Security

Website Hacked? Here's How to Respond in the First 24 Hours

by Sven Kilcher·

Is your WordPress site hacked? A step-by-step guide: stay calm, limit the damage, and get your site back safely.

Website Hacked? Here's How to Respond in the First 24 Hours

The message usually arrives at the worst possible time: “Something’s wrong with our website.” Strange redirects, a browser warning, or Google suddenly flagging “This site may be hacked.” Before panic sets in: most hacked WordPress sites can be cleaned up within a few hours — if you follow a structured process. That’s exactly what this guide walks you through.

1. Stay calm and take the site offline (don’t delete anything)

The first instinct is often to start changing things immediately. A better approach: put the site into maintenance mode or block access through your hosting panel, instead of deleting files at random. This stops visitors from encountering harmful content while preserving evidence for the investigation that follows.

2. Get a rough sense of the damage

Before fixing anything, take stock: Are there unknown admin accounts? Have files changed that hadn’t been touched in months? Is the site redirecting to unfamiliar domains? Is Google Search Console showing a security warning? This initial assessment determines whether restoring the last clean backup is enough, or whether a deeper cleanup is needed.

3. Restore a clean backup — if you have one

The fastest way back to normal is almost always a backup from before the attack. Important: check the creation date carefully so you don’t accidentally restore a version that was already compromised. Afterwards, still work through the remaining steps — a backup fixes the symptom, not necessarily the underlying cause.

4. Reset every set of credentials

WordPress login, FTP/SFTP, database, hosting panel, and any connected services (e.g. email marketing tools) should all get new, strong passwords. After a hack, it’s rarely clear exactly which credentials were exposed — so reset everything rather than just the most obvious one.

5. No backup? Clean up manually instead of starting from scratch

Without a clean backup, manual cleanup is the way forward: compare WordPress core, theme, and plugin files against their originals, remove unknown files and admin accounts, and check the database for injected scripts. It’s the more time-consuming route, but it’s doable — and getting professional help here can prevent something being missed.

6. Find the root cause, not just the symptoms

A common mistake: the site gets cleaned up, but the entry point stays open — and the hack repeats within days. Check specifically: was a plugin or theme outdated? Was a password too weak? Was a known vulnerability quietly being exploited? The cleanup is only really finished once the cause is known.

7. Check Google Search Console and request a review

If Google flagged a security warning, it won’t disappear automatically after cleanup. Under “Security Issues” in Search Console, you can request a review once the site is verifiably clean. Depending on the case, that can take a few days.

8. Lock things down for the future

After the immediate cleanup, the most important part follows: making sure it doesn’t happen again. Up-to-date software, a malware scanner, two-factor authentication, and regular, tested backups all belong on the list — I’ve laid out the concrete steps in 10 Steps to Stronger WordPress Security.

Conclusion

A hack is unpleasant, but rarely the end of the world — as long as you follow a structured process: secure, assess, clean up, find the cause, lock it down. If this feels like too much to handle right now: I take care of the cleanup and set up ongoing maintenance afterward so it doesn’t happen again. Just reach out via the contact form.

FAQ

Das willst du wissen

How do I know if my WordPress site has been hacked?
Common signs include unexpected redirects, new admin accounts you didn't create, a Google security warning, unusually high server load, or visitors reporting spam content. When in doubt, a security scan with a malware scanner will confirm it.
Do I need to rebuild the website from scratch?
In most cases, no. A clean backup or careful manual cleanup can restore the existing installation. A full rebuild is only necessary in cases of very deep compromise.
Should I notify authorities or my customers?
If personal data may have been affected (e.g. through a contact form or a shop), reporting obligations under GDPR toward the supervisory authority may apply. Legal advice is worth seeking here, in addition to the technical cleanup.
How long does it take to get a hacked WordPress site back online?
With a clean backup, often just a few hours. Without one, and with a deeper cleanup required, it can take one to several days depending on the scope.
Sven Kilcher – WordPress Freelancer
WordPress Freelancer

Die WP Helping Hand, WordPress Freelancer

Sven Kilcher

Ich bin Sven, dein erfahrener Partner für alles rund um WordPress. Mit über 8 Jahren Expertise und mehr als 120 zufriedenen Kunden stehe ich dir zur Seite, um deine Website professionell zu gestalten, zu warten und weiterzuentwickeln. Ob es um maßgeschneiderte Lösungen oder regelmäßige Wartungen geht – ich bin für dich da.

44
Alter
8 Jahre
Erfahrung
120+
Kunden
50+
Wartungen