ShieldWave

All articles

Signs your website was hacked, and what to do in the first hour

Redirects only on mobile, strange pages in Google, new admin accounts, emails in spam. How to recognise a break-in and what to do calmly in the first hour.

Radek, ENSOMEDIAPublished 5 min readPo polskuبالعربية

A hacked website rarely looks hacked. There is no skull on the home page and no message from the attacker. The site works, the contact form sends emails, and when you look at it now and then, nothing seems wrong.

That is deliberate. Whoever has taken over the site wants to use it for as long as possible: to send spam, to boost other sites in Google, or to send your customers to scams. The later you notice, the better for them.

Below are the signs you can spot yourself, and a plan for the first hour after something worries you.

Redirects that only other people see

A customer tells you that when they opened your site they ended up on a prize draw, a fake shop, or a page claiming their phone has a virus. You check on your computer and everything looks normal.

That is a very typical pattern. Malicious code often redirects only some visitors: only on phones, only people arriving from Google search results, and only now and again, so it is harder to reproduce. A logged-in administrator usually sees nothing at all.

How to check: take your phone, switch off Wi-Fi so you are on mobile data, open a private tab, search Google for your business and tap the result. Do not type the address yourself. And if a customer reports a redirect, take it seriously even if you cannot make it happen for yourself.

Strange pages in Google

Search Google for site:yourdomain.com and scroll through the results. You are looking for pages nobody in your business created: text in Japanese, adverts for pills, casinos, fake designer trainers. Sometimes the title or description of your home page changes in the search results, while the page itself looks the same as always.

Google may also add a note to your listing saying the site may be hacked, and Chrome may show visitors a red warning screen before they get in. If you have Google Search Console, open the Security issues report. Google describes there what it found and often lists example addresses. Search Console also emails the site's owners when this happens, so check that nothing has landed in your spam folder.

Signs in the admin, from your host and in your email

In the WordPress admin, open Users and filter the list by the Administrator role. A new account with a name you do not recognise is a serious sign. Malicious code sometimes hides such an account from the list, too. When it does, the count next to "Administrator" above the table does not match the number of people you can see below it.

Other signs worth acting on:

  • an email from your hosting company about a suspended account, malicious files found, or unusually heavy load on the server,
  • your emails bouncing back with a mention of a blacklist, or customers saying they find your messages in spam, because someone is sending spam from your server,
  • a plugin in the admin that nobody installed,
  • Google Ads rejecting your ads because of malware or a compromised landing page,
  • the site suddenly slowing down although nobody has changed anything.

One sign on its own does not settle it. Two at once is a reason to deal with it today.

The first hour: step by step, without panic

Once you know, or strongly suspect, a break-in, the most important thing is not to rush. Most of the damage at this stage comes from good intentions: deleting half the files, reinstalling everything and assuming the matter is closed. A week later the attacker comes back the same way, because nobody found out how they got in.

  1. Write down what you see. Take screenshots, note the address the site redirects to, the time, and who reported what. Keep the emails from your hosting company and from Search Console.
  2. Do not delete anything. Leave suspicious files and accounts in place until someone has looked at them. They are the evidence that shows how the break-in happened.
  3. Change passwords. For the hosting control panel, the WordPress administrator accounts, FTP, and the email accounts on your domain. Do it from a computer you trust, and switch on two-factor login wherever you can. Leave the database password to your developer, because it also has to be changed in the site's configuration.
  4. Contact your developer and your hosting company. Ask the host to preserve the server logs and to take a copy of the site as it is now, before any clean-up starts. Logs are often kept only for a short time, and without them it is hard to work out what happened.
  5. Think about your visitors. If the site is sending people to scams, ask for it to be taken offline for now, or replaced with a maintenance page. Being offline for a day is better than sending customers to fraudsters.

Restoring from a clean backup

The quickest route to a clean site is usually a backup from before the break-in. The catch is in the word "before". An infection often sits on a site for weeks before anyone notices, so yesterday's backup may already be infected. Your developer needs to work out when the first foreign files appeared and go back to an older copy. This is exactly when backups kept in several older versions, away from the server, earn their keep.

Straight after restoring:

  • update WordPress, the theme and every plugin, because the restored site has the same hole it had before the break-in (more on that in the piece on outdated plugins),
  • remove any administrator accounts you do not recognise and change the passwords once more,
  • in Search Console, request a review so that Google removes the warning.

If there is no backup, or every copy is infected, what remains is cleaning the site by hand. That is a job for someone who does it regularly, and it usually takes longer.

GDPR and the 72 hours

If the site held personal data, such as orders, customer accounts or messages from a contact form, the break-in may count as a personal data breach. Under Article 33 of the GDPR you report it to your data protection authority within 72 hours of becoming aware of it, unless it is unlikely to put the people concerned at risk. In the UK that authority is the ICO, and in Poland it is UODO. Whether or not you report it, you are expected to keep a record of what happened and what you did about it.

This is where your notes from the first hour pay off. The time, the screenshots and the list of steps are exactly what anyone helping you prepare the report will ask for.