Your small business website has been hacked
A hacked website is recoverable, but the order you do things in matters. Here's the sequence that limits the damage and gets the warnings removed fastest.
Quick answer
Take the site offline or into maintenance mode first so visitors stop being harmed. Change every password — hosting, CMS, database, FTP, and the email account they're tied to. Restore from a backup taken before the compromise rather than trying to clean the live site. Then update everything, and request a review in Google Search Console to clear any 'deceptive site' warning.
Step-by-step
- 1
Take it offline before anything else
If your site is serving malware, spam, or redirecting visitors elsewhere, every minute it stays up damages customers and your reputation. Put it into maintenance mode or take it down entirely. A temporary holding page with your phone number is far better than a compromised site.
- 2
Change every password, starting with email
Hosting control panel, CMS admin, database, FTP or SSH, and critically the email account those accounts recover to. Attackers frequently retain access through a password reset route rather than the original hole. Turn on two-factor authentication everywhere it's offered.
- 3
Restore from a clean backup rather than cleaning
Cleaning a compromised site by hand is unreliable — backdoors are designed to be missed. If you have a backup from before the compromise, restoring it is faster and far more trustworthy. Check the backup date against when the problems started, and be conservative: an older clean backup beats a recent infected one.
- 4
Close the hole before going live again
Update the CMS, every plugin, and every theme. Remove anything you don't actively use — dormant plugins are a common entry route. If you don't know how the attacker got in, assume it was an out-of-date component or a reused password, and address both before republishing.
- 5
Get the Google warning lifted
If visitors are seeing a red interstitial warning, open Google Search Console and check the Security Issues report. Once the site is genuinely clean, request a review there. Reviews typically take a few days. Requesting one while the site is still compromised restarts the clock, so be certain first.
Tips & best practices
- ▸Automatic daily backups stored somewhere other than the server itself turn a catastrophe into an inconvenience.
- ▸Most small business sites are compromised by automated scanners, not targeted attacks — out-of-date software is the usual door.
- ▸If you take card payments, check your obligations: a compromise may trigger notification duties to customers and your payment provider.
- ▸A hosted website builder removes most of this risk, because patching is someone else's job.
Common questions
What should I do first if my website is hacked?
+−
Take it offline so visitors stop being exposed, then change every password including the email account your accounts recover to. Only then start on cleanup. Working on a live compromised site while customers are still hitting it makes the damage worse.
How do I know if my website has been hacked?
+−
Common signs are spam content or links you didn't add, visitors being redirected elsewhere, a browser or Google warning that the site is deceptive, a sudden traffic collapse, or your host suspending the account. Search Console's Security Issues report will confirm it.
Can I clean a hacked website myself?
+−
Restoring from a clean backup is far more reliable than manual cleaning, because backdoors are specifically designed to survive a cleanup. If you have no backup and the site is complex, a specialist is worth it — a half-cleaned site typically gets reinfected within days.
How do I remove the Google 'this site may be hacked' warning?
+−
Clean the site completely, then request a review under Security Issues in Google Search Console. Reviews usually take a few days. If you request one before the site is genuinely clean it will fail and you'll wait again.
How do I stop it happening again?
+−
Keep everything updated, delete unused plugins and themes, use unique passwords with two-factor authentication, and run automatic off-server backups. Or move to a hosted builder where security patching isn't your responsibility at all.