AC-02Guide verifiedReviewed July 2026
AC-028 minSafety-critical

Hacked website: contain first, repair second

A hacked website is an incident, not just a broken page. The priority is to reduce harm, protect accounts and preserve enough evidence to understand the entry point.

Written and reviewed by Flow Webdesign recovery engineering — WordPress, hosting, DNS and full-stack systemsPublished 24 July 2026Last reviewed 24 July 2026
01

1. Record the symptoms

  • Note redirects, spam pages, browser warnings, changed administrator accounts and unexpected emails.
  • Capture affected URLs and times without clicking suspicious downloads.
  • Check the site from a clean device if you suspect your own computer may be compromised.
02

2. Reduce immediate risk

  • Change hosting and administrator passwords from a clean device and enable multi-factor authentication where available.
  • Contact the host through its official support channel and ask whether they can isolate the site while preserving logs.
  • If payments or customer data may be affected, stop normal operation and escalate immediately.
03

3. Repair the cause, not only the symptom

  • A visible malicious file may be one result of the breach rather than the entry point.
  • Recovery should cover clean source, access keys, vulnerable dependencies, persistence mechanisms and verification.
  • Do not declare the site clean because one scanner or one page says so.

Still blocked after the safe checks?

Send Flow the exact error, when it started and the checks you completed. Never send passwords through the form.

Get website help