You have just found out. Maybe a customer mentioned a redirect, maybe Google is showing a warning, maybe your host suspended the account. Either way, your website has been hacked and you are trying to decide what to do first.
The next hour matters more than the rest of the week. Not because you can fix it in an hour, but because a few early decisions determine whether recovery takes a day or a fortnight.
Three instincts to resist
Start here, because these are the ones that cost people days.
Do not delete everything you find. Removing the spam pages feels productive and destroys the evidence you need to work out how they got in. If the entry point survives, the spam pages come back.
Do not restore a backup immediately. The instinct is strong and it is usually wrong. The recent backup probably contains the infection, the vulnerability is still present, and you will lose every order and enquiry since. Restore later, deliberately, once you know when the infection started.
Do not request a Google review yet. A failed review wastes days and makes the next attempt slower. Clean first, then ask.
Almost everything that makes a hack take two weeks instead of two days happens in the first hour, done with good intentions.
Minutes 0–10: Contain it
Your goal here is to stop further damage without destroying information.
- Take the site offline or into maintenance mode if it is actively harming visitors — serving malware, redirecting to scams, or skimming card details. A holding page is better than an infected one.
- Disable checkout if you run a store and there is any suspicion of card skimming. This is the one thing that cannot wait.
- Pause paid advertising. You are otherwise paying to send people to a compromised site.
If the site is only showing spam pages in search and is not actively dangerous, you can usually leave it up while you work. Weigh reputation against the cost of being offline.
Minutes 10–20: Preserve the evidence
Before changing anything, take a full copy of the site as it currently stands — files and database — and store it off the server. Yes, it is infected. That is the point. You will need it to work out what happened.
Then download your logs while they still exist: server access logs, error logs, and anything your security plugin recorded. Hosts rotate logs, sometimes daily, and once they are gone the timeline is unrecoverable.
That timeline is what tells you which backup is safe to use.
Minutes 20–35: Lock the doors
Assume the attacker still has access, because they usually do.
- Change every WordPress administrator password
- Change the hosting control panel password
- Change FTP and SFTP credentials
- Change the database password and update
wp-config.php - Regenerate the security keys in
wp-config.php— this invalidates every active session, including theirs - Remove any administrator accounts you do not recognise
- Rotate API keys for payment gateways and integrations
Step five is the one people miss. Changing a password does not always log an intruder out. Regenerating the keys does, immediately.
Minutes 35–50: Work out the scope
Now find out what you are actually dealing with. You are answering four questions.
When did it start? Sort files by modification date and check the logs. This determines which backup is clean.
What kind of infection is it? Spam pages, redirects, phishing pages, a mailer, card skimming. Each behaves differently and each has different urgency.
Was personal data involved? Customer records, order details, form submissions. This is a legal question with a deadline attached, not just a technical one.
How did they get in? Usually an outdated plugin, a weak password, or a nulled theme. If you cannot answer this, the clean-up is incomplete by definition.
Minutes 50–60: Notify who needs to know
Some of this is obligation, some is good practice.
Your host — they may have logs you cannot see, and they need to know if a neighbouring account is implicated.
Your payment processor, immediately, if there is any chance of card data exposure. Delaying makes this substantially worse.
Your regulator and affected customers, if personal data was involved. Under GDPR the window is generally 72 hours from awareness, and similar deadlines apply under PDPL. This clock started when you found out.
Being early and honest here is far better than being thorough and late.
What comes after the first hour
The actual clean-up. Replace core files, reinstall themes and plugins from official sources, clean the database, and — most importantly — find the backdoor. Our guide to removing malware from WordPress walks through the full process.
Then harden the site, request a Google review if you were flagged, and monitor closely for a fortnight. Reinfection almost always happens within the first two weeks, and almost always means the backdoor was missed.
When to stop and call someone
Handling it yourself is reasonable if the infection is simple, you are comfortable with files and databases, and the site is not commercially critical.
Get help if the site takes payments, if personal data may be involved, if your host has suspended the account, if you have cleaned it once and it came back, or if you are not confident you found everything. That last one matters most — an incomplete clean-up is worse than none, because it creates false confidence.
If you need it handled now
Our WordPress security and error fixing service handles the full response: containment, clean-up across files and database, backdoor removal, hardening, and the Google review if you have been blacklisted. There is a clean-or-free guarantee.
Once the site is clean, our security monitoring service makes sure the next incident is caught in hours rather than discovered by a customer.
Send us your web address and what you are seeing. We will tell you what we find, usually the same day.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.