What to Do If Your Website Gets Hacked Print

  • hacked website, malware removal, website compromised, site hack recovery
  • 0

Discovering your site has been hacked is stressful, but acting methodically gets you back online safely. Follow these steps.


Step 1: Contain the Damage

  • Change every password immediately: client area, Plesk, FTP, CMS admin, database users, and email accounts.
  • If the site is serving malware or phishing, temporarily take it offline or restrict access while you clean.
  • Scan your own computer for malware — stolen FTP passwords are a common entry point.

Step 2: Identify the Entry Point

  • Check for recently modified files — sort by date in the Plesk File Manager and look for files you didn’t touch.
  • Look for unknown admin users in your CMS.
  • Common culprits: outdated plugins/themes, weak passwords, abandoned test installations.

Step 3: Restore or Clean

Cleanest option: restore from a backup taken before the hack (see our backup/restore guide), then immediately update everything and change passwords again.

Manual cleaning: compare files against a fresh copy of your CMS, delete suspicious files, and check for injected code in index.php, .htaccess, and theme files. This is painstaking — incomplete cleaning means reinfection.

Step 4: Close the Hole

  • Update CMS, plugins, themes — remove anything unused.
  • Enable a security plugin or firewall.
  • Review our website security checklist.

Need a Hand?

Open a support ticket marked urgent — our team can help assess the damage, restore backups, and check server logs for the attack vector.


Kas see vastus oli kasulik?
Back