Clean up a hacked website
Signs your site was hacked
Section titled “Signs your site was hacked”- Visitors are sent to other websites, or see pages, links or ads you did not add.
- Your browser or Google shows a warning that the site is dangerous.
- New files appear that you did not upload, or files change without you editing them.
- Unknown administrator accounts appear in WordPress.
- Your mail is refused as spam, or people receive spam you did not send.
If you see any of these, work through the steps below in order. Contact support at any point if you need help.
1. Close the site to visitors
Section titled “1. Close the site to visitors”For WordPress, switch on Maintenance mode in the WordPress Toolkit. Visitors see a maintenance notice instead of the hacked pages while you work.
2. Lock the attacker out
Section titled “2. Lock the attacker out”Change every password that gives access to the site, starting with the control panel. Use a new, unique password for each.
| Access | Where to change it |
|---|---|
| Control panel | My account. Turn on two-factor authentication too. See Keep your account secure. |
| Other control panel users | Remove anyone who no longer needs access. See Manage users. |
| SFTP and SSH | Set a new password, and remove SSH keys you do not recognise from SSH key manager. See Connect with SFTP and SSH. |
| FTP accounts | Delete accounts you do not use. See FTP accounts. |
| WordPress users | Under Users in the Toolkit, delete administrators you do not recognise and change the passwords of the rest. |
| Database users | Add a new database user with a new password and give it access to the database, then put its details in the site’s configuration (wp-config.php for WordPress). See Create databases and use phpMyAdmin. |
| Mailboxes | If spam was sent from your addresses, reset those mailbox passwords. See Change a mailbox’s password, name or size. |
Also check:
- Logs: the activity log shows changes in your account and who made them, such as sign-ins and new users. See Activity log.
- Cron jobs: delete scheduled tasks you did not create. See Schedule tasks with cron jobs.
Do this on your own computer too: run a virus scan, because a stolen password often comes from malware on the PC used to manage the site.
3. Restore or clean the site
Section titled “3. Restore or clean the site”Restore a backup from before the hack (fastest)
Section titled “Restore a backup from before the hack (fastest)”If you know roughly when the site was hacked, restore a backup taken before then. See Back up and restore a website.
A restore brings back the site as it was, including the weakness the attacker used. Go straight on to step 4 afterwards, or the site can be hacked again the same way.
Anything added after that backup, such as orders, posts or uploads, is lost for the parts you restore. If you need to keep recent content, restore only the files and keep the current database, then check the database for unknown administrator accounts.
Clean it yourself
Section titled “Clean it yourself”If there is no clean backup:
- Update WordPress, every plugin and every theme in the Toolkit. See Keep WordPress updated.
- Delete plugins and themes you do not use, and any you did not install yourself.
- Look in File Manager for files that do not belong, such as unfamiliar
.phpfiles inwp-content/uploads, and for recently changed files. - Replace WordPress core files and plugins with fresh copies from wordpress.org rather than trying to repair them.
Cleaning a site by hand is hard to do completely. If you are not sure the site is clean, ask a web developer or contact support.
4. Stop it happening again
Section titled “4. Stop it happening again”- Keep everything updated. Out-of-date plugins are the most common way WordPress sites are hacked. Turn on auto-updates in the Toolkit.
- Turn on ModSecurity, the web application firewall, for each domain on the website’s Security page. See ModSecurity.
- Use two-factor authentication for the control panel and for WordPress administrators.
- Give each person their own sign-in instead of sharing passwords. See Give other people access to your account.
- Use correct file permissions: 644 for files and 755 for folders, never 777. See Fix file and folder permissions.
5. Reopen the site
Section titled “5. Reopen the site”Switch off Maintenance mode. If Google showed a warning for your site, ask Google to review it again through Google Search Console once the site is clean.