©Code byMilanParmar

Business website hacked? What to do first

How to tell it's a hack, the first hour, whether customer data is involved, clean vs restore vs rebuild, finding the way in, removing Google's warning, costs, and a checklist.

10 min read

A gray river pebble with a hairline crack on a desk

If your business website has been hacked, work in this order: tell your host and take the site offline, change every password, keep a copy as evidence, then clean it or restore a backup made before the hack. Close the hole the attacker used before you ask Google to remove its warning, or the site gets hacked again.

A hacked website is rarely personal. Attackers run automated tools that scan the web for known weak spots, like an old plugin or an admin page with a guessable password, and your site is found the same way as thousands of others. That's why the fix is less about the attacker and more about the site: what was changed, how they got in, and whether the site is worth cleaning. This guide is for owners of a live business website or web app who aren't developers. It covers the signs, the first hour, customer data, the clean-or-rebuild decision, Google's warning, and what it costs. When the site turns out to be a web app someone else built, the cleanup becomes the first stage of a product takeover.

How to tell if your website has been hacked

Some hacks are obvious. Others are built to stay hidden from you and show only to visitors arriving from Google, so the owner is often the last to know. These are the signs to check:

  • A warning in Google or the browser.Google's Search Console help says affected sites can show a warning label in search results, or a full-page warning in the browser before the site opens.
  • Visitors land on a different site. Often a gambling, pharmacy, or fake prize page, and often only on phones or only when coming from a Google search.
  • Pages you never wrote. Search Google for site:yourdomain.comand scroll. Hundreds of pages in another language, or selling products you don't sell, mean someone is publishing spam on your domain.
  • Admin users you don't recognisein your website's editor or hosting account.
  • Your host suspends the account or emails you about malware or unusual traffic.
  • Email problems. Customers get spam from your domain, or your own emails start landing in spam folders.

To see what visitors see, open a private browser window on your phone, search for your business, and click through from Google. If you have Google Search Console, the Security issues report is the most reliable check. Google groups problems into three kinds: hacked content added without permission, malware or unwanted software, and social engineering, meaning pages that trick visitors into handing over passwords or card details.

What to do in the first hour after a website hack

The goal of the first hour is to stop the damage spreading, not to fix everything. Do these in order:

  1. Screenshot what you see.The warning, the redirect, the strange pages, with dates. You'll need them for the host, for Google's review, and possibly for insurance.
  2. Call or message your host. Hosts deal with hacks every day, can check their server logs, and on some plans will clean the files for you.
  3. Take the site offline properly.Google's web.dev guidance is to stop the web server, or point the domain at a simple "back soon" page on a different server that returns a 503 (temporarily unavailable) code. It warns that blocking Google with robots.txt isn't enough, because real visitors can still reach the harmful pages.
  4. Change every password, from a device you trust: hosting, file access (FTP or SFTP), the database, every admin account on the site, the domain registrar, and the email account those logins reset to. Turn on two-factor login wherever it's offered.
  5. Remove users you don't recognise, including old accounts for past developers or agencies.
  6. Don't delete the site yet. A copy of the hacked files and database shows how the attacker got in. Delete it and you lose the evidence, and sometimes the only copy of recent content.

If you can't get into the hosting or the domain because a former developer set them up in their own name, recovering those comes first. The steps are in what to do when your web developer disappears.

Hacked website with customer data: who to tell

A defaced homepage and a spam redirect are embarrassing. A hack that reaches customer data is a legal matter. Work out which you have by asking what the website stores: contact form entries, bookings, customer accounts and passwords, order history, or uploaded files.

If your checkout sends customers to a payment provider's own page (Stripe, PayPal, Razorpay, Square), card numbers usually never touch your server. Names, emails, addresses, and order details still might. If the site takes card numbers in its own form, assume they were exposed until someone proves otherwise, and tell your payment provider the same day.

