain in plain sentences what you did: which pages you removed, that you changed passwords and turned on two-step verification, that you removed unknown users, and that you updated the software. A short, specific note works well here. Bing offers similar tools for site owners, and it's worth sending the same note there.
The spam pages may also linger in search results for a while. Use the removals section of the same dashboard to ask for those addresses to be hidden, using the list you made in the first step. A review usually takes a few days, and if it comes back rejected, something is still on the site and it's time to go back to your host.
If you never set up that dashboard, set it up now. It asks you to prove you own the domain, usually by adding a line at your domain registrar, and your host can walk you through it.
How Pixedi handles this in the Care plan
Our Care plan, $250 a month, covers website care and security, uptime, email health and watching the business's online accounts. In practice that means we keep backups and software updates in order, keep track of who has admin access, check that business email isn't landing in spam, and watch for the warning signs above so the owner hears about a problem from us. If a site does get hacked, the steps in this article are the ones we follow, and the monthly report says what happened and what we changed.
Before anything goes wrong, do two things this week. Write down who has admin access to your website, hosting, domain registrar and business email, and ask your host when your last backup was taken and how far back the backups go. If nobody can answer either question, start there.
Ask AI about this article
Opens the assistant in a new tab with this page as the source.
Keep reading
Want this handled for your business?
Start with the free site audit: speed, search, mobile, security, local presence and email, in plain English.


