# My website has been hacked. What do I do now?

Source: https://dijituldns.co.uk/guides/website-hacked/
Updated: 2026-10-08

> If your website has been hacked, put it into maintenance mode, change every password, restore a clean backup from before the attack, then patch whatever let the attacker in. dijitul cleans up hacked sites and hosts them on Complete Hosting at £1 a day + VAT, with daily backups, updates and security monitoring included.

## Key facts

- Most website hacks come from out-of-date plugins, themes, core software or weak passwords.
- A clean backup taken before the hack is the fastest safe way to recover.
- Deleting the obvious bad files is rarely enough: attackers usually leave hidden backdoors.
- Every password needs changing: hosting, control panel, FTP/SFTP, database, CMS admin and email.
- Google can flag a hacked site in search results, and you can request a review once it is clean.
- dijitul Complete Hosting (£1 a day + VAT) includes daily backups, updates, security and monitoring.

## Signs your website has been hacked

A hack is not always obvious. Some attackers deface your home page. Most try to stay hidden so they can keep using your server.

- Visitors are redirected to spam, gambling or fake shop sites, often only on mobile or only from Google.
- Google shows "This site may be hacked" or your browser shows a red warning page.
- Strange pages appear in Google that you never wrote, often in another language.
- New admin users you did not create appear in your CMS.
- Your host suspends the account for sending spam or using too many resources.
- Files you do not recognise appear, such as odd PHP files in your uploads folder.

## What to do in the first hour

Stay calm and work through this in order. Speed matters, but so does not destroying the evidence you need to find the cause.

- **Contain it.** Put the site into maintenance mode or ask your host to restrict access, so visitors are not harmed.
- **Take a copy of the hacked site.** Download the files and database as they are now. This helps work out how the attacker got in.
- **Change every password.** Hosting account, control panel, FTP/SFTP, database user, CMS admin accounts and any email accounts on the domain. Turn on two-factor login where you can.
- **Tell your host.** A good host can check server logs, scan the account and tell you whether other sites are affected.
- **Check for personal data.** If customer data may have been exposed, you may have reporting duties under UK GDPR. See our guide on [GDPR and web hosting](https://dijituldns.co.uk/guides/gdpr-web-hosting-uk/).

## How to clean a hacked website properly

There are two safe routes. Pick the one that fits what you have.

### Route 1: restore a clean backup

If you have a backup from before the hack, restore both files and database. Then update everything straight away, because the hole that let the attacker in is still in that backup. This is why [daily backups](https://dijituldns.co.uk/website-backups/) with a decent history matter: some hacks sit unnoticed for days. dijitul keeps daily backups for 14 days, and it is worth keeping your own older copies too.

### Route 2: clean the site by hand

With no clean backup, the site has to be cleaned file by file.

- Replace the CMS core, plugins and themes with fresh copies from the official sources.
- Search for suspicious code such as *eval(*, *base64_decode(* and *gzinflate(* in PHP files.
- Check the uploads folder for PHP files. Uploads should normally be images and documents only.
- Check the database for injected scripts, spam links and unknown admin users.
- Check .htaccess files and cron jobs (Scheduled Tasks in Plesk) for anything you did not add.

## How to stop it happening again

- Keep the CMS, plugins and themes updated, and remove anything you no longer use.
- Run a supported PHP version where possible. Older sites can stay on older PHP while you plan a fix, but it should be a plan, not a forever.
- Use strong unique passwords and two-factor login for every admin.
- Use SFTP, not plain FTP.
- Keep daily off-site backups and test a restore now and then.
- Put the site behind Cloudflare to filter some bad traffic before it reaches the server.
- If your site is no longer maintained by anyone, read our guide on [whether to rebuild or keep an old website](https://dijituldns.co.uk/guides/rebuild-or-keep-old-website/).

## How dijitul helps with a hacked website

dijitul has been running websites for UK businesses since 2006. If your site has been hacked, we can move it onto our managed hosting, clean it up and get it back online. Our [website rescue](https://dijituldns.co.uk/website-rescue/) service handles sites that are broken, hacked or abandoned.

[Complete Hosting](https://dijituldns.co.uk/complete-hosting/) costs £1 a day + VAT (£365 a year + VAT). It includes managed server updates, security and monitoring, daily backups kept for 14 days, free SSL, a Plesk login and Cloudflare DNS set up for you. Read more about our [website security](https://dijituldns.co.uk/website-security/) approach, or [order Complete Hosting](https://clients.dijitul.uk/order). Call 01623 650333 if the site is down right now.

## FAQs

### How do I know if my website has been hacked?

Common signs are redirects to spam sites, a browser or Google warning, unfamiliar pages in Google results, admin users you did not create, and your host suspending the account for spam. Some hacks only show to mobile visitors or people arriving from Google, so test from a phone and from a search result, not just by typing your address.

### Can I just delete the hacked files?

Usually not on its own. Attackers often leave hidden backdoors in other files, the database or scheduled tasks, so they can get back in. The safer options are restoring a clean backup from before the attack and updating everything, or replacing all core software with fresh copies and checking the database by hand.

### Should I tell my customers my website was hacked?

It depends on what was exposed. If personal data such as names, emails or order details may have been accessed, UK GDPR may require you to report it to the ICO within 72 hours and, in some cases, to tell the people affected. Check the ICO's breach guidance or take advice if you are unsure.

### How long does it take to recover a hacked website?

With a clean recent backup, a small site can often be restored and updated in a few hours. Without a backup, a manual clean can take a day or more depending on the size of the site and how deep the infection goes. Getting Google warnings removed can take a few more days after you request a review.

### Why do websites get hacked?

Most hacks are automated. Bots scan the internet for known holes in out-of-date plugins, themes and CMS versions, and for weak or reused passwords. Small business sites are not targeted personally; they are simply found by scanners. Keeping software updated and using strong unique passwords removes most of the risk.

### Can dijitul fix my hacked website?

Yes. dijitul can move a hacked site onto its managed hosting, clean it, update it and keep it backed up. Complete Hosting costs £1 a day + VAT and includes daily backups, server updates, security and monitoring, free SSL and UK-based support. Call 01623 650333 or email info@dijitul.uk to get started.

## Pricing and ordering

dijitul Complete Hosting is £1 a day + VAT (£365 a year + VAT). Order at https://clients.dijitul.uk/order?product=complete-hosting&ref=dijituldns&src=website-hacked or call 01623 650333.
