ISO 9001 certifiedPCI DSS compliantServing business since 1997320,000+ hosted domains99.9% guaranteed uptime24/7 supportISO 9001 certifiedPCI DSS compliantServing business since 1997320,000+ hosted domains99.9% guaranteed uptime24/7 support
Security

My Website Was Hacked: What Now? Hour-by-Hour Recovery Plan

Your website has been hacked. Follow this hour-by-hour incident response plan to contain the damage, clean the infection and prevent it happening again. First 24 hours are critical.

Your website has been hacked. Follow this hour-by-hour incident response plan to contain the damage, clean the infection and prevent it happening again. First 24 hours are critical.

Signs your website has been hacked

Not every hack is obvious. Some infections sit quietly for months, sending spam or stealing payment data without changing a single page you can see. Common signs include unexpected redirects to unfamiliar domains, warnings from Google Safe Browsing, strange user accounts appearing in your admin panel, files you did not create showing up on the server, and a sudden drop in search traffic because search engines have flagged your site as compromised.

If your hosting provider sends you an abuse notice about phishing or spam originating from your account, take that as confirmed evidence, not a suggestion. Act immediately.

Some signs are server-side only. Check your error logs for unfamiliar scripts running, unexpected database queries, or files being modified outside your usual workflow. If you share hosting, a neighbour account being compromised can spill into yours.

Immediate actions — the first hour

The first hour is about containment, not investigation. Do not start poking around the code yet. The priority is stopping the attacker from doing more damage and preserving evidence.

  • Take your site offline. Replace index.php or index.html with a static holding page, or use your hosting control panel to suspend the account.
  • Change every password: hosting control panel, FTP/SFTP, database, CMS admin, and every user with elevated privileges. Use a password manager — do not type passwords by hand.
  • Revoke all active sessions in your CMS. WordPress, Joomla and other platforms let you invalidate logged-in sessions so the attacker cannot stay connected.
  • Enable two-factor authentication on every account that supports it before you begin any cleanup.
  • Download a full backup of the site as it is now. This preserves evidence and gives you a fallback in case the cleanup goes wrong.

Do not delete anything yet. Do not notify users yet. Do not pay a ransom — there is no evidence that paying results in a clean site.

Assess the damage — hours 2 to 6

Once the site is contained, shift to understanding what happened and what was accessed. This triage determines whether you can clean the site yourself or need professional help.

Start with the access logs. Look for unexpected admin logins from unfamiliar IP addresses, especially outside the Gulf region. Check timestamps to establish the window of compromise. If you use cPanel, the Raw Access logs and the Recent Visitors log are the quickest places to look.

Check the database for unauthorised admin accounts, strange entries in the options or settings tables, and unexpected content in posts or pages. Look for base64-encoded strings, eval() calls, and obfuscated PHP in your theme and plugin files.

Determine the attack vector. Common entry points are outdated plugins or themes, weak admin passwords, nulled (pirated) software with backdoors, unpatched CMS core files, and compromised FTP credentials. The vector tells you what to fix beyond just cleaning the files.

Clean the site — hours 6 to 18

Cleaning a hacked site means removing every malicious file and database entry. Partial cleaning is worse than no cleaning because it leaves backdoors that reinfect the site immediately.

The safest method is a clean reinstall. Download a fresh copy of your CMS and all plugins from the official sources. Compare every file in your installation against the originals using a checksum tool — anything that differs is suspect. Replace all core and plugin files with the clean versions, then apply every available security update.

For the database, use a tool like WP-CLI or phpMyAdmin to search for common malware patterns: base64_decode, eval(gzinflate, system calls, and unfamiliar user accounts. Remove any suspicious entries and reset all user passwords in the database.

If you use a security plugin like Wordfence or Sucuri, run a full scan after the manual cleanup to catch anything you missed. Do not rely on the scanner alone — scanners miss novel malware.

Restore from backup — if you have a clean one

Restoring from a backup is faster than manual cleaning only if the backup predates the infection. Restoring a backup that was taken after the hack simply reinstalls the problem.

If you have a backup from before the infection, restore it to a staging environment first. Update all passwords, upgrade every plugin and theme, and run a security scan before bringing it live. The vulnerability that let the attacker in the first time is still present in the old backup unless you patch it.

If you do not have a clean backup, manual cleaning is the only option. This is where a professional security service saves both time and risk. We handle hacked site recovery for Bahrain businesses and can usually restore a site within 24 hours.

Harden against future attacks

Once the site is clean, the clock starts on hardening. Most hacked sites are recompromised within 30 days because the root cause was never addressed.

  • Update everything: CMS core, all plugins, themes, server software. Enable automatic updates where possible.
  • Implement a web application firewall (WAF). Cloudflare's free tier blocks the majority of automated attacks.
  • Enforce strong password policies. No admin should use a password shorter than 16 characters.
  • Limit login attempts. A plugin or server rule that blocks an IP after five failed attempts stops most brute-force attacks.
  • Disable file editing from the CMS admin panel. In WordPress, define DISALLOW_FILE_EDIT in wp-config.php.
  • Set correct file permissions. Directories should be 755, files 644. Nothing should be writable by the web server unless it absolutely has to be.
  • Schedule automated security scans weekly and review the logs monthly.

Consider moving to a host with built-in security monitoring. Our hosting platform includes automated malware scanning, a web application firewall, and daily backups with one-click restore.

When to call a professional

You should call a professional if any of the following apply: the hack involved payment data (PCI DSS compliance is now at risk), the site is built on a custom platform you did not build, you do not have a clean backup, the site keeps getting reinfected after cleaning, or you simply cannot afford the downtime while you learn security on the job.

A professional clean costs less than the reputational damage of leaving the site compromised. Pricing starts at BD 85 for a standard WordPress cleanup, and we include a post-recovery hardening report with every job.

See our website security checklist for a preventative approach, and read our backup guide to make sure you never lose a clean copy again. If your SSL certificate was compromised during the attack, our SSL guide explains how to get a fresh one issued.

Questions

Frequently asked questions

Look for unexpected redirects, Google Safe Browsing warnings, strange admin accounts, files you did not create, and a sudden traffic drop. Your hosting provider may also send an abuse notice if the site is sending spam.

Yes, if you have technical experience and a clean backup. The process involves replacing all core files, cleaning the database, changing every password, and patching the vulnerability. If any of that sounds unfamiliar, call a professional.

In Bahrain, professional WordPress cleanup starts at BD 85. Custom sites and e-commerce platforms cost more because the review is more complex. Most cleanups are completed within 24 hours.

If the site is cleaned quickly and a proper redirect strategy is used, rankings typically recover within two to four weeks. Google's manual action team can review your site once the cleanup is verified.

Update everything, use a web application firewall, enforce strong passwords, limit login attempts, disable file editing in the admin panel, and run automated security scans weekly. Most reinfections happen within 30 days because the root cause was not fixed.

Put this to work on your site

Send us the brief and we will tell you what it takes, what it costs and how long it will run.

WhatsApp us