← Back to Blog ✻ staying safe

What to Do If Your Website Gets Hacked

Nordlyte Web Studio · Security Guide · 9 min read

stay calm — here's exactly what to do

Finding out your website has been hacked is stressful, but panicking rarely helps. If you're thinking "my website is hacked, what do I do now," here's the answer: a clear, calm walkthrough of what to check, how to fix it fast, and how to make sure it doesn't happen again.

Signs your site may have been hacked

Immediate steps to take

1 Don't panic — but act quickly

The longer a compromised site stays live, the more damage it can do to your reputation and search rankings. Move through the next steps promptly, but methodically.

2 Change all passwords immediately

Update your hosting account, website admin (e.g. WordPress), FTP, and any connected email passwords — assume all of them may be compromised, not just one.

💬 Short on time? We can just tell you what you need.

Chat with us →

3 Take the site offline temporarily if needed

If the hack is actively harming visitors (malware, redirects, phishing content), it's often safer to put the site into maintenance mode or take it offline until it's cleaned, rather than leave it live.

4 Restore from a clean backup

If you have a recent, clean backup from before the hack, restoring it is usually the fastest way back to normal — followed immediately by a password reset, since restoring alone doesn't fix the vulnerability that let the hack happen.

5 Identify and close the vulnerability

Common causes include outdated plugins, weak passwords, or an unpatched theme. Update everything to the latest version and remove any plugins or tools you no longer use — fewer moving parts means fewer entry points.

6 Request a review if Google flagged you

If your site shows a security warning in search results, use Google Search Console to request a review once you've confirmed the issue is fixed — this can take a few days to clear.

🔐 the uncomfortable truth: most hacks are preventable — this is exactly why regular updates and backups matter so much

The quick fix, if you're short on time

If you just need the fastest path to fixing a hacked website: change every password immediately, restore from your most recent clean backup, update everything (plugins, themes, core software) to the latest version, then request a Google review if you've been flagged. That order matters — restoring a backup without also changing passwords and patching the vulnerability just invites the same hack again.

How to prevent it from happening again

Should I hire someone to handle this?

If you're not comfortable diagnosing and fixing the issue yourself, it's worth getting a developer involved quickly — the cost of professional cleanup is usually far less than the cost of prolonged downtime or lost customer trust.

Frequently asked questions

My website is hacked — what do I do first?

Change every password immediately (hosting, admin, FTP, email), then restore from your most recent clean backup if you have one. Don't skip the password change even if you restore a backup — it doesn't fix the vulnerability that let the hack happen.

How do I fix a website that's already been hacked?

Restore a clean backup, update all software to the latest version, remove unused plugins, and change every password. If Google has flagged your site, request a review once you've confirmed it's clean.

What if I don't have a backup to restore?

Recovery is slower and more manual — you'll need to identify and remove the malicious code directly, which is where hiring a developer becomes worth it fast. This is also the strongest argument for setting up automated backups going forward, so you're never in this position twice.

Dealing with a hacked site right now?

Message us — we can help assess and fix it, and set up protection going forward.

✉️ Get a Maintenance Quote
← Back to all articles
Need help with your website?Get a free quote →