rawatweb

Website Hacked: What to Do First and What Makes It Worse

Website hacked? The correct handling order, the mistakes that make things worse, and how to make sure the infection does not come back after cleanup.

Editorial illustration: a defensive wall with one gap and an abstract orange exclamation mark

There are few moments that panic a website owner more. One is opening your own website and finding pages you did not create, or Google flagging it with a dangerous-site warning. Worse still: sometimes you see nothing wrong, but visitors get a warning from their browser.

A situation like this demands calm and the right order. Acting fast matters, but acting fast in the wrong way can destroy evidence, ruin recovery, or bring the infection back within days.

This guide covers what needs to be done, in the right order.

Signs your website may already be under attack

Some attacks are clearly visible, some deliberately hidden. Signs to suspect:

  • Pages or links appear that you never created, often at unusual addresses.
  • Search results show strange titles or descriptions for your website.
  • The browser warns that the website is not safe.
  • The website slows drastically for no clear reason.
  • There are new administrator accounts you do not recognise.
  • The inbox fills with registration notices or failed login attempts.
  • Hosting bills rise because of abnormal resource usage.
  • There are new files or folders inside the website directory.

If any of these signs appear, treat your website as being in an emergency.

What to do, in order

The order below is arranged so you do not lose the ability to recover the website, and do not destroy evidence you need.

1. Do not change anything yet

The first reflex is usually to delete suspicious files or reset settings. Avoid that for a few minutes. You want to know how the attack entered before closing it, because otherwise the same gap will be used again.

2. Take the website off the public internet if the infection is spreading

If your website endangers visitors — spreading malware or redirecting them elsewhere — cut public access temporarily. The simplest way is enabling maintenance mode or changing a setting in the hosting panel. Being offline for a day is far better than passing the infection to your customers.

3. Make a copy of the current condition

Download the files and database before doing any cleanup. This copy matters for two things: as analysis material, and as evidence if you need help from another party.

4. Change every password

Start with the hosting account, admin panel, file access, and email. Change them all, and do it from a device you trust is clean. If you reuse the same password across services, change it there too.

5. Scan your own devices

Some infections start from the computer of the person managing the website being infected first. If the source is there, cleaning the website will not solve the problem.

6. Establish whether there is a clean backup

Find a backup copy from before the infection entered. To confirm it is clean, you need to estimate when the infection started. If no copy can be confirmed clean, manual cleanup will be necessary.

7. Clean and close the gap

Proper cleanup covers three things: removing the malicious code, closing the gap that was used to get in, and removing the back doors the attacker may have installed. The third step is most often skipped, and that is why infections often return after cleanup.

8. Restore and test

Once clean, test the website thoroughly: the homepage, product pages, forms, transactions, the admin panel, and transactional email. Also check the user list and any suspicious new files.

9. Request a review from Google

If the website was flagged, request a review through Google Search Console after cleanup. The warning usually disappears within days of it being declared clean.

10. Strengthen and monitor

After recovery, strengthen the defence layers: two-step verification, login-attempt limiting, file monitoring, routine updates, and tested backups. The basic security principles are in how to secure a WordPress website. Install monitoring for the coming weeks, because repeat attacks are fairly common.

Mistakes that make things worse

Some reactions that seem sensible but cause damage:

Deleting suspicious files without closing the gap. The infection returns within days, through the same entry point.

Replacing all website files with old versions without checking the database. In some attacks, malicious code is also inserted into the database. Replacing files alone does not solve it.

Reinstalling WordPress and then restoring the old, still-infected database. This mistake makes the problem loop.

Assuming cleanup is finished once the website looks normal. A dormant infection can reactivate later. A thorough check is needed, not just looking at the homepage.

Delaying notification to affected parties. If customer data may have been taken, delay makes the problem bigger.

If the website handles transactions

For an online store, the order differs slightly. After securing a copy, confirm that the transaction data and payment statuses are still intact. Also check for fake orders or price changes you did not make.