The US Federal Trade Commission's data breach guide for businesses (2023) says to consider independent forensic investigators, not to destroy forensic evidence, to report to local police, and to remove any personal information that was posted on your website. It also notes that every US state has a law requiring businesses to notify people when their personal information is breached. The UK, Canada, Australia, and the EU have their own reporting rules and deadlines. I'm not a lawyer: if personal data may be involved, talk to one, and to your insurer, before you tell customers what happened.

If you do need to write to customers, keep it plain: what happened, what data was involved, what you've done, and what they should do, such as changing a password they reused elsewhere.

Clean a hacked website, restore a backup, or rebuild?

This is the decision that sets the cost. It depends on two things: whether you have a backup from before the hack, and whether the site is worth keeping. Google's web.dev guide says to check that a backup was made before the hack, and to reinstall software fresh rather than upgrade it, because upgrades can leave old infected files behind.

What to do with a hacked website, by situation
Your situationWhat to do
Clean backup from just before the hackRestore it, update everything, change passwords again, close the hole
Clean backup, but months oldRestore it, update everything, then carefully re-add newer content from the hacked copy by hand
No clean backup, site otherwise fineClean a copy away from the live server, reinstall the software fresh, then put the clean copy live
Hacked before, dozens of plugins, dated anywayRebuild on a simpler setup and move the content across, rather than paying for a cleanup that may not last
A web app with customer accountsA developer reviews the code and data first; clean and fix in place unless the code is beyond repair

Most hacked business websites I'm asked about run on WordPress, where the question is really whether the site is worth keeping on WordPress at all. If it has been hacked before and depends on plugins nobody updates, a cleanup buys time rather than a fix. The signs and the cost of each route are in keep WordPress or rebuild a custom website. If you do rebuild, keep your page addresses and redirect anything that moves, so the rankings you had before the hack carry over. Redesign or start over covers how to do that without losing Google traffic.

How hackers get into business websites

Cleaning the files without finding the way in is the most common mistake after a hack. Google's web.dev guide warns that if one infected file stays on the server, the site is more likely to be hacked again. Ask whoever cleans the site to tell you, in writing, which of these it was:

Out-of-date plugins, themes, or software

On WordPress and similar systems, the holes are usually in the add-ons rather than the core software. Once a hole in a popular plugin is made public, automated tools start looking for sites that haven't updated it. A plugin you stopped using but never deleted counts, and so does a "free" copy of a paid theme downloaded from an unofficial site.

Weak, reused, or leaked passwords

An admin password reused from another service that was breached, or a hosting login shared by email with three past freelancers. Two-factor login closes most of this.

Forgotten copies and old accounts

A test copy of the site in a subfolder, an old version left on the same hosting account, or an admin account for an agency you stopped using years ago. Nobody updates these, and one infected site on a hosting account can spread to the others.

Weak custom code

On a web app, the hole is often in the code itself: a form that doesn't check what's typed into it, a page that shows data without checking who's logged in, or a secret key left in code anyone can read. Apps built quickly with AI tools often have this last problem. That's a code review, not a cleanup.

How to remove Google's hacked-site warning

Google doesn't remove its warning on its own schedule. You ask for a review once the site is clean. Before you do, web.dev lists four things you must have done: verified ownership of the site in Search Console, cleaned the site, fixed the hole, and put the clean site back online. The pages must be open to Google's crawler, so remove any block you added while the site was offline.

Then open the Security issues report in Search Console, select Request review, and describe exactly what was wrong and what you did. How long the review takes depends on the kind of problem:

Google review times after a hacked site is cleaned
What Google foundReview time, per web.dev
Phishing (pages that steal logins or card details)About a day
MalwareA few days
Spam pages added by the attackerUp to several weeks

Don't request a review early to "see if it passes". Google's Search Console help says asking while problems remain can slow the next review, or get the site marked as a repeat offender. If the review fails, the report usually shows more sample infected pages, which tells you where to look next. Spam pages the attacker created should be deleted so they return a "not found" error; Google drops them from its results over the following weeks.

