Get a free website with any plan

See how
TROUBLESHOOTING

My website has been hacked

Last updated

IN SHORT

Flashcloud recommends a methodical cleanup after a hack: lock out attackers by changing every password and enabling two-factor, find the entry point, scan for malware, restore from a clean backup if you have one, then patch what let them in.

A hacked website is fixable. Don't panic. Work through the cleanup methodically.

Stop the bleeding

First, prevent further damage:

  1. Take a snapshot if you're on a VPS — preserves the current state for forensics.
  2. Take a backup of your hosting account in cPanel — same idea.
  3. Change all passwords immediately:
    • Hosting / cPanel password.
    • FTP passwords (all accounts).
    • WordPress / CMS admin passwords.
    • Database passwords (and update wp-config.php).
    • Portal password (the Account page).
  4. Enable two-factor authentication on your portal account (Account → Security).
  5. Disable any unused FTP accounts.

This locks attackers out of further re-entry while you clean up.

Identify the entry point

How did they get in? Common vectors:

  • Outdated plugin or theme with known exploit (most common for WordPress).
  • Outdated CMS core — WordPress 5.x, Joomla X.x with known CVEs.
  • Weak password that was brute-forced.
  • Compromised FTP credentials — maybe stored insecurely on a developer's laptop.
  • Phished login — admin clicked a phishing link, gave up credentials.
  • Hijacked plugin — a legitimate plugin was compromised in the supply chain.
  • Insecure custom code — SQL injection, file upload vulnerability.

Check:

  • Plugin/theme/CMS versions — anything outdated?
  • Recent admin user activity — logins from unusual IPs?
  • Modified files — what's been changed recently? (find /home/your-user -mtime -30 -type f).
  • Server logs — unusual access patterns, suspicious POST requests.

Run a malware scan

See Scanning your website for malware for the full options. Quick path:

  1. Server-side: cPanel → Imunify360 → Start Scan.
  2. WordPress-side: install Wordfence → run a deep scan.

The scans find:

  • Modified WordPress core files (file integrity issues).
  • Injected JavaScript or PHP.
  • Backdoor files (commonly named .php files in /wp-content/uploads/).
  • Suspicious database content.

Note the findings.

Restore from a clean backup

The fastest path to a clean site is restoring from a backup taken before the compromise:

  1. Identify when the compromise happened — server logs and file modification dates point at this.
  2. Find a backup from before that date — see Backup options.
  3. Restore — typically from the Backups tile.
  4. After restore, immediately update everything so the same exploit can't be re-used.

If you don't have a clean backup, manual cleanup is needed (next section).

Manual cleanup (if no clean backup)

For each detected malware:

  1. Delete the file — if it's a backdoor or wholly malicious.
  2. Restore from official source — for modified WordPress core files, replace with a clean copy from WordPress.org.
  3. For modified plugin/theme files, re-install the plugin/theme from a clean source.
  4. Remove unauthorized admin users — go to wp-admin → Users and delete any you don't recognize.
  5. Audit cron jobs — attackers sometimes add scheduled cron jobs to maintain access. Check cPanel → Cron Jobs.
  6. Audit .htaccess — attackers may add redirects or include rules.

For each piece of WordPress:

  • WordPress core — re-install via wp-admin → Updates → Re-install. Or via wp-cli: wp core download --force.
  • Themes — delete and re-install from WordPress.org or from your developer.
  • Plugins — same.

After cleanup, run another scan to verify nothing was missed.

Patch the entry point

Once cleaned, fix what let them in:

  • Update WordPress core to the latest version.
  • Update all plugins and themes.
  • Remove unused plugins and themes (smaller attack surface).
  • Replace weak passwords with strong ones.
  • Enable two-factor on all admin accounts.
  • Audit FTP accounts — only keep what's needed.
  • Restrict admin access by IP if your team works from a known network.

If a specific plugin's vulnerability was the entry point:

  • Confirm the plugin is now updated to a patched version.
  • If the plugin is abandoned (no updates in years), replace with an alternative.

Notify if needed

Depending on what happened:

  • Customer data exposed? Many jurisdictions require breach notification (GDPR, state laws, etc.). Consult legal counsel.
  • Phishing pages were hosted on your domain? Notify customers via email so they don't fall for the lookalike if it ever resurfaces.
  • Credit card data exposed? Specific requirements via PCI DSS.
  • Site flagged by Google? Submit re-review via Search Console after cleanup.

For a hacked site that affected customers, a transparent post-incident communication often goes a long way for trust.

Get help

If cleanup is overwhelming or you're not confident:

  • Open a ticket with our team — we can help review, particularly if backups are available.
  • Hire specialists — services like Sucuri, MalCare, and Wordfence offer paid cleanup. Costs typically $100–500 for a one-off cleanup.
  • For complex cases (e-commerce sites, regulated industries), professional help is worth the cost.

After recovery

Once the site is clean and stable:

  1. Review what went wrong — write down the cause and fix for future reference.
  2. Set up better backup hygiene — daily backups, off-site storage, tested restore process.
  3. Schedule periodic reviews — quarterly check that updates are current, no suspicious users, no new files.
  4. Consider a security service — for ongoing protection (Wordfence Premium, Sucuri).

A site that's been hacked once is more likely to be targeted again — attackers share lists of compromised domains. Hardening after the first incident is critical.

Power-user note

For technical incident response with logs and forensics:

  • Server access logs show exactly which requests hit the site and when. Filter for suspicious patterns: weird user agents, lots of POST requests to admin URLs, requests to known-malicious paths.
  • MySQL slow query log sometimes catches SQL injection attempts.
  • auditd on a VPS can record system-level activity for deep investigation.

For high-stakes compromises, copy logs off the server before they rotate — preserve evidence for any legal or law-enforcement involvement.

Common questions

How do I know if my website was actually hacked?

Run a malware scan first: cPanel's Imunify360 for server-side checks, Wordfence for a deep WordPress scan. These catch modified core files, injected code, and backdoor files, usually named .php files hidden in /wp-content/uploads/.

What's the fastest way to fix a hacked site?

Restoring from a clean backup taken before the compromise, typically from the Backups tile in your hosting account. Check server logs and file modification dates to pinpoint when the hack happened, then find a backup from before that date.

What if I don't have a clean backup to restore from?

You'll need manual cleanup: delete backdoor files, re-install WordPress core from WordPress.org, re-install any modified plugins or themes from a clean source, and remove admin users you don't recognize. Run another scan afterward to confirm nothing was missed.

Will my site get hacked again after I clean it up?

It's more likely, not less, since attackers share lists of compromised domains. Patch the entry point immediately: update WordPress core and all plugins, remove unused plugins and themes, replace weak passwords, and enable two-factor on every admin account.

Do I have to tell anyone that my site was hacked?

It depends on what happened. Exposed customer data can trigger legal breach-notification requirements under GDPR or state laws, so consult legal counsel. If phishing pages were hosted on your domain, notify your customers directly by email.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.