This site contains affiliate links — we may earn a commission if you sign up through them. Details

Website Hacked? A Step-by-Step Recovery Guide (2026)

Complete guide to recovering a hacked website — identifying signs, isolating the site, removing malware, restoring from backup and preventing reinfection

Website Hacked? A Step-by-Step Recovery Guide (2026)

Signs your website has been hacked

Many site owners do not realise they have been hacked until someone reports it or Google flags the site. Spotting the signs early greatly reduces the damage, because malware left in place spreads to other files and hurts your SEO.

5 things to do the moment you find out

Based on real-world use, do not panic-delete everything — you may destroy evidence and a clean backup you have not separated yet. Work calmly in order: stop the damage first, then recover.

  1. Stay calm and record the time and symptoms as evidence
  2. Change key passwords now: hosting panel, FTP, database and email
  3. Contact your host's support — many can scan and help recover
  4. Snapshot the current state (files + database) for later forensics
  5. Do not pay any ransom, and do not delete server logs

Take the site offline temporarily

Putting the site into maintenance mode stops the malware from reaching visitors and prevents attackers from using your site to send more spam. You can still access the backend to clean up.

📊 Key takeaway: Enable a maintenance page or restrict access with a password (.htpasswd)

Scan for malware and injected files

The heart of recovery is finding which files were changed and what was injected. Malware often hides in files that look legitimate or uses obfuscated base64 code that is hard to read.

Clean up and restore from backup

This is important — the safest and fastest route is to restore a clean backup from before the hack, then update everything to the latest version. Without a backup you must remove infected files one by one — slow and easy to miss something.

  1. Restore a clean backup from before the hack (where auto-backups save you)
  2. Update the CMS, all plugins and themes to the latest versions
  3. Remove every unknown plugin, theme and user account
  4. Regenerate system keys and salts (e.g. wp-config) to kill old sessions
  5. Re-scan to confirm the site is truly clean before going live

Rotate all passwords and access keys

Even after cleaning the files, if attackers still have your old passwords they can return. Change everything related and enable two-factor authentication.

  1. Change hosting panel, CMS admin and database passwords
  2. Change FTP/SFTP passwords and delete unused FTP accounts
  3. Regenerate all API keys and tokens you previously used
RecommendedAsiaGB.com — the hosting & VPS we use and recommend: servers in Thailand and Singapore, SSD storage, managed through DirectAdmin, with 24-hour Thai support and 99% uptime.

Editor's pick from our hands-on testing.

Visit AsiaGB →

Request review to clear Google warnings

If Google has flagged or delisted your site, after cleaning you must request a review through Search Console — otherwise users keep seeing the red warning and your traffic stays gone.

Prevent re-infection and choose secure hosting

Recovery ends with long-term prevention. A site on hosting with automatic malware scanning and regular backups bounces back from incidents far faster. From our testing, our recommended provider asiagb.com runs cpGuard to continuously scan for malware and web shells, offers SSD storage managed through DirectAdmin, and has 24-hour Thai support that genuinely helps during an incident.

Frequently Asked Questions

Should I delete everything and start over after a hack?
Not always. If you have a clean backup from before the hack, restoring it and updating to the latest versions is usually faster and safer. Wiping everything should be a last resort when there is no backup and cleaning is not possible.
Can I recover without any backup?
Yes, but it is harder and slower. You must scan for infected files, strip injected code and compare against the original CMS files one by one. Ask your host's support team, who have scanning tools, and enable automatic backups immediately afterwards.
Why did my Google ranking drop after the hack?
Google may flag the site as unsafe or delist pages to protect users, and injected spam pages worsen your quality signals. After cleaning, request a review in Search Console to recover.
What kind of hosting reduces the chance of being hacked?
Choose hosting with automatic malware scanning, a firewall, regular backups and responsive support. From our testing, our recommended provider asiagb.com runs cpGuard for continuous scanning, with SSD storage managed through DirectAdmin and 24-hour Thai support.