Website Rescue
Website hacked? A calm first-hour checklist
A hacked website feels personal. It almost never is — most attacks are automated bots exploiting an out-of-date plugin, and most small-business sites are fully recoverable. What matters is doing the right things in the right order in the first hour. Here they are, in plain English, from a family-run Dorset IT firm that’s been calming this exact panic since 1995. Rated 4.9 on Google.
- ● Same-day response
- ● Family-run since 1995
- ● 4.9 on Google
Stay calm
First: it’s recoverable, and it’s not personal
You usually find out one of four ways: your homepage has been defaced; Google shows a red “this site may be hacked” or “deceptive site ahead” warning; customers tell you your site is redirecting somewhere odd; or you spot strange pages under your own domain in search results — pharmacy spam, gambling links, pages you never wrote.
Take a breath. The overwhelming majority of small-business hacks are automated: a bot scanned thousands of sites for a known weakness — typically an out-of-date WordPress plugin, theme or a weak password — and yours happened to match. Nobody sat down and targeted your business, and almost every site in this position can be recovered.
Two things before you touch anything. First, take screenshots of what you can see — the defacement, the warning, the odd search results. You may need them for your host, your insurer or the ICO. Second, don’t start deleting files in a panic; you can destroy the evidence of how they got in, which is the one thing you need to know to stop it happening again.
If you’d rather talk it through with a human first, call us on 01202 775566 — we respond the same day.
// NEED THIS FIXED RIGHT NOW?
Skip the DIY — call 01202 775566 and we can be looking at your screen within minutes. You watch everything we do, and most problems on this page are fixed in one short remote session. (Mon–Fri, 9am–5pm.)
The first hour
The first-hour checklist, in order
Take the site offline or into maintenance mode. Log in to your hosting control panel and switch on maintenance mode, or ask your hosting company to suspend the site temporarily — they deal with this daily and can usually do it in minutes. A plain holding page is far better than serving malware to your customers, and it stops the damage to your Google standing getting worse while you work. (If you’re already looking at an “Account Suspended” page, your host has done this step for you — ring them before anything else, because that page can also mean unpaid hosting and data at risk of deletion.)
Change every password — all of them, in this order. Start with the hosting control panel account, because it controls everything else. Then FTP/SFTP, then every CMS admin user (check the user list for admin accounts you don’t recognise and remove them), then the database password, then any email accounts that live on the same hosting. Do this from a computer you trust, make every password unique, and switch on two-factor authentication wherever it’s offered. If you reused the old password anywhere else — and most people have — change it there too.
Scope the damage before you fix anything. Is it just defacement? Are there injected spam pages (search Google for site:yourdomain.co.uk and look for pages you didn’t write)? Is malware being served to visitors? And the question that matters most legally: what personal data does the site hold or connect to — contact-form submissions, customer accounts, order history, a mailing list? Write down what you find. It drives everything in the next step.
Legal duties
The ICO, your customers, and reporting it properly
If the site holds or processes personal data — even just names and email addresses from a contact form — you need to assess whether this is a reportable data breach. Under UK GDPR, a breach that is likely to pose a risk to people’s rights and freedoms must be reported to the Information Commissioner’s Office within 72 hours of you becoming aware of it. Not every hack qualifies — a defaced brochure site that stores no customer data often doesn’t — but you must make the assessment and keep a record of your reasoning either way. The ICO’s own guidance and self-assessment tool at ico.org.uk walk you through it in plain language.
Tell affected customers honestly and early. If their data may have been exposed, a short, plain email — what happened, what you’ve done, what they should do — protects them and your reputation far better than silence. People forgive a hack; they don’t forgive a cover-up.
You can also report the attack to Action Fraud on 0300 123 2040. And for a proper plan rather than a panic, the NCSC’s Small Business Guide: Response & Recovery is the national authority on handling a cyber incident — it’s free and written for firms exactly your size.
Two honest caveats. If payment-card data may have been accessed, involve a specialist forensics firm — that’s a regulated area and beyond what a general IT firm should handle alone, and we’ll tell you so if it applies. And if the breach raises questions of liability or a dispute, seek proper legal advice — nothing on this page is a legal opinion.
