Discovering your website has been hacked is stressful — defacement, spam, warnings in Google, or it is offline entirely. Take a breath: with the right steps, in the right order, you can recover and come back stronger.
1. Contain it
Put the site into maintenance mode or take it offline to stop the damage spreading and protect visitors. Change all passwords — hosting, CMS, database, FTP and email — immediately.
2. Assess the damage
Scan the site for malware and check what was affected: files, database, user accounts. Note any Google Search Console warnings so you can address them later.
3. Restore from a clean backup
If you have a recent, clean backup from before the hack, restoring it is the fastest route. Make sure the backup itself is not compromised.
4. Clean what you cannot restore
No clean backup? Remove malicious files and code, replace core CMS/plugin files with fresh copies, and remove any unknown admin accounts.
5. Find and close the entry point
This is the step people skip — and why they get hacked again. Identify how they got in (an outdated plugin, a weak password, a vulnerability) and fix that specific hole.
6. Harden and monitor
Update everything, enable two-factor authentication, add a web application firewall, and set up monitoring. Then request a review from Google if your site was flagged.
Do this in order
- Contain → assess → restore/clean → close the entry point → harden.
- Skipping the entry-point step means it recurs.
- If customer data was exposed, follow your legal notification duties.
Been hacked and need help now? Nexgenz cleans infected sites, finds and closes the entry point, and hardens everything so it does not happen again.
