Website Hacked? What to Do in the First 24 Hours
Strange redirects, spam pages, unknown admin users or a malware warning? Here is a step-by-step plan for the first 24 hours after a website hack: contain, clean, secure and recover.
Table of Contents
Quick answer: If your website is hacked, act in this order: contain the damage by taking the site offline or into maintenance mode, preserve evidence and logs, change every password and API key, find and remove malicious code and unknown users, patch the vulnerability that let the attacker in, restore from a clean backup if needed, then request a security review from Google if your site was flagged. QuickHire cybersecurity support helps investigate and fix hacked websites by the hour.
A hack is stressful, and the urge is to delete things fast. Slow down for a moment. A clear sequence protects your users, your data and the evidence you need to stop it happening again.
What are the signs a website has been hacked?
Visitors are redirected to spam, gambling or pharmacy sites.
Google shows "This site may be hacked" or a browser shows a malware warning.
Unknown pages appear in Google search results for your domain.
New admin users, changed passwords or unknown files on the server.
Hosting suspends the account for malware or sending spam.
Sudden traffic spikes, high server load or outgoing spam emails.
What to do in the first 24 hours after a hack
Contain (hour 0 to 1). Put the site in maintenance mode or restrict access. Alert your hosting provider.
Preserve evidence. Download server, access and application logs, and take a full copy of files and database before changing anything.
Reset access. Change hosting, CMS admin, database, FTP or SSH, email and domain registrar passwords. Rotate API keys and payment gateway credentials. Turn on two-factor authentication.
Remove attacker access. Delete unknown admin users, SSH keys, scheduled tasks and backdoor files.
Find the entry point. Common causes are outdated plugins or themes, weak or reused passwords, exposed admin panels and vulnerable custom code.
Clean or restore. Remove malicious code, or restore from a backup taken before the hack, then patch the vulnerability before going live.
Scan and verify. Rescan files and database and check for hidden redirects and spam pages.
Recover your reputation. If Google flagged the site, fix the issues and request a review in Search Console.
Should I restore a backup or clean the hacked site?
Option | Best when | Watch out for |
|---|---|---|
Restore a backup | You have a clean backup from before the hack and little has changed since | The vulnerability is still there. Patch it before going live. |
Clean the live site | No clean backup exists or recent data like orders must be kept | Missed backdoors lead to reinfection within days |
Why does my website keep getting hacked again?
Reinfection almost always means the original entry point was never fixed, or a backdoor was missed. Attackers often leave several hidden files or admin accounts. A proper security audit finds the root cause, not just the visible symptoms.
Do I need to tell customers or authorities?
If personal or payment data may have been exposed, you may have legal duties to notify affected users and regulators. In India, CERT-In directions require many organizations to report certain cyber incidents within six hours. Check your obligations with a legal advisor as early as possible.
How to protect your website after recovery
Keep the CMS, plugins, themes and server packages updated.
Use unique passwords, two-factor authentication and least-privilege access.
Add a web application firewall and file change monitoring.
Keep automated, off-site backups and test restores.
Run regular security audits and vulnerability scans.
When should you call a security expert?
Call immediately if customer data or payments are involved, if the site was reinfected, or if you cannot find how the attacker got in. QuickHire cybersecurity support services cover security audits, vulnerability fixes, access and permission issues and malware investigation. For server hardening and SSL issues, pair it with cloud and DevOps support.
Frequently asked questions
What is the first thing to do if my website is hacked?
Contain the damage first. Put the site in maintenance mode or restrict access, alert your host, and save copies of logs and files before making changes.
How do I know how my website was hacked?
Review server access logs, recently changed files, new user accounts and outdated plugins or software. A security audit traces the entry point so it can be patched.
Will restoring a backup remove the hack?
It removes the malicious changes if the backup predates the hack, but the vulnerability remains. Patch the entry point and reset all credentials before going live.
How do I remove the 'This site may be hacked' warning from Google?
Clean the site, fix the vulnerability, then request a review through the Security Issues report in Google Search Console.
How much does hacked website recovery cost?
QuickHire cybersecurity support starts at ₹1,250 per hour. The total depends on how widespread the infection is and whether a clean backup exists.
Get your issue fixed today
Book cybersecurity support on QuickHire, share the problem and a verified expert starts after a short kick-off call. For a full overview of every support service, read our guide to on-demand technical support.
