If your whole hosting account is compromised, not just a single site, lock out the attacker everywhere they could have gotten a foothold, then find and close the entry point before you restore anything. Skipping the lockdown step is a common reason sites get reinfected after a clean restore.
This article covers account-wide compromise: multiple sites affected, unfamiliar cPanel changes, or mail/cron/FTP being abused. If only one WordPress or CMS install looks off, my website has been hacked is the narrower path.
Lock down every access point first
Change these passwords immediately, in this order, before you do anything else:
- Portal password (Account page), and turn on two-factor authentication under
Account → Securitywhile you're there. - Hosting/cPanel password.
- Every FTP account password, and delete any FTP account you don't recognize.
- Every email account password (an attacker with mailbox access can reset everything else downstream).
- Database passwords, and update the corresponding credentials in your application's config file (
wp-config.phpfor WordPress, or equivalent). - Any WordPress or CMS admin accounts, and delete admin users you didn't create.
Take a full backup of the account first if you can, even a compromised one. It preserves evidence of what happened and gives you a fallback if cleanup goes wrong.
Check for account-wide persistence
A site-level hack usually stays in one docroot. An account-level compromise can plant persistence in places that survive a single-site cleanup:
- Cron Jobs - open the Cron Jobs tile and look for anything you didn't schedule. A cron job that re-downloads a malicious file on a timer is a common way reinfection happens right after a manual cleanup.
- Email Forwarders and Autoresponders - check for forwarders quietly copying mail (invoices, password resets) to an outside address.
- Addon Domains and Subdomains - confirm every entry is one you created. Attackers sometimes add a subdomain to host a phishing page under your reputation.
- FTP and Git Version Control - review for accounts or repos you don't recognize.
- File Manager - across every domain on the account, not just the one that triggered the alert.
Find the entry point
Cleaning the symptom without finding the entry point does not prevent reinfection. Work through the likely vectors:
- An outdated plugin, theme, or CMS core with a known vulnerability.
- A weak or reused password that was brute-forced or leaked in an unrelated breach.
- Credentials stored insecurely on a developer's machine, or phished from an admin.
- A vulnerable custom script somewhere on the account, especially older or abandoned sites you forgot were still live.
If you have PHP or access logging enabled, the entry point often shows up as a cluster of unusual POST requests right before the first suspicious file appeared. See enabling error logging if logging isn't already on, and check the per-domain access log for the timeframe just before you noticed the compromise.
Scan and clean
Run a full scan across every site on the account, not just the one that tripped the alert; a compromise that started on one domain can spread laterally to others sharing the same account. Open cPanel and run Imunify360 under Security for a server-side scan. Full detail on what to do with each type of finding is in scanning your website for malware.
For sites where the scan finds core file modifications or backdoor files rather than just injected snippets, restoring from a clean backup is usually faster and more reliable than manual cleanup. Pick a backup dated before your earliest evidence of compromise, restore it from the Backups tile, then reapply the password changes above since a restore won't undo those.
After cleanup
Once every affected site is clean and every credential is rotated, go back through the checklist: confirm cron jobs, forwarders, FTP accounts, and admin users all match what you expect, and that two-factor authentication is on for the portal. Watch the account for a few days, and run another manual scan under Security in cPanel partway through that window. A fresh eye on your own logs for the first week catches anything the scanners missed.
When to contact support
If you're not confident you've found every affected file, if the scan keeps finding new malware after cleanup, or if you suspect the compromise reaches beyond what you can see in cPanel, open a ticket from the portal. It goes to a real person, not a bot, and they can look at server-level signals you don't have access to from cPanel alone.