If your WordPress site has been hacked, start here: don’t delete anything, change your key passwords, and don’t restore an old backup yet. Then get a proper cleanup, one that removes the infection and finds out how the attackers got in, so it doesn’t happen again next week.
Take a breath. This happens to a lot of businesses, and it’s almost always fixable. Here’s what to do, in order.
Is it really a hack?
A few common signs:
- Google or your browser shows a warning like “This site may be hacked”
- Visitors get sent to spam or gambling sites
- Strange pages show up in Google results for your site
- Your host suspended your account
- There are admin users you don’t recognize
If you’re seeing any of these, it’s time to act. (Here’s the full list of warning signs.)
The first hour, in order
1. Breathe, and don’t delete anything.
It’s tempting to wipe the site and start over. Don’t. Cleaning a site is usually faster and safer than rebuilding it, and deleting it destroys the clues about how the attack happened.
2. Change your key passwords.
Start with your WordPress admin, your hosting account, and your email. If you share any of these logins with other people, change them anyway. You can sort out who needs access later.
3. If you can, take a copy of the site as it is now.
A backup of the hacked site can help show how the attackers got in. If your host makes this easy, go ahead. If not, skip it. Whoever cleans your site can take care of it.
4. Talk to your host if they’ve suspended you.
Hosts often suspend hacked sites to protect their other customers. Ask what they found and what they need to restore your account. Keep their reply, since it can help with the cleanup.
5. Write down what you’re seeing.
Take screenshots, note the time, and jot down anything unusual: a warning message, a strange page, an email from a customer. Details like these speed up the cleanup.
6. Get help.
Unless you’re comfortable digging through files and databases, this is the moment to bring in someone who does this regularly.
Why restoring a backup usually isn’t enough
Restoring yesterday’s backup feels like the quick fix. The problem is that it brings back the same security hole the attackers used. If that hole is still open, the site can be reinfected within days, sometimes hours. And if the infection started weeks ago, your recent backups may contain it too.
A backup is a great tool for recovery, but only after you know how they got in.
What a real cleanup includes
A proper cleanup does more than delete the obvious malware. It finds and removes hidden backdoors, removes unknown admin users, closes the hole the attackers used, updates everything, and, if Google flagged your site, requests a review to clear the warning. (Here’s what our cleanup covers.)
Check the accounts around your website
A hack is a good reason to look beyond the website itself:
- Review your other accounts. Check your email, domain registrar, social media, and payment tools for logins or changes you don’t recognize.
- Stop reusing passwords. If the same password works anywhere else, change it there too, and give every account its own password from now on. A password manager makes this easy.
- See whether your email has turned up in a data breach. Billions of passwords have leaked from other companies, and attackers try them on sites everywhere. You can check your email address for free at Have I Been Pwned.
What to tell your customers
If customers noticed, a short, calm note is enough. For example:
“Some of you may have seen a warning or unusual content on our website this week. We’ve had it cleaned and secured, and it’s safe to visit again. No action is needed on your part. Thanks for letting us know, and for your patience.”
Only send something like this once the site is clean. If customer information may have been exposed, like payment details or account logins, talk to a professional about what you’re required to tell people.
After it’s fixed
Most hacks aren’t personal. Automated bots scan millions of sites for the same weak spots: outdated plugins, weak or reused passwords, and software nobody’s watching. A cleanup fixes today’s problem. Ongoing care fixes the reasons it happened.
When you join one of our plans, your cleanup is included, and we keep your site updated, backed up, and monitored from then on. With Website Care, you also get a team that keeps your site current, so the next thing you send us is a new blog post, not another emergency.
Need help right now?
We take action on emergencies the same business day, Monday through Friday, Pacific time.
FAQ
Will I lose my website?
In most cases, no. A cleanup removes the infection from your existing site, and your pages, posts, and images stay in place.
Should I contact my customers?
If they noticed something, a short note once the site is clean is a good idea. If customer information may have been exposed, get professional advice about what you’re required to tell them.
How long until Google removes the warning?
Once your site is clean, a review can be requested from Google. Google handles it on its own schedule, which usually takes a few days.





