Step-by-step · Maintenance and Security

Recovering from a Hacked Website

Recovering from a hacked website means returning to a trusted state and closing the route used by the attacker. Simply deleting visible spam or reinstalling one plugin is not evidence of recovery.

Information checked: 21 July 2026.

Recovering from a hacked website means returning to a trusted state and closing the route used by the attacker. Simply deleting visible spam or reinstalling one plugin is not evidence of recovery.

In brief: Rebuild or restore from a trusted state, rotate access and close the original entry point.

Contain and preserve

  1. Restrict public access or isolate affected components.
  2. Preserve logs, suspicious files, alerts and provider evidence.
  3. Protect email, domain, hosting and administrator accounts using a clean device.
  4. Revoke unknown sessions, keys and recovery methods.
  5. Assess connected services and other sites that share credentials.

Find the trustworthy recovery point

Recovery choices

Clean rebuild from supported software
When appropriate: Integrity is uncertain or compromise is deep; Risk: Requires careful data migration
Restore known-clean backup
When appropriate: A trustworthy pre-incident copy exists; Risk: May reintroduce the vulnerable entry point
Selective repair
When appropriate: Scope is narrow and expert analysis is available; Risk: Hidden persistence may remain

Return to service safely

  • Patch or remove the entry point.
  • Rotate passwords, API keys, database credentials and sessions.
  • Validate files, database, administrators, scheduled tasks and redirects.
  • Test forms, email, payments and user accounts.
  • Reopen gradually with additional monitoring.
  • Assess personal-data notification and customer communication.

Acceptance check

Document the root cause, affected period, recovered assets and monitoring evidence. Continue watching for recurrence and suspicious search results or outbound email after reopening.

Do not trust the compromised control panel

If an attacker controlled an administrator account, changes made through that same session may be observed or reversed. Use a clean device and verified support channel to protect email, domain, hosting and recovery methods before rebuilding the site.

Records to keep

  • Known-clean administration route.
  • Affected and rotated credentials.
  • Root-cause and persistence findings.
  • Post-recovery monitoring plan.

Owner test: Confirm that every privileged session and integration key that existed during the compromise has been reviewed, revoked or justified.

Sources and date checked

This practical guidance was checked against the following primary sources. Legal duties depend on the organisation and service, so obtain qualified advice where the consequences are significant. Date checked: 21 July 2026.

Keep the decision under your control

Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.