Skip to content
Webcrab
All posts

Security · 3 October 2026 · 6 min read

My website was hacked: what to do in the first hour

A clear first-hour checklist for a hacked website: contain it, protect customers, keep evidence, and avoid the mistakes that make it worse.

Finding out your website has been hacked is stressful, and stress leads to mistakes. The first hour matters more than anything that comes after it. Here is what to do, and what to avoid.

Minute 0 to 10: Confirm and contain

Confirm it is really a hack. Common signs are defaced pages, redirects to other sites, new pages in Google you did not create, a host suspension notice, or a customer telling you the site shows warnings. Check in a private browser window, because some hacks only show to visitors who arrive from Google.

Contain the damage. Ask your host to put the site into maintenance mode, or turn it off, so more visitors are not exposed. If you have a shop, pause orders until you know whether payment pages were touched.

Minute 10 to 20: Change the keys

Attackers often keep access through passwords. From a device you trust (not one that might be infected), change:

  • Your hosting account password
  • Your website admin passwords, for every user
  • FTP and SSH passwords
  • Your database password (and update the site's configuration to match)
  • Your email password, if the same password was used anywhere else

Use a password manager so each one is long and unique, and turn on two-factor login wherever it is offered.

Minute 20 to 35: Preserve evidence

Before you clean anything:

  1. Take a full backup of the files and the database, exactly as they are now
  2. Screenshot what visitors see, and the warnings you were shown
  3. Ask your host for access logs for the last few days
  4. Write down when you first noticed it and what changed recently, for example a new plugin or an updated theme

This evidence helps find how the attacker got in. Without it, the same hole stays open.

Minute 35 to 50: Tell the right people

  • Your host. Many hosts help with scans and temporary restores
  • Your team. Anyone with a login should change their passwords
  • Your payment provider, if you take payments, so they can watch for fraud
  • Customers, if their information may have been exposed. Be honest, short and practical: what happened, what it means for them, what you are doing

Minute 50 to 60: Decide who cleans it

You have two real options:

  • Restore a clean backup from before the infection, then update everything and close the way in
  • Clean it properly by removing malware and backdoors, which needs experience

Our guide to removing malware from WordPress covers the steps. If you are not confident, or the site handles money or personal data, get help. Our emergency team can take over at this point.

Mistakes that make it worse

  • Deleting everything and starting again without finding the hole, so it happens again
  • Only fixing what is visible. The visible defacement is rarely the only change
  • Reusing old passwords or sharing new ones over email or chat
  • Restoring a backup without checking its date. If the backup already contains the malware, you restore the problem
  • Paying a ransom or a "recovery" stranger who contacted you first
  • Waiting. The longer a site stays infected, the more Google trusts it less

After the first hour

Once the site is clean, harden it so it does not repeat:

  • Update WordPress, themes and plugins, and delete what you do not use
  • Add daily off-site backups and test a restore
  • Turn on monitoring and malware scans
  • Run a free security scan to check headers, SSL and email protections

Our security and care service does all of this for you, with a monthly report.

If you are in the first hour right now, contact us. We reply fast and we will tell you honestly what is wrong.

Let's build something that lasts.

Tell us about your business. You'll get a written quote with a fixed price within one working day.

Get a quote