Have I been hacked? Signs, first steps and how we can help
Finding out your website may have been hacked is stressful, but it happens to websites of every size and it is fixable. This guide covers the common signs, what to do straight away, how we clean it up, and how to stop it happening again.
How do I know if my website has been hacked?
These are the most common signs customers notice:
- Your visitors see warnings in their browser, such as "Deceptive site ahead" or "This site may be hacked", or Google flags the site in search results.
- Visitors are shown pop-ups, fake "verify you are human" pages, or unrelated ads.
- The site redirects to other websites you did not set up.
- Your site suddenly runs slowly, shows errors, or stops loading.
- You find admin users, plugins, or files you did not create.
- Emails appear to be sent from your domain that you did not send, and recipients report spam from your address.
- Your search rankings drop suddenly for no obvious reason.
- Files or folders on the site cannot be deleted or changed, even though they are yours.
You do not need to diagnose it yourself. If you have seen any of these, report it and we will investigate.
What should I do right now?
- Do not delete anything. Files and logs are evidence and deleting them can make cleanup harder or remove the chance of restoring what was lost.
- Change your cPanel password: How do I change my cPanel login details for a hosting service
- Change your email account passwords: Email Accounts - Changing password
- If you use WordPress, check the Users list in wp-admin for any accounts you do not recognise. Do not delete them yet; just note them.
- Open a support ticket with as much detail as you can: when you first noticed the problem, what you or your visitors saw (screenshots help a lot), any error messages or warnings from Google or your browser, and whether you recently installed anything or shared your login details.
What happens after you report it?
When you open a ticket, our team will:
- Investigate the account and site files to confirm what happened and how.
- Remove malicious files, plugins and injected code. Anything removed is quarantined first, so nothing is lost and the change can be rolled back if needed.
- Remove hidden administrator accounts added by the attacker.
- Reset your website admin password and send you a new one via a secure one-time link.
- Re-scan the site and verify it is genuinely clean before we confirm anything to you.
- Check any other websites on your account, because infections can spread between sites.
How can I stop it happening again?
Most infections start with outdated software, weak passwords, or unused plugins. A few habits make a big difference:
- Keep WordPress, your theme and your plugins up to date: Enable Automatic Wordpress Updates and Wordpress - update plugins
- Use strong, unique passwords everywhere: The Importance of a GOOD Password
- Turn on two-factor authentication (2FA) for your WordPress admin logins where your security plugin or theme supports it.
- Delete plugins and themes you no longer use. Every extra plugin is another possible way in.
- Do not share your cPanel or FTP login details, and remove access for anyone who no longer works with you.
- Keep regular backups so you always have a clean copy to restore from: Jet Backup - Restore Backup and Backup Policy for Hosting Australia
Is my data safe?
In most cases, yes. Malware normally sits on top of your existing files rather than destroying them, and our cleanup process quarantines anything removed so it can be recovered. We also keep backups of hosting accounts, so if files were damaged or deleted there is usually a recent copy that can be restored.
If Google has flagged your site, we can also help you request a review once the site is clean so the warning is lifted.
Still unsure?
If you are not sure whether something is an attack or just a technical fault, that is fine. Open a ticket anyway and describe what you are seeing. It is always better to check.