Your Website Has Been Hacked: The Recovery Plan

Your Website Has Been Hacked: The Recovery Plan - feature image for the Rapid Ready AI blog.

What you will end up with

A restored website that your customers can access again, a clear record of what happened and when, payment processors notified and ready to resume, and the entry point closed so it cannot happen twice.

Before you start

  • Your hosting login details and password manager
  • Your hosting provider's phone number and support ticket system
  • A list of who needs to know: staff, customers, payment processor (Stripe, PayPal, Square, etc.)
  • Access to any backups you have made, or knowledge of your host's backup schedule
  • A timeline of when you first noticed the problem

Step 1: Take the site offline immediately

Your first move is to stop the site from serving to visitors. This prevents further damage and stops attackers from using it.

Log into your hosting control panel. Most hosts offer a simple maintenance mode toggle. If yours does, switch it on. Visitors will see a static message instead of your site. Your data stays intact.

If your host does not have maintenance mode, rename your main index file (usually index.html or index.php) to something like index.html.backup. Create a new blank index file with a single line: "Site under maintenance. We will be back shortly." Upload it to your root folder.

What you should see: A plain message when you visit your domain. No errors. No malicious content visible.

Step 2: Contact your hosting provider and report the breach

Call them. Email is too slow. Have these details ready when you call:

  • Your account number and domain name
  • When you first noticed the breach (date and time)
  • What you saw (malware warning, defaced page, unexpected files, etc.)
  • Whether you use their backup service or your own

Tell them you need an urgent security review and a list of all backups available from before the breach date. Ask them to check their server logs for suspicious login attempts or file uploads. Request they flag your account for priority support.

What you should see: A ticket number, a named support contact, and a timeframe for their initial review.

Step 3: Notify affected customers and payment processors

Send a brief, honest message to your customers today. Delay makes things worse. Use this template:

"We discovered unauthorised access to our website on [date]. We have taken it offline and are working with our hosting provider to restore it. If you made a purchase with us, your payment card data is handled by [payment processor name] and was not stored on our servers. We will update you by [specific date]. Thank you for your patience."

Send the same message to your payment processor (Stripe, PayPal, Square, etc.) with your account details. They have fraud teams and need to know immediately. Do not speculate about what was accessed. Do not blame your host publicly. Do not say "we have been hacked" in a way that sounds like you ignored security.

What you should see: Delivery confirmations from your email provider and an acknowledgement from your payment processor.

Step 4: Work with your host to restore from a clean backup

Your host will offer you a list of backups. You need the most recent one made before the breach date. If you discovered the breach on Monday, ask for the Friday backup.

Before your host restores it, ask them to:

  • Scan the backup files for malware
  • Confirm the backup date in writing
  • Tell you how long the restore will take

Once restored, do not make it live yet. Ask your host to give you a staging URL (a temporary address where you can view the restored site privately). Visit it. Check that:

  • Your homepage loads without errors
  • Your contact form works
  • Your payment links are intact
  • No warning messages appear in your browser

What you should see: A working copy of your site before the breach, accessible only to you.

Step 5: Change all passwords and API keys

Log into your hosting control panel with a new password. Then change these, in order:

  • Your hosting account password
  • Your domain registrar password (where you own your domain name)
  • Any API keys for payment processors, email services, or third-party tools
  • Your CMS admin login (WordPress, Shopify, etc.)
  • Any FTP or SFTP credentials
  • Your email account password

Use a password manager to generate new ones at least 16 characters long. Do not reuse old passwords.

What you should see: Confirmation messages from each service as you update them.

Step 6: Scan for remaining malware or backdoors

Even after restore, check for hidden files the attacker may have left behind. Ask your host to run a security scan on the restored files. If they do not offer this, ask them to check for:

  • Files modified after your backup date
  • Hidden files starting with a dot (.) in your root folder
  • Unusual .php or .js files in unexpected locations

If you use WordPress, install a security plugin such as Wordfence or Sucuri. Note that free versions have limitations; paid versions offer more thorough scanning. Run a full scan. It will flag suspicious code. Review any alerts and delete flagged files only if you recognise them.

What you should see: A clean scan report with no critical alerts.

Step 7: Patch and update everything

The breach happened because something was out of date. Update immediately:

  • Your CMS (WordPress, etc.) to the latest version
  • Every plugin and theme you use
  • Your server software (ask your host to do this)
  • Any custom code or integrations

Do this on the staging URL first, not on your live site. Test everything again. Then apply the same updates to your live site.

What you should see: Version numbers increase in your admin panel. No error messages after updates.

Step 8: Review access logs to understand how they got in

Ask your host for server access logs from the week before the breach. Look for:

  • Login attempts from unfamiliar IP addresses
  • Requests to files that do not exist (scanning for vulnerabilities)
  • Unusually large file uploads
  • Requests to admin pages at odd times

You do not need to be a technician to spot patterns. Anything that looks unusual, screenshot it and send it to your host. They can interpret it. This tells you whether the breach came from a weak password, an unpatched plugin, or something else.

What you should see: A clear timeline of suspicious activity and your host's explanation of the likely entry point.

If it does not work

Incomplete backup recovery

Your host restores the backup but some files are missing or corrupted. Ask them to restore to an older backup date instead. If all backups are compromised, ask whether they keep offsite copies. If not, you may need to rebuild from scratch. This is rare but possible. Your host should help you identify what is missing.

Site still showing malware after restore

Your browser cache or your host's cache is serving old files. Clear your browser cache completely (not just cookies). Ask your host to flush their cache. Wait 24 hours for DNS to refresh. If malware still appears, the backup itself was infected. Contact your host immediately and request a scan of the backup files before they restore again.

Customers reporting continued issues

They may be seeing cached versions on their devices. Ask them to clear their browser cache and try again. If the problem persists on multiple devices, your site may not be fully restored. Check your staging URL again. If it works there but not live, your host may not have completed the restore. Contact them for status.

Next steps

Set up automated daily backups through your host or a third-party service like BackWPup or UpdraftPlus. Store at least one backup offsite, away from your hosting account.

Enable two-factor authentication on your hosting account, domain registrar, and CMS admin panel. This makes passwords alone useless to attackers.

Schedule a security audit with your host or a freelance security specialist every six months. They will check for unpatched software and weak configurations.

If you use WordPress, keep automatic updates enabled for the core software. For plugins, update within a week of release.

A breach is disruptive but recoverable. The steps above will get you back online and prevent it happening again. If you get stuck at any point—or if you want someone to handle this for you—we can help. Get in touch and we'll walk you through it.

Powered by WHMCompleteSolution