What to Do If Your Website Has Been Hacked

Discovering that your website has been hacked can be stressful, especially when customers rely on it to find your business, send enquiries or make purchases. You may see unfamiliar pages, strange redirects, a warning from your browser or search engine, or notice that your website has stopped working.

The most important thing is not to panic or repeatedly change files without a plan. A rushed response can destroy useful evidence, leave the attacker’s access active or restore an infected backup. Follow a clear sequence: contain the problem, protect your accounts, identify the cause, clean or restore the website, and monitor it afterwards.

1. Confirm that the problem is really a hack

Not every website error is a security breach. A plugin update, expired domain, hosting problem, database error or incorrect configuration can also make a site appear broken. However, treat unusual behaviour seriously until you can verify what happened.

Possible signs of compromise include:

  • Unexpected pages, links, pop-ups or advertisements appearing on the website.
  • Visitors being redirected to unrelated websites.
  • New administrator accounts that nobody in your organisation created.
  • Unfamiliar files, themes, plugins or changes to existing content.
  • Business email sending messages that you did not write.
  • Your hosting provider, browser or search engine displaying a security warning.
  • A sudden increase in server usage, spam or failed login attempts.

Check the website from a separate device and network if possible. If the issue affects only one computer, that device may be infected or misconfigured. You should also ask your hosting provider to review server activity and confirm whether the problem is limited to the website or affects other services on the account.

2. Contain the damage

If the site is actively redirecting visitors, distributing malware or exposing customer information, temporarily take it offline or place it in a maintenance mode. This reduces the number of people exposed while you investigate.

Do not simply delete the visible hacked page and assume the problem is solved. Attackers often leave hidden files, scheduled tasks or additional administrator accounts. Removing one symptom may allow the compromise to return.

If you cannot safely take the site offline yourself, contact your hosting provider or a qualified website security professional. A practical hosting provider should be able to explain the available options in clear language rather than expecting you to manage complex server tools alone.

3. Secure every account connected to the website

A hacked website may be only one part of a larger account compromise. Change passwords for the hosting account, website administrator accounts, domain registrar, business email, database and any third-party services connected to the site.

Use a separate, strong password for each service. Do not reuse the same password for your email and hosting account. If an attacker can access your email, they may be able to reset passwords for other services, so securing the main business email account is particularly important.

Enable multi-factor authentication wherever it is available. Then review account users, recovery email addresses, forwarding rules, API keys and active sessions. Remove accounts that no longer belong to current staff, former developers or agencies. Your business should retain direct access to its domain, hosting and website rather than depending entirely on a former employee or third party.

4. Preserve useful information before cleaning

Before deleting files or reinstalling the website, record what you can. Take screenshots of warning messages, suspicious pages and unexpected accounts. Note when the problem was first discovered and what changes were made shortly before it appeared.

Ask your hosting provider whether server logs, access logs or backups are available. These records may help identify how the attacker entered the site and whether other websites or email accounts were affected. Avoid editing the only copy of important logs or evidence.

If your website collects personal information, customer enquiries or payment details, consider whether the incident may have exposed sensitive data. The appropriate response can depend on the type of information involved and the systems affected. If you suspect customer or financial information was exposed, seek qualified legal, compliance or cybersecurity advice promptly.

5. Find the likely entry point

Cleaning the website without fixing the cause often leads to another compromise. Common entry points include:

  • Outdated WordPress core software, plugins or themes.
  • Vulnerable or pirated themes and plugins.
  • Weak or reused passwords.
  • Compromised hosting, email or domain accounts.
  • Incorrect file permissions or insecure server settings.
  • Old staging sites, backups or unused applications left online.
  • Malware on a computer used to manage the website.

For a WordPress website, review the installed plugins, themes and administrator accounts. Remove software that is unused or no longer supported, but do not update or delete everything blindly if you still need evidence for investigation. A managed WordPress support provider can help review the installation and determine which components should be removed, replaced or updated.

6. Clean the website or restore it safely

There are two main recovery approaches: cleaning the existing installation or restoring a known-clean backup.

Cleaning the existing site

Cleaning may be appropriate when you need to preserve recent content or when a reliable backup is unavailable. It involves identifying malicious files, unauthorised code, suspicious accounts and altered settings. This work should be performed by someone who understands the website platform and hosting environment.

Restoring a backup

Restoring can be faster when you have a backup from before the attack. However, do not assume the newest backup is safe. A backup created after the compromise may contain the same malicious files or unauthorised accounts.

After restoring, update the website software, change all relevant passwords and review the site before making it public again. Also check whether new customer orders, enquiries or content created after the backup need to be preserved separately.

A backup is useful only if it can be restored. Businesses should know where backups are stored, how often they are created and whether restoration has been tested. Your hosting plan and website management process should match how much backup and recovery responsibility you want to handle yourself.

7. Check the domain, email and website settings

Website recovery should include more than the visible pages. Review the domain’s DNS records, nameservers, SSL configuration and renewal details. An attacker who controls the domain account may redirect visitors or interfere with email even if the website files are clean.

Check business email accounts for unfamiliar forwarding rules, filters, signatures or sent messages. If customers received suspicious messages from your address, let them know through a trusted communication channel and advise them not to open unexpected links or attachments.

Confirm that HTTPS is working correctly and that contact forms, payment connections and important integrations function as expected. Test the website on a mobile device as well as a desktop computer, since many customers in Nigeria and across West Africa access business websites primarily through mobile networks.

8. Monitor the website after recovery

Recovery is not complete when the homepage looks normal. For the following days and weeks, watch for new administrator accounts, changed files, unusual traffic, failed logins, unexpected email activity and repeated redirects.

Keep website software and extensions updated. Remove unused plugins, themes and user accounts. Use least-privilege access so each person has only the permissions needed for their work. Make regular backups and keep at least one copy separate from the live website.

Consider adding security monitoring or a web application firewall if it suits your website and budget. You do not need to buy the most expensive security service automatically. The right level of protection depends on the website’s importance, the information it handles, how often it changes and how much technical support your organisation needs.

A simple incident workflow for a small business

  1. Stop exposure: Put the website into maintenance mode or ask your host to restrict access.
  2. Secure access: Change hosting, email, domain and administrator passwords from a trusted device.
  3. Record evidence: Save screenshots, dates, warnings and relevant account changes.
  4. Get technical help: Ask your host or a security specialist to inspect the site and logs.
  5. Recover safely: Clean the installation or restore a verified, pre-incident backup.
  6. Fix the cause: Update software, remove unused components and close unauthorised access.
  7. Monitor: Continue checking the website, email, domain and hosting account after it returns online.

How to reduce the risk of another hack

No website can be guaranteed to be completely immune to attacks, but basic preparation can make an incident less damaging. Keep domain ownership information accurate, monitor renewals and ensure more than one trusted person can access essential accounts. Use strong unique passwords and multi-factor authentication. Keep WordPress, themes and plugins maintained, and avoid unsupported or illegally distributed software.

Choose hosting with the support level your organisation actually needs. A small business that does not have an internal technical team may benefit from managed WordPress support and practical assistance with updates, backups and troubleshooting. The goal is not to become a server administrator; it is to ensure that technical responsibilities are covered reliably.

A hacked website is a serious problem, but a structured response can limit disruption and protect customer trust. Contain the site first, secure every connected account, preserve information, recover from a verified clean source and address the weakness that allowed the compromise. Then maintain the website as an ongoing business asset rather than treating security as a one-time repair.