Notification to customers needs preparing early, especially if their data may be affected. Recovering trust is far harder than recovering the website.

Preventing the next attack

Once the website is recovered, a few things most reduce the risk:

  • Update every component, and schedule routine updates. A routine like this is the core of periodic website care.
  • Enable two-step verification for every privileged account.
  • Limit login attempts and change the login page address.
  • Delete unused accounts and plugins.
  • Install a firewall and file monitoring.
  • Make routine backups off-site, and test the restore.
  • Check the user list and new files every month.

No single step makes a website immune. What genuinely lowers risk is a combination run consistently.

How long recovery usually takes

Recovery time depends heavily on how far the infection spread and how ready the recovery material is. As a general guide:

  • Cleanup with a clean backup available: a few hours to one business day.
  • Cleanup without a backup, with limited infection: one to three business days, including tracing leftover malicious code.
  • Cleanup with infection spread to the database and theme files: three to seven business days, with longer testing.
  • Online stores: plus time to check the integrity of transaction data and payment statuses.

What decides it, besides the level of damage, is whether the cleanup closes the entry gap or not. A quick cleanup that does not close the gap ends with the same attack days later, and the total cost becomes far larger.

How we handle an attacked website

When we receive a website in an emergency, the work order is always the same and is never skipped.

First, we secure a copy of the current condition. This matters so that no cleanup step destroys the analysis material. Second, we trace how the attack entered, looking for new accounts, new files, database modifications, and traces in the server logs. Third, we close that gap, including restoring settings the attacker may have changed.

Only after that is cleanup run: removing malicious code from files and database, replacing every credential, and strengthening the defence layers. We finish with thorough testing of the homepage, service or product pages, forms, transactions, and transactional email.

For websites using a popular content management system, we also make sure the component versions are current, because the next attack usually uses the same gap if the components are left behind. Once everything is clean and tested, routine monitoring is installed so early signs can be known faster.

We provide this as the Audit & Recovery service, a one-time payment. The final price is given after seeing the level of damage, not after the work is finished.

Evidence and records worth keeping

Most people clean up immediately without saving anything, then regret it when the problem reappears with no material to trace. Keeping the following takes only a few minutes.

Save a complete copy of the website’s condition when it was found infected, including the files and database. Note roughly when the problem started and how you found out. Save screenshots of strange pages, browser warnings, and search tool notices. If there are access logs from the server, keep the part showing activity around the time of the incident.

These records are useful for three things: tracing how it got in, making sure the same infection does not repeat, and explaining the real condition to whoever helps you. Without records, tracing becomes guesswork, and guesswork stretches the recovery time.

Who to contact first

When a website is infected, several parties can help, and choosing the right one saves time.

The hosting provider is useful for server-level things: viewing access logs, restoring from backups they hold, or temporarily limiting access. Contact them early, especially if you have lost panel access.

Your website developer is useful if still reachable and still familiar with the website structure. Note that most website build agreements do not include malware cleanup, so this work is usually billed separately.

A website care service is useful when the website needs recovering and then maintaining. Its advantage is that the work does not stop at cleanup: gaps are closed, components updated, backup installed, and monitoring running.

What you should not do is hand this work to an inexperienced person merely because they are cheaper. A mistake at the cleanup stage can destroy data that should still have been recoverable, and the cost of that is far bigger than the difference in service price.

What you need to understand about the cost

Malware cleanup is not pleasant work to do yourself while learning. A mistake at this stage can delete data that should have been recoverable. So many website owners choose to hand it over.

We handle these cases as the Audit & Recovery service, a one-time payment starting from Rp750k, with the final price confirmed after we see the level of damage, not after the work starts.

If your website is in an emergency, contact us on WhatsApp and describe what you see. If you are not sure whether your website is genuinely infected or just has an ordinary problem, the free audit can confirm its condition first.

#hack #malware #recovery
Let's talk about your website

Does any of this look like your website?

Tell us on WhatsApp. We look first, explain what needs fixing, then you decide. For a fuller picture, request the free audit.

Chat with us