The honest fork
Clean it, or rebuild it clean?
Once the site is offline and the passwords are changed, you face the decision most guides skip: disinfect the existing site, or rebuild it clean. Here’s the honest version of both.
Cleaning means scanning for and removing injected files, reinstalling the CMS core, updating every plugin and theme, and checking the database for planted admin users and spam content. It can absolutely work — and if your site is recent, well-maintained and you have a clean backup from before the infection, it’s usually the right call. The catch: if nobody ever finds the door the attacker used, reinfection is common. Cleaning the same site twice costs more than doing it properly once.
Rebuilding is often the cheaper, calmer option when the site is an ageing WordPress install with abandoned plugins, when it’s been infected before, or when there’s no clean backup to restore from. You keep your content, your domain and your Google standing, and start from a clean, modern foundation — done properly, without losing rankings. We’ve set out exactly how that works on our website rebuild page, so we won’t repeat it here.
We speak from experience: in June 2026 we replaced our own WordPress site with a hand-built static one. There are no plugins and no database to attack — a far smaller attack surface — and in our own Lighthouse measurements mobile performance went from roughly 65 to the high 80s. We’re not saying every business should do the same; we are saying the clean-vs-rebuild question deserves an honest answer, not a default invoice for cleaning.
Aftercare
Hardening, backups, and getting the Google warning removed
Once the site is clean (or rebuilt), a few habits stop the sequel:
- Backups with a tested restore. A backup you’ve never restored is a hope, not a backup. Keep copies going back weeks, keep at least one copy away from the hosting account itself, and test a restore once in a while.
- Update everything, on a schedule. Out-of-date plugins and themes are the number-one way in. Remove any plugin or theme you don’t actually use — deactivated isn’t deleted.
- Tighten the accounts. Two-factor authentication on hosting and CMS logins, unique passwords, and no shared “admin” account that half the office knows.
- Clear the Google warning. In Google Search Console, the Security Issues report shows what Google found; once the site is genuinely clean you request a review from the same screen, and the red warning is normally lifted after Google re-checks. Don’t request the review before the cleanup is finished — failed reviews slow the next one down.
- Check your own front door. Run your site through our free website checker — it flags basics like missing HTTPS — and there are SSL and domain checks in our free tools suite. All free, no sign-up.
If you’d rather someone kept an eye on updates, backups and monitoring for you as a matter of routine, that’s part of what our business IT support plans cover — and every piece of work we do comes with a written Service Report, so you can see exactly what was done and why.
Local help
Hacked and want a human? Bournemouth, Poole & Dorset
If you’d rather hand this to someone, here’s how we work. Call 01202 775566 Monday to Friday, 9–5, and we respond the same day — when your site is serving malware to customers, waiting until next Tuesday isn’t an option. You can also text us on 07520 615332. Almost all cleanup and recovery work is done remotely, so it starts fast; we visit on site when a job genuinely needs it.
We’re a family-run IT firm, going since 1995, with a 4.9 rating on Google. Because we look after websites, hosting, email and day-to-day IT under one roof, a hacked site doesn’t get bounced between three suppliers each blaming the other — one firm owns the problem end to end, including the awkward conversation with your hosting company.
And the honest bit: we’re an experienced IT support firm, not a certified security consultancy or a forensics lab. For the everyday reality of small-business hacks — compromised WordPress sites, injected spam, defacements, hijacked email — that’s exactly what you need. For serious breaches involving payment-card data or likely legal action, you need specialists, and we’ll say so on the first call rather than sell you something we shouldn’t. Every job is quoted up front — no hourly meter quietly running while you panic.
