Discovering your site has been hacked is stressful, but acting methodically gets you back online safely. Follow these steps.
Step 1: Contain the Damage
- Change every password immediately: client area, Plesk, FTP, CMS admin, database users, and email accounts.
- If the site is serving malware or phishing, temporarily take it offline or restrict access while you clean.
- Scan your own computer for malware — stolen FTP passwords are a common entry point.
Step 2: Identify the Entry Point
- Check for recently modified files — sort by date in the Plesk File Manager and look for files you didn’t touch.
- Look for unknown admin users in your CMS.
- Common culprits: outdated plugins/themes, weak passwords, abandoned test installations.
Step 3: Restore or Clean
Cleanest option: restore from a backup taken before the hack (see our backup/restore guide), then immediately update everything and change passwords again.
Manual cleaning: compare files against a fresh copy of your CMS, delete suspicious files, and check for injected code in index.php, .htaccess, and theme files. This is painstaking — incomplete cleaning means reinfection.
Step 4: Close the Hole
- Update CMS, plugins, themes — remove anything unused.
- Enable a security plugin or firewall.
- Review our website security checklist.
Need a Hand?
Open a support ticket marked urgent — our team can help assess the damage, restore backups, and check server logs for the attack vector.

Entry Level
Dedicated Server
Email Service
Design Services
Marketing Services
Domains
Billing
Support
Tools
Company
Support
Tools