← All insights
August 31, 2026·Web Maintenance·3 min read

What Happens When Your Website Gets Hacked: A Calm, Step-by-Step Walkthrough

Discovering your website has been compromised is stressful, and panic tends to produce worse decisions than a clear process would. Here’s what actually needs to happen, in order, without the alarmism.

A compromised website is a solvable problem with a known process. The damage that matters most usually comes from delay and disorganized response, not from the initial breach itself.

Primo Collab

First: confirm it’s actually a compromise

Not every strange behavior is a hack. A malformed plugin update, a caching issue, or a DNS problem can all look alarming and have nothing to do with security. Before reacting, confirm what’s actually happening: unexpected admin users, defaced content, spam injected into pages, malware warnings from your browser or Google Search Console, or unfamiliar files in your hosting account are genuine signs. A slow page or a display glitch, on its own, usually isn’t.

The first-response steps to take, in order, after confirming a website compromise

Take the site offline or into maintenance mode

If compromise is confirmed, the first real action is limiting further damage and exposure, not investigating in place while the site stays fully live and potentially serving malicious content to visitors or continuing to be exploited. Maintenance mode or taking the site temporarily offline buys time to actually diagnose the problem properly.

Change every credential, not just the obviously compromised one

Hosting account, CMS admin accounts, database, FTP/SFTP, any connected third-party service. If one credential was compromised, treat all of them as suspect until proven otherwise, since attackers who gain initial access often look for additional footholds before being noticed.

Identify how they got in

Common entry points: an outdated plugin or theme with a known vulnerability, a weak or reused admin password, a compromised third-party integration, or an outdated CMS core. Fixing the visible damage without identifying and closing the actual entry point means the same compromise can simply happen again.

Clean the site from a trusted backup, or manually if needed

A clean backup from before the compromise is the fastest, most reliable path back to a known-good state, provided the entry point has actually been closed first. Without a clean backup, manual cleanup, removing injected code, unfamiliar files, and unauthorized users, is more time-consuming and carries more risk of missing something.

Request a malware review once clean

If the site was flagged by Google Search Console or browsers as unsafe, a clean site still needs a formal review request before those warnings clear for visitors. Skipping this step means the site can be fully cleaned but still show a security warning to anyone trying to visit it.

Put monitoring in place so this gets caught faster next time

The single best way to limit damage from any future compromise is catching it faster. Uptime monitoring, security scanning, and a maintenance plan that keeps core software patched all reduce both the odds of a repeat and how much damage occurs before it’s caught.

The mistake to avoid

Rushing to restore the site without identifying how the attacker got in is the most common mistake, and it usually leads to a second compromise soon after the first is “fixed.” Getting the site back online matters, but getting it back online with the actual vulnerability closed matters more.

Tell us what you're building.

We keep it small and hands-on. You're talking directly with the people building your site, not a sales rep.

See what clients say