My website or email account has been hacked: what to do
Work through the Contain steps first, whatever the symptom. They stop the damage getting worse. Then follow the section for your case.
Signs you've been hacked
Website
- Pages redirect to gambling, pharmacy or adult sites, sometimes only on phones or only from Google results.
- Google shows "This site may be hacked" or "Deceptive site ahead".
- New pages, posts or admin users you didn't create.
- Files you don't recognise in
public_html, or recently changed files you didn't touch. - Your host suspended the account for malware or phishing.
- Contacts receive spam or phishing from your address.
- Bounces for messages you never sent flood your inbox.
- The Sent folder has messages you didn't write, or is suspiciously empty.
- The account hit the sending limit, or was suspended for spam.
- Outlook or your phone suddenly asks for the password, because we reset it.
Contain: do these now, in order
- Change the control panel password. Log in via the client area one-click login (see How to log in to cPanel or DirectAdmin) and set a new, long, unique password.
- Change every email password on the account, not just the one that's obviously hacked. See How to reset or change an email account password. Then update your devices, or your connection gets blocked by failed logins.
- Change FTP passwords and delete FTP accounts you don't recognise.
- Change your client area password and turn on 2FA. See How to turn on two-factor authentication for my client area.
- Change the WordPress (or other CMS) admin password, and the database password in the control panel and in the site's config file.
- Check your own computer. Run a full antivirus scan on every computer that has these passwords saved. A hacked PC is the most common way passwords leak, and changing them from an infected machine hands the new ones over too.
Hacked website: clean it
1. Find how they got in
Almost always one of: an outdated plugin, theme or CMS version; a weak or reused password; or a leaked FTP password from an infected computer. Fixing the symptom without fixing the cause means it happens again within days.
2. Clean the site
Option A: Restore a backup from before the hack. Fastest and most reliable if you have one. Restore both files and database, then immediately update everything and change passwords. Webway can help with a restore; open a ticket.
Option B: Clean in place.
- In the control panel, take a full backup first, so nothing is lost if cleaning goes wrong.
- In WordPress, delete every plugin and theme you don't use. Update everything that remains.
- Reinstall WordPress core: Dashboard → Updates → Re-install replaces core files with clean copies.
- Delete plugins and themes you do use, then reinstall them fresh from wordpress.org. Uploaded copies may be infected.
- In File Manager, sort
public_htmlby Last Modified. Look for files changed around the hack date that you didn't change, especially.phpfiles inwp-content/uploads, files with random names, and extra.htaccessfiles in subfolders. Delete them. - Check Users in WordPress. Delete admin accounts you don't recognise.
- Check
.htaccessinpublic_htmlfor redirect rules you didn't add. Replace with the default WordPress block if unsure. - Check
wp-config.phpfor added lines at the top or bottom. - Run a malware scanner plugin (Wordfence, or Sucuri's scanner) and fix what it finds.
Webway can clean it for you. Open a ticket and we'll run a clean. If a site can't be cleaned completely, we'll recommend reinstalling it from scratch, because a partly cleaned site usually gets reinfected.
3. Remove the warnings
- Google: in Google Search Console, go to Security Issues and request a review once clean.
- Browser warnings clear within a day or two of Google's review.
- Blacklists: check your domain on an online blacklist checker and request delisting where needed.
4. Stop it recurring
- Turn on automatic updates for WordPress, plugins and themes.
- Remove unused plugins and themes.
- Use unique passwords and 2FA on WordPress admin.
- Keep the PHP version current. See How to change my PHP version and PHP settings.
- Keep backups you can restore. Check they actually restore.
Hacked email: stop the spam
- Change the password (done in Contain). This cuts the spammer off immediately; sending stops within minutes.
- Check settings the attacker may have added:
- Forwarders sending copies of your mail elsewhere (control panel Forwarders, and filters in webmail).
- Autoresponders.
- A changed signature.
- Check the Sent folder to see what went out. If invoices or banking details were involved, warn the recipients: attackers use hacked accounts to send fake "our bank details have changed" emails.
- Warn your contacts briefly that emails from you around those dates were not from you, and not to open links.
- Check the computer and phone that use this mailbox for malware. A stolen password usually comes from a device, a phishing page, or the same password used on another breached site. Check yours at haveibeenpwned.com.
- If the account was suspended for spam, reply to our ticket once the password is changed and devices are checked. We unsuspend once we're satisfied it's stopped. See My hosting account is suspended: what do I do?
- Check your domain isn't blacklisted and that SPF, DKIM and DMARC are set. See How to set up SPF, DKIM and DMARC for my domain. Deliverability may be poor for a few days.
What Webway can and can't do
- We can: run a malware clean on your site, reset passwords, suspend a compromised mailbox to stop spam, tell you which mailbox or script was sending, and help with restores.
- If a site can't be cleaned completely, we recommend reinstalling it.
- We can't: recover data that was deleted before the last backup, or manage your computer's security.
Still stuck?
Open a support ticket and include:
- The domain and, for email, the affected address.
- What you've seen: redirects, defacement, Google warning, spam bounces. Screenshots or a forwarded example as an attachment.
- When it started, as best you can tell.
- Which passwords you've changed so far.
- Whether the site is WordPress (and its version), another CMS, or custom.
- Whether you have a clean backup and its date.
- Whether you've scanned the computers that use these logins.
Did this answer it?