codexier.

Maintenance & Security

Website Hacked? What to Do in the First 24 Hours

By CodexierPublished 6 min read

A hacked website is a bad day, not a catastrophe, provided you do things in the right order. Most damage after a breach comes from the response: cleaning before understanding, restoring a backup that is also infected, or forgetting that customer data on the server has legal deadlines attached. This guide is the sequence for the first day, written to be followed under stress.

Signs that you have been hacked

  • Google or your browser shows a warning that the site may be harmful, or the site drops out of search results.
  • Redirects to other sites, pop-ups, or spam pages appearing in search results under your domain.
  • Unknown admin users, plugins or scheduled tasks; files changed at odd hours.
  • Your host or email provider suspends the account for sending spam.
  • Customers report emails or password resets they never requested.

Contain: take control of access

The attacker's advantage is that they are still inside. Containment removes that, and it must happen before anything else, including the investigation. In order:

  1. Put the site into maintenance mode or take it offline at the host if it is serving malware, phishing pages or leaking data. A short outage costs less than another hour of exposure.
  2. Change passwords for the CMS admin, hosting control panel, database, FTP or SSH, and the domain registrar. Use a password manager and unique passwords.
  3. Revoke and reissue API keys, tokens and any integrations that hold credentials, including payment and email services.
  4. Log out all sessions and remove admin users you do not recognise; downgrade the ones you do until the cause is known.
  5. Enable two-factor authentication everywhere it exists, starting with hosting and the registrar.

Preserve evidence before cleaning

The instinct is to delete the malicious files immediately. Resist it for one hour. Without a copy of the compromised state you cannot find how they got in, cannot tell what data they reached, and cannot answer the questions a regulator, an insurer or a customer will ask.

What to copyWhere fromWhy it matters
All site files, including uploadsHosting file manager or SFTPFinds backdoors and the first modified file
Database dumpHosting panel or CMS exportShows injected content and new admin users
Access and error logs, as far back as availableHosting panel; ask the host if not visibleThe entry point and the attacker's IP and timing
Screenshots of symptomsBrowser, search results, warningsEvidence of visible impact
A written timelineYouWhen noticed, what was done, by whom; needed for any report

Store the copies off the server, with the date in the folder name. Do not upload them to the compromised site's own backup tool.

Restore from a clean backup

Choose a backup from before the earliest sign of compromise, using the file modification dates and logs you preserved to date it. A backup from yesterday is useless if the backdoor was planted three weeks ago. Restore files and database together to a fresh environment if your host allows it, then, before making it live, update the CMS, every plugin and theme, remove anything unused, and reset all passwords again.

If no clean backup exists, the site must be cleaned by hand or rebuilt from a fresh install with content re-imported carefully; a scanner helps but is not proof. This is the point where an outside pair of eyes is worth paying for, and our performance and security optimisation covers the cleanup, the hardening and the monitoring that follows. Why backups fail exactly when needed, and how to test them before that day, is in our backups and restore guide.

Report to IMY if personal data is involved

If the site holds personal data, customer accounts, order history, form submissions, newsletter lists, and the attacker may have accessed it, GDPR requires you to notify IMY within 72 hours of becoming aware, unless the breach is unlikely to pose a risk to the people affected. You do not need the full picture to file; a first report can be updated. If the risk to individuals is high, for example passwords or payment details exposed, you must also inform the affected people directly.

  • Note the exact time you became aware; that is when the clock started.
  • Write down what data categories the site holds and which the attacker could plausibly have reached.
  • File the notification through IMY's e-service with what you know, and update it as the investigation continues.
  • Keep the internal record even if you decide not to notify; you must be able to show why.
  • Tell your payment provider immediately if a checkout was tampered with.

After the first day, close the hole for good: identify the entry point from the logs, remove abandoned plugins and users, set up updates and monitoring, and schedule the restore test. When you do not need us for any of this: a maintained site with current backups, two-factor authentication and a host that helps can be recovered by a competent administrator in a day. What justifies a health audit is not knowing how they got in, or a site nobody has updated in a year. Either way, if you are reading this with a live incident, book a call and we will help you triage on the spot.

Frequently asked questions

Should I take the website offline if it has been hacked?

If it is serving malware, phishing pages or leaking data, yes, immediately, behind a maintenance page. The outage costs less than continued harm to visitors and to your search reputation. If the compromise is limited to spam content, containment of access can come first with the site up.

Do I have to report a hacked website to IMY?

Only if personal data was, or may have been, accessed and the breach poses a risk to the people concerned. Then you have 72 hours from becoming aware. A brochure site with no forms or accounts usually holds no personal data beyond server logs; a shop or a site with logins almost always does.

Can I just restore yesterday's backup?

Only if you know the compromise happened after it was taken. Attackers often plant a backdoor weeks before doing anything visible, so yesterday's backup may contain it. Date the compromise from file changes and logs, restore from before that point, then patch and update before going live.

Dealing with a hacked site right now?

Book the next free slot and we will walk through containment and evidence with you on the call, tell you whether the backup you have is usable, and quote a fixed price for cleanup and hardening if you want it done.

Book a free 15-minute call