Skip to content

Clean up a hacked website

  • Visitors are sent to other websites, or see pages, links or ads you did not add.
  • Your browser or Google shows a warning that the site is dangerous.
  • New files appear that you did not upload, or files change without you editing them.
  • Unknown administrator accounts appear in WordPress.
  • Your mail is refused as spam, or people receive spam you did not send.

If you see any of these, work through the steps below in order. Contact support at any point if you need help.

For WordPress, switch on Maintenance mode in the WordPress Toolkit. Visitors see a maintenance notice instead of the hacked pages while you work.

Change every password that gives access to the site, starting with the control panel. Use a new, unique password for each.

Access Where to change it
Control panel My account. Turn on two-factor authentication too. See Keep your account secure.
Other control panel users Remove anyone who no longer needs access. See Manage users.
SFTP and SSH Set a new password, and remove SSH keys you do not recognise from SSH key manager. See Connect with SFTP and SSH.
FTP accounts Delete accounts you do not use. See FTP accounts.
WordPress users Under Users in the Toolkit, delete administrators you do not recognise and change the passwords of the rest.
Database users Add a new database user with a new password and give it access to the database, then put its details in the site’s configuration (wp-config.php for WordPress). See Create databases and use phpMyAdmin.
Mailboxes If spam was sent from your addresses, reset those mailbox passwords. See Change a mailbox’s password, name or size.

Also check:

  • Logs: the activity log shows changes in your account and who made them, such as sign-ins and new users. See Activity log.
  • Cron jobs: delete scheduled tasks you did not create. See Schedule tasks with cron jobs.

Do this on your own computer too: run a virus scan, because a stolen password often comes from malware on the PC used to manage the site.

Restore a backup from before the hack (fastest)

Section titled “Restore a backup from before the hack (fastest)”

If you know roughly when the site was hacked, restore a backup taken before then. See Back up and restore a website.

A restore brings back the site as it was, including the weakness the attacker used. Go straight on to step 4 afterwards, or the site can be hacked again the same way.

Anything added after that backup, such as orders, posts or uploads, is lost for the parts you restore. If you need to keep recent content, restore only the files and keep the current database, then check the database for unknown administrator accounts.

If there is no clean backup:

  1. Update WordPress, every plugin and every theme in the Toolkit. See Keep WordPress updated.
  2. Delete plugins and themes you do not use, and any you did not install yourself.
  3. Look in File Manager for files that do not belong, such as unfamiliar .php files in wp-content/uploads, and for recently changed files.
  4. Replace WordPress core files and plugins with fresh copies from wordpress.org rather than trying to repair them.

Cleaning a site by hand is hard to do completely. If you are not sure the site is clean, ask a web developer or contact support.

  • Keep everything updated. Out-of-date plugins are the most common way WordPress sites are hacked. Turn on auto-updates in the Toolkit.
  • Turn on ModSecurity, the web application firewall, for each domain on the website’s Security page. See ModSecurity.
  • Use two-factor authentication for the control panel and for WordPress administrators.
  • Give each person their own sign-in instead of sharing passwords. See Give other people access to your account.
  • Use correct file permissions: 644 for files and 755 for folders, never 777. See Fix file and folder permissions.

Switch off Maintenance mode. If Google showed a warning for your site, ask Google to review it again through Google Search Console once the site is clean.