Finding out your website's been hacked is a gut-punch — strange pop-ups, a "deceptive site" warning, or spammy pages you never created. Take a breath. Most hacks are recoverable, and panicking leads to mistakes. Here's the calm, step-by-step process I use.
1. Don't delete anything yet
Your first instinct might be to start deleting files. Resist it. You need the evidence to understand how they got in — otherwise you'll clean the site and get reinfected within days.
2. Take the site offline safely
Put up a temporary maintenance page so visitors (and Google) aren't exposed to the compromised site. This protects your reputation while you work.
3. Scan and identify the damage
Use a reputable malware scanner to find infected files and injected code. Common signs include:
- Unfamiliar admin accounts you didn't create.
- Modified core files or strange code at the top of PHP files.
- New files with random names in your uploads folder.
4. Clean, then close the door
Remove the malicious code, restore clean copies of any modified files, and — critically — find and patch the vulnerability that let them in. Usually it's an outdated plugin, a weak password, or an abandoned theme.
5. Ask Google to take another look
If your site was blacklisted, request a review through Google Search Console once it's clean. This lifts the scary browser warnings.
Prevention beats recovery, every time
Once you're clean, lock it down: keep everything updated, add a security plugin or firewall, enforce strong passwords, and — above all — set up automatic backups. A hack is a bad day; a hack with no backup is a catastrophe.
Message me on WhatsApp. Malware cleanup and hardening is something I handle regularly — I'll get you back online and keep you there.