My website has been hacked. What do I do?
The signs, the first hour, who to tell, the clean up options, and why it is usually old WordPress.
See the templatesThe short answer: take it offline or put up a holding page, change every password, and decide between cleaning it and rebuilding it. For a small business site a rebuild from a clean template is often quicker and safer than a clean up. If any customer data was on the site, there is a reporting duty.
Signs
- Google shows "This site may be hacked" or the browser blocks it
- Pages redirect to gambling or pharmacy sites
- Strange new pages or links you did not add
- Your host emails you about malware
- Customers say they got spam from your address
The first hour
- Put up a holding page or take the site down. Ask your host how
- Change the passwords: hosting, the site login, the domain registrar, your email
- Turn on two factor login wherever it is offered
- Check your email account is not forwarding to somewhere it should not
Who to tell
If the site held customer data (a shop, a booking system, a member area) and it may have been taken, UK GDPR gives you 72 hours to report it to the ICO if people are at risk. A plain brochure site with a contact form that sends to your email usually holds no data, which is one reason we build them that way.
Clean or rebuild
Cleaning a WordPress site means someone going through every file and the database. It can be done, and it can be done badly. Rebuilding a small site from a clean template with the words and photos you already have is often a day, and the result has nothing left to be hacked through.
Why it was probably WordPress
Most small sites that get hacked are WordPress installs with plugins nobody has updated. A plain static site has no plugins, no database and no login on the public page, which is why ours are built that way.
Need a hand with this? Ring us on 020 3627 0767 or send a message. We will tell you straight whether it is a ten minute fix or a bigger job.