Finding out your website's been hacked is a gut-punch — strange pop-ups, a "deceptive site" warning, or spammy pages you never created. Take a breath. Most hacks are recoverable, and panicking leads to mistakes. Here's the calm, step-by-step process I use.

1. Don't delete anything yet

Your first instinct might be to start deleting files. Resist it. You need the evidence to understand how they got in — otherwise you'll clean the site and get reinfected within days.

2. Take the site offline safely

Put up a temporary maintenance page so visitors (and Google) aren't exposed to the compromised site. This protects your reputation while you work.

Important: Change every password now — hosting, WordPress admin, FTP, and database. Use new, strong, unique ones. A surprising number of reinfections happen because an old password was never rotated.

3. Scan and identify the damage

Use a reputable malware scanner to find infected files and injected code. Common signs include:

  • Unfamiliar admin accounts you didn't create.
  • Modified core files or strange code at the top of PHP files.
  • New files with random names in your uploads folder.

4. Clean, then close the door

Remove the malicious code, restore clean copies of any modified files, and — critically — find and patch the vulnerability that let them in. Usually it's an outdated plugin, a weak password, or an abandoned theme.

5. Ask Google to take another look

If your site was blacklisted, request a review through Google Search Console once it's clean. This lifts the scary browser warnings.

Prevention beats recovery, every time

Once you're clean, lock it down: keep everything updated, add a security plugin or firewall, enforce strong passwords, and — above all — set up automatic backups. A hack is a bad day; a hack with no backup is a catastrophe.

Hacked right now and not sure what to do?
Message me on WhatsApp. Malware cleanup and hardening is something I handle regularly — I'll get you back online and keep you there.