Skip to main content

Threats and response

Website Hacking Guide

If a website may be compromised, act calmly and record what happens. Containment, evidence and a clean recovery matter more than quickly hiding the visible symptom.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

A hacked website can redirect visitors, expose data, send spam, damage search visibility or give an attacker a route into connected services. The first visible change may not show the full extent or original entry point.

Deleting one suspicious file can destroy evidence while leaving another backdoor in place. A structured response helps the business make safer decisions about isolation, notification and recovery.

Know the exposure

Common risks

01

Persistent access

Attackers may add accounts, scheduled tasks, modified plugins or hidden files that survive a superficial clean-up.

02

Connected account compromise

Reused credentials or stolen sessions can extend the incident to hosting, email, DNS, analytics or payment services.

03

Unclean restoration

A recent backup may already contain the weakness or malicious change, so its date alone does not make it trustworthy.

Investigate, do not ignore

Warning signs

  • Unexpected redirects, pop-ups, downloads or browser security warnings
  • Unknown administrator accounts, files, database users or scheduled jobs
  • Spam pages in search results or unexplained changes to titles and links
  • A sudden increase in outbound email, resource use, errors or security alerts
  • DNS, hosting or account-recovery details changed without authorisation

Reduce likelihood and impact

Practical steps

  1. 01

    Start an incident record

    Note times, symptoms, alerts, recent changes and who has access. Preserve relevant logs and snapshots before they rotate or are overwritten.

  2. 02

    Contain carefully

    Work with the host or incident specialist to isolate the affected service, restrict access and protect visitors without destroying useful evidence.

  3. 03

    Secure connected accounts

    From a trusted device, reset relevant credentials, revoke sessions and tokens, enable MFA and check recovery details. Do not reuse suspected passwords.

  4. 04

    Find the scope and entry point

    Review application, hosting, account, file and database evidence. Check whether data or connected systems may also be affected.

  5. 05

    Recover from known-clean sources

    Rebuild or restore as appropriate, patch the cause, verify the result, rotate secrets and increase monitoring before normal operation resumes.

Defined website support

How AHANIX can help

AHANIX can help assess website symptoms, coordinate ordinary web recovery tasks and rebuild website components when that is appropriate.

  • Review public symptoms and gather available website, hosting and change context
  • Liaise with the hosting provider on access, clean restoration and website configuration
  • Repair or rebuild agreed website components after the incident scope is understood

Clear limits

What this cannot guarantee

  • AHANIX cannot guarantee removal of every persistence mechanism or certify that an affected environment is clean.
  • Active attacks, sensitive-data exposure, extortion, criminal activity or complex forensics should be handled by qualified incident-response, legal and regulatory specialists.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Website hacking questions

Should I immediately restore the latest backup?

Not automatically. Preserve evidence first where practical and establish whether the backup predates the compromise and whether the original weakness has been fixed. Otherwise the incident may return.

Can changing every password fix a hacked website?

Credential rotation is important, but it does not remove malicious files, vulnerable code, stolen tokens or altered DNS. The wider scope and entry point still need investigation.

Do I need to tell customers?

That depends on what happened, the data and services involved, contractual duties and applicable law. Preserve facts and obtain appropriate legal or data-protection advice promptly.

A scoped next step

Need help with a suspected website incident?

Share the symptoms and current provider details. AHANIX will explain which website work is in scope and when specialist incident response is the safer route.

Contact AHANIX

Continue in the Security Centre