Technical Guides 03/08/2026

My Website Was Hacked / Looks Suspicious - What To Do Right Now (2026 Emergency Guide)

Your site redirects to spam, Google flags "this site may be hacked," or pages appear that you never built. A calm action guide: what to check immediately, what not to touch in panic, and when to repair versus rebuild.

Reading time: 15 min Naor Cohen
My Website Was Hacked / Looks Suspicious - What To Do Right Now (2026 Emergency Guide)

Emergency, not panic

"The site looks weird" is not a small design glitch. Sometimes it is a bug. Sometimes someone is already inside the server.

The phone rings. A client says Google marked the site as hacked. Or the homepage redirects to a casino. Or English pharmacy pages appear that nobody wrote. That moment feels like a fire - and it is exactly when people do the worst thing: delete everything without a snapshot, change one password, and hope it disappears.

I am Naor from NaorX. I have cleaned hacked sites, ancient WordPress plugins, open server permissions, and "quick fixes" that brought the same backdoor back a week later. This article is not a legal investigation or an enterprise SOC playbook. It is a clear action order when a business owner needs to know what to do this morning.

Do not do this now:

Do not wipe all files without a forensic snapshot. Do not install a "magic cleaner" plugin and assume you are done. Do not ignore email / hosting / WordPress accounts still on a weak password. A breach you do not close comes back.

Signs it is a real breach (not just a bug)

  • Strange redirects: some visitors land on foreign pages, especially mobile or certain countries.
  • Google / Safe Browsing warning: "this site may be hacked" or a red interstitial.
  • Content you did not write: posts, pages, or random PHP files with junk names.
  • New admin users in WordPress or the hosting panel.
  • Mail leaving your domain that you did not send (server used for spam).
  • Sudden CPU / traffic spikes with no campaign you are running.
  • Poisoned SEO: Google shows titles and links on topics you never touch.

A CSS bug does not create a new admin. A broken plugin does not send thousands of emails overnight. Several signs together - treat it as a security incident.

First hour: action order

1) Document what you see

Screenshots of the warning, redirect URL, suspicious page, and discovery time. If you have Search Console - save the message. It helps cleanup and client communication later.

2) Confirm access to domain and hosting

Without DNS, cPanel / server, and the domain mailbox, you are stuck. If access sits with an old vendor who does not answer, that is part of the problem. Ownership at handover is covered in what you get at delivery.

3) Rotate passwords - in the right order

Start with hosting, domain, primary email, then the CMS (WordPress etc.). New strong passwords - not the same string with a 1 at the end. Enable 2FA everywhere it exists.

4) Consider maintenance mode / temporary takedown

If the site is spreading spam or skimming data, a short maintenance page can be more responsible than leaving the door open for customers.

5) Do not restore an old backup blindly

A backup from two weeks ago may already include the backdoor. Blind restore = the breach smiling again.

Important:

If you run a store or lead forms with customer data - assume exposure is possible. Sometimes customers need a notice, or card activity needs a check. Do not lie to yourself about it.

Where attackers usually get in (especially WordPress)

Most SMB sites in Israel are not breached by a movie hacker. They are breached because:

  • Plugins / themes not updated for years
  • Weak or shared admin passwords
  • Old developer users still active
  • Open file uploads without protection
  • Cheap hosting with old PHP / unpatched servers
  • Migrating a site that was already infected

This ties to website maintenance: "fix and forget" is how you get here. Updates, backups, and plugin hygiene are insurance.

Repair vs rebuild - when each

Cleanup can make sense when:

  • The site is relatively current and infection looks localized
  • You have a verified clean backup from before the breach
  • Someone skilled can walk logs, permissions, and plugins one by one

Rebuild should be on the table when:

  • WordPress with dozens of abandoned plugins and no maintainer
  • The breach returns after a "cleanup"
  • The codebase is untrusted legacy - same frame as patch, upgrade, or rewrite
  • The business already needs a new structure, payments, or speed - and the breach only exposed it

From the field:

A cheap cleanup that never closes the entry vector costs more than a clean rebuild. If you "clean again" every month, you are not saving - you are paying for the same fire in installments.

After cleanup: do not stop at "it is live again"

  1. Remove unused plugins and themes.
  2. Update core, plugins, PHP to supported versions.
  3. Audit admin users - only who needs access, least privilege.
  4. Limit login attempts (rate limit / 2FA / careful login path changes).
  5. Confirm HTTPS and a valid SSL certificate.
  6. Off-server automatic backups - and one tested restore.
  7. Search Console: request a review after you are sure it is clean.
  8. Watch for 1-2 weeks for new files, new users, and odd load.

What to tell customers (without useless panic)

If the site is your storefront, silence looks worse than short transparency. A status note / business WhatsApp can say: the site is under temporary security maintenance, orders / leads go to an alternate channel, we will be back when it is stable. Do not promise "nothing happened" if you do not know.

Quick mental checklist

  • Document + screenshots
  • Access to domain / hosting / email
  • Rotate critical passwords + 2FA
  • Isolate (maintenance) if customers are at risk
  • Find the entry vector - not only the symptom
  • Decide: deep cleanup or rebuild
  • Harden + backup + monitor
  • Request Google warning removal after a real clean

Summary

A hacked site is not a bad design day. It is an incident where someone used your server for spam, poisoned SEO, or data theft. The right response is ordered: document, lock access, find how they got in, clean or rebuild, then harden so it does not return.

If your site is flagged, redirecting, or you are unsure what was touched - do not play with magic plugins. Bring someone who can read logs and files, or build a clean path from scratch.

Site flagged / redirecting / looking suspicious and you need a pro?

At NaorX I handle cleanup, hardening, and sometimes a rebuild when the base is rotten. Describe what is happening via the contact form - and we can see if it is a point fix or a clean new path.

Need help with your project?

Whether it's a website, bot, automation or something else - I'm here to help you build a solution that works

Share this article:

More Articles You Might Like

Keep reading and expand your knowledge