// RELATED
- Web designer disappeared? How to get your website back — when the person with the keys has vanished
- Is your web designer holding your website hostage? — when they’re present but withholding access
- Slow WordPress site: fix it or rebuild it? — the other reason old sites reach breaking point
- Website rebuild without losing rankings — the clean-foundation exit path
- Free website checker — see what state your site is in right now
FAMILY-RUN SINCE 1995 · ★ 4.9 ON GOOGLE · 200+ COMPUTERS UNDER OUR CARE · NO FIX, NO FEE · SAME-DAY REMOTE SUPPORT
// GOOD QUESTIONS
Frequently asked
Google says “this site may be hacked” — what do I do?
That warning means Google has detected spam pages, malware or suspicious redirects on your site. Follow the first-hour checklist above: take the site into maintenance mode, change every password, then get the site properly cleaned. Once it’s genuinely clean, use the Security Issues report in Google Search Console to request a review — the warning is normally removed after Google re-checks the site.
Do I have to report a hacked website to the ICO?
Only if personal data is involved and the breach is likely to pose a risk to people’s rights and freedoms. If it is, UK GDPR requires you to report it to the ICO within 72 hours of becoming aware. A defaced brochure site holding no customer data often isn’t reportable — but you must assess it and record your reasoning either way. The ICO’s self-assessment tool at ico.org.uk walks you through the decision, and for disputes or liability questions you should seek legal advice.
How did hackers get into my small-business website?
Almost always automatically, not personally. The usual doors are an out-of-date WordPress plugin or theme, a weak or reused password, or an old admin account nobody remembered. Bots scan thousands of sites a day for these known weaknesses. That’s actually good news: close those doors and you’ve dealt with the realistic threat.
My website shows “Account Suspended” — is that a hack?
Not always. Hosting companies suspend accounts both for malware and for unpaid bills — and in either case your files can be at risk of deletion if it’s left unresolved. Ring the hosting company first to find out which it is, then act accordingly. If you can’t reach whoever manages the hosting, our guide for when a web designer has disappeared covers how to take back control.
Should I pay if the hacker demands money?
UK law enforcement and the NCSC do not encourage paying — payment funds crime and there’s no guarantee you’ll get anything back, or that they won’t return. For a website (as opposed to ransomed office computers) it’s rarely even relevant: the site can almost always be restored from backups or rebuilt without paying anyone. Report demands to Action Fraud on 0300 123 2040.
Can a hacked WordPress site be fixed remotely?
Usually, yes. Cleanup, password rotation, malware removal and hardening are all done through hosting and CMS access, so most of our recovery work happens remotely the same day you call — no waiting for a visit. We come out on site when a job genuinely needs it.
How much does hacked website cleanup cost?
We quote each job individually after a quick look, because a defaced homepage and a deeply infected site with a compromised database are very different jobs — and sometimes the honest answer is that a clean rebuild costs less than repeated disinfection. You’ll get a plain-English quote before any work starts, and a written Service Report after it.
Is it better to clean a hacked site or rebuild it?
If the site is recent, well-maintained and you have a clean backup from before the infection, cleaning is usually right. If it’s an ageing install with abandoned plugins, has been infected before, or has no trustworthy backup, rebuilding on a clean foundation is often cheaper over two years and ends the reinfection cycle. Our website rebuild page explains how that’s done without losing your Google rankings.
Do I need to tell my customers my website was hacked?
If their personal data may have been exposed — email addresses, accounts, order details — yes, and quickly. A short honest note explaining what happened, what you’ve done and what they should do (usually: change their password if they had one) protects them and preserves trust. If no customer data was involved, a notification usually isn’t required, but honesty if anyone asks always is.
How do I stop my website being hacked again?
Four habits cover most of it: keep the CMS, plugins and themes updated and delete the ones you don’t use; use unique passwords with two-factor authentication on hosting and admin logins; keep backups you’ve actually test-restored, with a copy held away from the hosting account; and check the site occasionally with a scanner or our free website checker. A well-built lightweight site also simply has less to attack — which is one reason we rebuilt our own without plugins or a database.
Hacked and want it handled today?
Call 01202 775566 (Mon–Fri, 9–5) and a real local engineer looks at it the same day — honest advice on whether to clean or rebuild, no jargon, no scare tactics. Every job is quoted before we start.
01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM