Website hacked? What now? Here’s how to restore your website without further damage

Has your website been hacked, or do you suspect something is wrong? Then the order in which you act is what matters most. Immediately deleting random files or restoring an old backup can hide the cause, overwrite evidence, or simply bring an infection back again. First limit the damage, keep what you need to investigate what happened, and then restore in a controlled way.

For a company website or online store, a hack isn’t just a technical problem. Customers, personal data, email accounts, payments, and your visibility in Google may also be involved. That’s why below you’ll find a practical step-by-step plan for Belgian self-employed professionals and SMEs, with extra attention to WordPress.

DNS Belgium advises owners of a hacked website to act quickly, take the website offline for investigation, determine the cause, and then restore a backup. See the official explanation about website hacking.

1. First check whether your website has really been hacked

Not every outage is a hack. An error after an update, an expired certificate, or a faulty plugin can look serious without anyone having broken in. So look for multiple signals before drawing conclusions.

  • You see pages, links, pop-ups, or texts that no one on your team has placed.
  • Visitors are redirected to strange websites.
  • You can no longer log in, or unknown admin accounts have been created.
  • Your hosting provider reports malware, unusual server usage, or suspicious files.
  • Google Search Console reports a security issue or your browser shows a red security warning.
  • Your website suddenly becomes extremely slow, sends spam, or uses an unexpectedly high amount of server capacity.
  • Unknown pages appear in Google, for example about gambling, medicines, or other spam topics.

Note: no notification in Search Console does not automatically mean the website is clean. An attacker can also keep quiet or only abuse parts of the site.

2. Limit further damage without immediately wiping everything

If visitors are at risk, you should isolate the infected website or the affected part as quickly as possible. For a typical SME site, that can mean temporarily showing a maintenance page, blocking traffic to infected sections, or asking the hosting provider to put the site in quarantine.

Do not automatically pull the plug on a server and do not immediately delete all suspicious files. In a serious or targeted attack, logs, files, and timestamps can be important to understand what happened. When in doubt, consult your hosting provider or a security specialist first.

  • Stop ads or campaigns that send visitors to the infected website.
  • Pause forms, payments, or logins if necessary if they are not working reliably.
  • Use a clean device for administration and password changes if you suspect that a computer may also be infected.
  • Do not disclose any public technical details that could help an attacker during the incident.

3. Make a copy of the hacked state and preserve evidence

A backup of a hacked site is not a recovery point, but it can be important evidence. Therefore, if it can be done safely, keep a complete copy of files and database before you start cleaning up. Also note when you discovered the issue and which notifications you have seen.

  • Save relevant server and access logs before they are overwritten.
  • Note suspicious users, modified files, unknown plugins and strange redirects.
  • Take screenshots of warnings in Search Console, your hosting control panel or browser.
  • Keep track of which recovery actions you perform and when.

WordPress also recommends saving a snapshot of the environment before cleanup, even if it is infected. See FAQ My site was hacked on WordPress.org.

4. Contact your hosting provider or webmaster

Your hosting provider often sees information that you cannot see in WordPress. Think of server logs, malware warnings, unusual CPU usage, modified files or accounts logging in from unusual locations. Therefore, ask early in the process what they have found and which recovery options are available.

  • Ask whether the host has already isolated the website or put files in quarantine.
  • Ask which backups are available and what dates they are from.
  • Ask whether other websites within the same hosting account may have been affected.
  • Have them confirm whether they can scan for malware or preserve server logs for investigation.

Don’t have a regular technical partner? The webmaster services of Moonbeetle are intended for technical maintenance, checks and support with issues related to websites and WordPress.

5. Also check email, hosting, domain name, and other accounts

A website hack is not always limited to WordPress. If the same passwords were used elsewhere, or if an attacker gained access to hosting or email, the problem can be bigger than just one website.

  • Check administrator accounts in WordPress and remove unknown users.
  • Check hosting, FTP/SFTP, and database accounts.
  • Check the account with your domain registrar and any DNS changes.
  • Check business email accounts for unknown forwarding rules, new sessions, or changed recovery addresses.
  • Check other websites that use the same hosting, management accounts, or passwords.

Change critical access from a trusted device and end suspicious sessions. After the full cleanup, it is wise to renew the most important passwords once again, so that stolen login details from the infected period do not remain usable.

6. Find the cause and thoroughly clean the website

Removing only visible malware is not enough. If the backdoor or vulnerability remains, the website can become infected again a few hours or days later. The cleanup must therefore also answer the question: how did the attacker get in?

  • Update the CMS, themes, and plugins to supported versions.
  • Replace modified WordPress core files with clean files from the official WordPress source.
  • Reinstall plugins and themes from reliable, official sources instead of keeping suspicious copies.
  • Remove unknown admin accounts, scheduled tasks, and software that is no longer used.
  • Check configuration files and the database for unwanted changes.
  • Use a malware scanner as a tool, but do not rely on a single scan as proof that everything is clean.

Do you have little technical experience, an online store with customer data, or an infection that keeps coming back? Then professional malware removal is safer than experimenting yourself. A half-cleaned website can get infected again without you noticing right away.

WordPress website hacked? Check these parts extra carefully

  • wp-admin and wp-includes: replace the core files with clean versions from WordPress.org.
  • Plugins and themes: remove outdated or unmaintained software and reinstall clean versions.
  • wp-config.php and .htaccess: check for unknown code, redirects, and changed settings.
  • Users and roles: remove unknown admins and grant only the necessary administrator rights.
  • Scheduled tasks (cron): check whether any unknown or suspicious tasks are active.
  • Authentication keys/salts: renew them after an incident so old sessions become invalid.

7. Restore only from a demonstrably clean backup

A backup is only a good recovery source if you are reasonably sure it is from before the break-in. If the website was infected for weeks without visible symptoms, a recent backup may also contain malware.

Therefore, distinguish between two types of backups:

TypePurposeImportant
Copy of the hacked stateInvestigation, evidence, and referenceDo not restore this as a “clean” production version.
Verified clean backupWebsite recoveryCheck the date, updates, and cause before putting the site live.

Don’t have a reliable clean backup? Then a controlled reinstallation or manual cleanup is often safer than randomly restoring an older copy.

8. Reset access and secure the restored website again

Only when the website is clean do you put security back in order. This is the moment to solve not only the visible hack, but also the weakness that made the incident possible.

  • Renew WordPress, hosting, FTP/SFTP, database and domain passwords where relevant.
  • Enable two-factor authentication for administrators and critical accounts.
  • Remove unused plugins, themes and accounts.
  • Install all relevant security updates.
  • Check file and user permissions.
  • Set up automatic backups and keep at least one copy outside the same hosting environment.
  • Test whether a backup can actually be restored.

After the recovery, you can further develop the preventive measures with the guide Website security in 2026. There you will find a more extensive approach to updates, access management, backups and monitoring.

9. Check whether there has been a data breach

A hacked website is not automatically the same as a notifiable data breach. However, you must assess whether personal data could have been lost, altered, viewed or copied. This is especially relevant for online stores, customer portals, membership websites, forms and websites where personal data is stored in a database.

The Belgian Data Protection Authority states that a controller must report a personal data breach without undue delay and, where possible, no later than 72 hours after becoming aware of it, unless it is unlikely that the breach poses a risk to the rights and freedoms of individuals.

  • Determine which personal data may have been affected and how many people are involved.
  • Assess the risk to the individuals concerned and document your reasoning.
  • Report the breach via the DPA portal when the legal notification threshold has been met.
  • If there is likely a high risk to individuals, communication to those affected may also be necessary.
  • Seek legal or privacy advice when the impact is unclear.

Important This section is general information, not legal advice. If sensitive data, payment data, medical information, or a major incident is involved, it is wise to involve a privacy or security specialist immediately.

10. Check Google, only then request a review, and then go live in a controlled manner

A hacked website can be flagged by Google as dangerous or misleading. Therefore, check the Security issues report in Google Search Console. Google shows examples of affected URLs there, but emphasizes that such a list is not necessarily complete.

According to the official Search Console documentation on security issues, you must fix and test all reported issues across the entire website before requesting a review.

  • Check the Security issues report in Search Console.
  • Test the affected URLs and also check similar pages that are not included in the example list.
  • Only request a review when you are sure that both the cause and the infection have been resolved.
  • Allow for a review time of several days to several weeks, depending on the type of issue.
  • After the restart, check rankings, indexing, server logs, and new warnings.

Then bring the website back online in a controlled manner. Test forms, checkout, login, email notifications, redirects, and other functions that are important to your business. A technically “clean” site that does not process inquiries or payments after recovery is not ready yet.

What can a hack do to your visibility in Google?

The impact varies by incident. Malware, hidden spam pages, redirects, or security warnings can deter visitors and reduce your organic traffic. Google may display warnings and keep harmful or hacked content out of the search results.

After recovery, your SEO doesn’t have to be permanently lost. Make sure all unwanted pages and redirects are gone, check Search Console, restore internal links and important pages, and keep monitoring over the coming weeks whether normal indexing and rankings return.

How is a website usually hacked?

With small business websites, a hack is often not a personal attack. Automated bots continuously look for known vulnerabilities and weak accounts. Many incidents arise from a combination of neglected maintenance and overly broad access.

  • Outdated or vulnerable plugins, themes, or CMS software.
  • Weak or reused passwords.
  • Too many admin accounts or accounts belonging to former employees.
  • Unreliable or “nulled” plugins and themes.
  • Poorly secured hosting, FTP, or domain accounts.
  • Vulnerable custom code, forms, or external integrations.
  • An infected device belonging to someone with admin access.

How do you prevent getting hacked again?

After an incident, it’s tempting to just install “a security plugin” and move on. The best protection is a combination of maintenance, access management, monitoring, and restorable backups.

  • Schedule regular updates and technical checks.
  • Use unique passwords and 2FA.
  • Limit admin privileges and remove old accounts.
  • Store automatic backups in a separate location and test restores.
  • Monitor for malware, unexpected changes, and suspicious logins.
  • Remove software you don’t use or that is no longer maintained.

That’s why this page ties in content-wise with the preventive guide on website security. One page helps during the incident; the other helps prevent you from ending up here again.

When is it better to bring in professional help?

Fixing it yourself is not always the cheapest option. If you’re not sure what is infected, the website keeps getting reinfected, or customer data may be involved, a mistaken recovery can cause more damage than it solves.

  • Your online store or customer portal processes personal data or payments.
  • The hack returns after you have already cleaned up the site.
  • Your hosting account contains multiple websites or business email.
  • You don’t know when the infection started and which backup is safe.
  • Google keeps reporting security issues.
  • You no longer have access to WordPress, hosting, or domain management.

Do you want someone to review the technical situation and help determine what needs to be done? Take a look at the webmaster services from Moonbeetle or request an appointment.

Frequently asked questions about a hacked website

How do I know if my website has been hacked?

Watch for unknown content, redirects, suspicious users, hosting warnings, malware alerts, login problems, and the Security issues report in Google Search Console. A single symptom can also be a technical issue, so check multiple signs.

Should I take a hacked website offline immediately?

If visitors are at risk, you should limit further damage quickly. For a regular business website, a maintenance page or quarantine may be appropriate. In the case of a serious targeted attack, evidence may be important; in that case, consult your host or a security specialist first before wiping or reinstalling systems.

Can I just restore a backup?

Only if you are reasonably sure that backup is from before the break-in and is clean. Also, if possible, keep a separate copy of the hacked state for investigation and reference.

My WordPress website has been hacked. Do I need to remove all plugins?

During a thorough cleanup, it is wise to check plugins and themes and remove suspicious or outdated software. Reinstalling from the official source is safer than continuing to use unknown files from the infected installation.

Do I always have to report a data breach within 72 hours?

Not every website hack is automatically subject to mandatory reporting. If personal data has been leaked or has become accessible, you must assess the risk. In Belgium, for notifiable personal data breaches, the competent supervisory authority is informed without undue delay and, if possible, no later than 72 hours after becoming aware of it.

How do I remove the warning from Google?

First fix all security issues and test the entire site. Then request a review via the Security Issues report in Search Console. Google indicates that a review can take from a few days to a few weeks.

Can a hack harm my Google ranking?

Yes. Hidden spam, malicious redirects, malware, and browser warnings can harm traffic and visibility. After a full cleanup and a successful review, rankings can recover, but keep monitoring Search Console and your most important pages.

How do I prevent a second hack?

Update software promptly, use 2FA and unique passwords, limit admin privileges, remove unused software, make off-site backups, and monitor the site. Ongoing maintenance is more important than a single security plugin.

After recovery, you can further develop the preventive measures with the guide “Securing your website in 2026”. This keeps this page focused on incident recovery and keeps the security guide focused on prevention.

Conclusion: acting quickly is good, but the right order is more important

With a hacked website, speed matters, but a good sequence matters even more. Limit further damage, preserve the current state, involve your hosting provider, thoroughly clean the website, and restore only from a reliable source. Then check all access, any privacy obligations, and Google Search Console before going fully live again.

The last step is preventing the same thing from happening again. Updates, strong logins, 2FA, tested backups, and regular technical maintenance make a business website much more resilient against the next attack.

Website hacked? Not sure whether your website is completely clean or has been properly restored?

View Moonbeetle’s webmaster services or get in touch.

...

  • Website security in 2026: how to better secure your website

    Improve website security? Discover 14 practical steps for updates, strong logins, backups, WordPress security and safer website management.

  • Website not reachable? Here’s how to find the cause and get your site back online

    Website not reachable? Check 12 possible causes, from DNS and hosting to SSL and WordPress, and find out what you can safely check yourself.

  • Custom WordPress website: when is WordPress customization the right choice?

    Need a custom WordPress website? Discover when customization makes sense, what determines the costs, and how custom plugins, themes, and API integrations work.

  • Building a website with AI: what can it do and when do you need a web designer?

    AI can create an initial website concept in a few minutes. But is the result suitable for a professional business? Discover the possibilities, limitations, and checks.

  • GEO optimization in 2026: how to make your website visible in AI search results

    What is GEO optimization and how do you make your website visible in AI search results? Discover practical steps for Google AI, content, and measurement.

  • Online store marketing: how to get more visitors and more sales

    Improve your online store marketing? Choose the right approach for more visitors, higher conversion, better margins, and more repeat purchases in your online store.