What fixing a hacked website costs

What moves the total is which route from the table above you end up on, and how long the site stays offline or flagged.

  • Restoring a clean backup is the cheapest route: the restore itself, then updating everything and closing the hole. Some hosts include this on their plans.
  • Cleaning without a backup takes longer, because every file and the database have to be checked, and the price grows with the number of plugins and pages.
  • Rebuilding a marketing website costs the same as building one. With me, most custom business websites cost $8,000–22,000. Rebuilding the same pages on new templates is usually $7,000–18,000 as a redesign.
  • A hacked web app starts with a code review, which on my takeovers costs $2,500–6,000 and comes off the project price if you continue.
  • Hidden costs: lost enquiries while the site is down or flagged, forensic or legal advice if customer data was involved, and your own time dealing with customers.

Ask for a fixed price for the cleanup, and for a short written report with it: what was found, how the attacker got in, and what was changed to stop it happening again. A cleanup quote with no mention of the way in is a quote for the same job again next month.

How I set up websites and apps to limit the damage

I haven't written up a hacked-site cleanup as a case study, so here is the other half: the security decisions on projects I built, which are the things that decide how bad a hack can get.

On Hongirana, the school software that holds records for 1,000+ students, everyone has to log in, each role only sees what it needs, and fees and personal details sit behind role-based permissions. Backups and keeping the software up to date are part of running it, not an extra.

On the social challenge app, which has handled $40K in stakes, every balance lives on the server and every deposit, stake, and payout is recorded as its own entry. The app never trusts a balance sent from the browser, and payments are confirmed with PayPal before a wallet is credited. On the on-demand printing platform, uploaded documents are deleted automatically after printing, so there's nothing old to steal.

None of this makes a site impossible to hack. It makes a hack smaller: less data to lose, fewer places to hide, and a clear record of what changed.

Hacked website checklist and a message to your host

Once the site is clean, the way to stop a second hack is dull: updates applied every month, backups kept somewhere other than the server, two-factor login, and nobody holding an admin account they no longer need. That's what a support plan should cover, and what website maintenance costs shows what to pay for it. If your site has been hacked and you want a second opinion on cleaning or rebuilding, send me the address and what you're seeing.

Sources

  1. Security issues report, Google Search Console Help
  2. Request a review, web.dev (Google)
  3. Quarantine your site, web.dev (Google)
  4. Clean and maintain your site, web.dev (Google)
  5. Data breach response: a guide for business, US Federal Trade Commission
Milan Parmar

The developer

Freelance full-stack developer in Bengaluru with 5+ years of experience. I redesign websites, take over broken apps, and build SaaS products, with 18 case studies to show for it.

FAQs

Will a hack hurt my Google rankings for good?

Usually not, if you act quickly. The warning label in search results is what costs you clicks, and it comes off once Google reviews the cleaned site. Spam pages the attacker added can stay in Google for a while after you delete them. Make sure they return a "not found" error so Google drops them, and watch Search Console for a few weeks.

Is a custom-built website safer than WordPress?

It has fewer ways in, because there are no third-party plugins or themes for attackers to scan for, and no public admin login at a known address. It isn't immune. Weak passwords, out-of-date libraries, and careless code can still be exploited. What makes any site safer is the same: few moving parts, updates applied, two-factor login, and backups kept somewhere else.

My host suspended my account for malware. What now?

Ask the host exactly what they found and which files, in writing, and whether they can give you a copy of the account. Most hosts will restore limited access so you or a developer can clean it. Don't just move the infected files to a new host: the malware and the hole it came through move with them. Clean or rebuild first, then decide where to host.

Will a security plugin or scanner fix a hacked site?

A scanner can tell you that something is wrong and point to infected files, which is useful. Removing what it finds isn't the same as fixing the hack. If the out-of-date plugin, stolen password, or leftover backdoor that let the attacker in is still there, the site can be reinfected within days. Treat the scan as the start of the cleanup, not the end.