my site was hacked, what do i do now? the order of operations for the worst tuesday

cybersecurity · Apr 1, 2026 · 5 min read

the site is defaced, or redirecting to a casino, or your host emailed about phishing pages you did not upload. the next hour matters, and the instinct — start deleting things, change everything, panic-email everyone — is exactly wrong. here is the order that works.

hour one: contain, do not clean

  • do not delete anything yet. the defaced pages, the strange files, the logs — they are the evidence that tells you which door was used. deleting first means cleaning blind and getting re-hacked through the same hole.
  • take it offline if you must, deliberately. a maintenance page is better than a malware distributor; hosts can suspend the account at your request in minutes. your reputation and your visitors’ browsers both prefer the pause.
  • change the critical passwords from a clean device — registrar, hosting, cms admin, database. do it after the initial snapshot, because the attacker’s access might be a password you are about to rotate out from under your own evidence.

hour two: assess

  • how did they get in? outdated plugin, reused password, nulled theme, the form with no protections — the five doors are listed in is my website secure. the logs or the malware’s location usually name the door.
  • what did they touch? defacement only, or injected pages (pharma spam, phishing), or data? if the site stored customer data — orders, form submissions — the notification duty question appears, and it is a legal question, not a technical one. be honest about the answer’s reach.

day one: clean and restore

the professional move is restore, not surgical cleaning: wipe the environment, redeploy from a known-good source (your last clean backup, or the original code), update everything, then reattach the content. cleaning “just the bad files” leaves backdoors; attackers count on exactly this. if there is no clean backup, that fact becomes the lesson of the year — the tested-backup habit is the cheapest insurance in what recurring costs does a website have.

then close the door that let them in, or the timeline repeats: the updates installed, the password rotated properly, the plugin removed, the form hardened. the door list is the checklist.

week one: the aftermath that matters

  • ask google to re-review if search console flagged the site — otherwise the  this site may be hacked  label outlives the malware by weeks.
  • tell the truth at the right size. visitors who saw the defacement deserve a line of honesty; customers whose data may have been involved deserve a direct message, and possibly the law requires one. honesty here is not just ethics — it is what keeps the incident from becoming the story.
  • write down what happened. one page: how they got in, what it cost, what changed. this document is what turns the worst tuesday into the last one of its kind.

FAQ

can i clean it myself or do i need a professional?

if a clean backup exists and the door is identified: yourself, in an evening. if there is no backup, or data was involved, or the site sells things: a professional, today. the hourly cost is smaller than one more week of being compromised.

will my seo recover?

yes, if the cleanup is real and the re-review is requested. rankings dipped by hacks recover; rankings hidden by “cleaned”-but-not-really sites do not, because the malware returns and the trust does not.

how do they even find small sites?

they do not find yours specifically — scanners enumerate the entire internet continuously. my honeypot logs what arrives on an unused server within hours: beetrap, 200 lines of go. you were not chosen; you were reachable, and the door was open.

the closing thought

being hacked is not a verdict on you; it is a scheduled event that visited early. contain before cleaning, restore instead of stitching, close the named door, and write it down. every owner who does this once runs the five-door checklist forever after — which is the only real difference between the sites that get hacked twice and the ones that never again.

if you would rather the worst tuesday be handled by the person who built the site: