In-depth guideSecurity and compliance

Hacked website recovery: what to do first

Actions to take immediately if your website has been hacked or infected, in order, with what really helps and what doesn't help.

Editorial illustration of the guide: hacked website: the guide to getting back in control
Security and compliance Hacked website recovery: what to do first Comprehensive study · GXN
TL;DRThe answer in one minute

If your site has been hacked, stay calm, it's more common than you think and it is almost always correct. The first steps are to immediately change all passwords related to the site, to make a copy of the current condition before touching anything else, to identify the visible extent of the problem, and to proceed with the cleaning and closing of the entrance door that allowed the incident. After cleaning, the step that almost everyone forgets is to harden security to prevent it from happening again.

First, breathe

A pirated site is scary, but in the vast majority of cases, it's not catastrophic and it's settled. Automated attacks that affect most small and medium-sized sites are usually not directed personally against you. They target known large-scale vulnerabilities at thousands of sites at the same time. You're probably not a specific target, you're a door that someone found.

Immediate actions, in order

Change all site-related passwords. Hosting, site administration, associated email, everything that could have been compromised at the same time.

Make a copy of the current state before cleaning anything. Even infected, it can help to understand what happened.

Look what's visible. The site displays strange content, redirects it to another site, a browser displays a security warning. This observation helps to determine the extent of the problem.

Check if your host has suspended the site on its own initiative, which sometimes happens automatically in case of malicious content detection.

Stay calm and don’t delete anything in a rush. Hasty deletions can destroy valuable evidence to understand exactly how the breach entered.

Decision cardThe four angles to keep together
01First, breathe 02Immediate actions, in order 03What is done next, the actual cleaning 04The step everyone skips
Guide reading grid
AngleDimension to examineUse in the decision
01 First, breathe Setting the Context
02 Immediate actions, in order Identify dependencies
03 What is done next, the actual cleaning Compare options
04 The step everyone skips Preparing for the next step

What is done next, the actual cleaning

Identify the entrance door. Almost always, it's not updated software, a weak password, or a forgotten account with still active access.

Remove malicious content injected into the files or database from the site.

Close the identified entrance door. There's no point cleaning if the rift remains open for the next attack.

Restore from a healthy backup if manual cleaning is too complex or incomplete.

Request review from Google or other services if security warnings have been publicly posted.

Interactive tool

Set your decision

Select the dimensions that describe your situation. The result is to organize the next conversation, not to replace an analysis.

What concerns you now
Starting point Document before you decide

Choose the dimensions that apply to show the recommended level of attention.

0 / 100

The step everyone skips

Once the site is cleaned and released online, the natural reflex is to turn the page and move on. This is exactly the time to tighten security, not relax vigilance. Update all software, review all accounts with access, set up continuous monitoring, and check that backups actually work, not just in theory.

Jumping this step is cleaning once and waiting for the next attack, which will probably come by the same path.

What we can do, and what we don't do

We perform technical clean-up, identify entry points, harden security, and restore after incidents. We don't conduct formal legal investigations or certified intrusion analysis for insurance purposes. If your situation requires this level of investigation, we'll be upfront about it and direct you to appropriate resources.

What I see on the ground

Almost every hacked website I have cleaned in twenty years shared the same profile: updates delayed for months or years, former employee or provider accounts left active, and no verified backup. Sometimes a backup existed in theory but had never been tested.

The attack itself was almost never sophisticated. It was accumulated negligence that opened the door, not a computer crime genius.

When this guide is not enough

If personal data from customers have potentially been exposed, the situation goes beyond mere technical cleaning and involves notification obligations that fall under your legal counsel. If you suspect a targeted criminal intent against your company, rather than a generic automated attack, consultation with the appropriate authorities becomes relevant in addition to technical work.

Frequently asked questions

01Should we pay a ransom after a website attack?

Generally no, there is no guarantee that paying will solve anything, and it encourages the continuation of these practices. Restoring from a healthy backup is almost always preferable.

02How long does a complete website cleanup take?

It varies greatly depending on the magnitude, but the initial emergency usually settles in hours or a few days, with the complete hardening that follows.

03Will a hacked website lose its Google rankings?

A well-managed incident, with quick cleaning and review request, usually has a limited and temporary impact on the SEO.

04How can we verify that a website is clean after remediation?

A complete technical check, including files and database, confirms whether the infection has been completely removed, not just visible symptoms.

Editorial method

In-depth guide prepared by GXN based on real business situations. Recommendations remain independent of brands and providers.

Official sources

References to verify for your situation

These references support the external rules and frameworks cited in this guide. They do not replace legal or professional advice tailored to your organization.

G
About the publisher

GXN

Senior expertise directly accessible, supported by specialists when the project requires it.

Discover GXN
Next step

If this is currently underway, the digital SOS section of our site is designed for this particular emergency.

Otherwise, free assessment gives you an honest reading of your current security situation.

No call required. No sales sequence.

Request a free evaluation