Information checked: 21 July 2026.
Recovering from a hacked website means returning to a trusted state and closing the route used by the attacker. Simply deleting visible spam or reinstalling one plugin is not evidence of recovery.
In brief: Rebuild or restore from a trusted state, rotate access and close the original entry point.
Contain and preserve
- Restrict public access or isolate affected components.
- Preserve logs, suspicious files, alerts and provider evidence.
- Protect email, domain, hosting and administrator accounts using a clean device.
- Revoke unknown sessions, keys and recovery methods.
- Assess connected services and other sites that share credentials.
Find the trustworthy recovery point
Recovery choices
- Clean rebuild from supported software
- When appropriate: Integrity is uncertain or compromise is deep; Risk: Requires careful data migration
- Restore known-clean backup
- When appropriate: A trustworthy pre-incident copy exists; Risk: May reintroduce the vulnerable entry point
- Selective repair
- When appropriate: Scope is narrow and expert analysis is available; Risk: Hidden persistence may remain
Return to service safely
- Patch or remove the entry point.
- Rotate passwords, API keys, database credentials and sessions.
- Validate files, database, administrators, scheduled tasks and redirects.
- Test forms, email, payments and user accounts.
- Reopen gradually with additional monitoring.
- Assess personal-data notification and customer communication.
Acceptance check
Document the root cause, affected period, recovered assets and monitoring evidence. Continue watching for recurrence and suspicious search results or outbound email after reopening.
Do not trust the compromised control panel
If an attacker controlled an administrator account, changes made through that same session may be observed or reversed. Use a clean device and verified support channel to protect email, domain, hosting and recovery methods before rebuilding the site.
Records to keep
- Known-clean administration route.
- Affected and rotated credentials.
- Root-cause and persistence findings.
- Post-recovery monitoring plan.
Owner test: Confirm that every privileged session and integration key that existed during the compromise has been reviewed, revoked or justified.
Sources and date checked
This practical guidance was checked against the following primary sources. Legal duties depend on the organisation and service, so obtain qualified advice where the consequences are significant. Date checked: 21 July 2026.
Keep the decision under your control
Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.