Website May Be Hacked
Higher-risk issue — be cautious and consider professional help sooner.
Strange pages, redirects, warnings, or behavior suggest someone may have tampered with your site. The goal now is to confirm carefully and act deliberately — not fast and destructively.
Common signs of this issue
- Pages you didn't create appear — often spam about pharmaceuticals, gambling, or luxury goods — or your content changed on its own.
- Visitors get redirected to spam, ads, or adult sites (sometimes only from Google results, or only on phones — attackers hide from owners deliberately).
- Google or the browser shows a "Deceptive site ahead" or malware warning on your domain.
- New admin users you didn't create, or your own login suddenly doesn't work.
- Your host emails you about malware, phishing content, or suspicious activity — or suspends the account outright.
- Search results for your site show strange titles, foreign-language spam, or pages you never made.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Work from a device you trust, and don't log into anything from shared or public computers while investigating.
- Search Google for
site:yourdomain.comand scan the results for pages, titles, or languages you never published — indexed spam pages are one of the clearest external signs of compromise. - Visit your site the way victims do: from a Google search result, on a phone, in a private window. Redirect malware often behaves normally for direct visits and owners, and only fires for search traffic.
- Check Google Search Console for security notices (Security & Manual Actions → Security issues) — a read-only check, and Google's scanner sees things you can't.
- Run your domain through a free scanner such as Google Safe Browsing's site status page or a "website malware scanner" — external scans are safe and need no credentials.
- Document everything now: screenshots of what you see, which URLs, where redirects lead, dates and times. Evidence disappears as malware updates itself, and documentation is the first thing a professional needs.
- Establish your last known-good backup date — from your host or backup plugin — without restoring anything yet. Restoring over a live infection, or restoring an already-infected backup, both make cleanup harder.
- Check whether anything mundane explains it instead: an expired domain being parked with ads, an ad network gone rogue, or a broken plugin can mimic hack symptoms. The site:search and Search Console checks help separate the two.
What this usually means
These signs may indicate compromise — most commonly via an outdated plugin or theme, a stolen or weak password, or another infected site on the same hosting account. But look-alikes exist (rogue ad scripts, expired services, misconfigurations), and nobody can certify a hack from the outside alone. Confirming means examining files and logs.
If it is a compromise, understand what you're dealing with: modern site malware hides copies of itself in multiple places and rebuilds what you delete. That's why the amateur instinct — find the weird file, delete it, done — fails. Real cleanup removes all of it, closes the entry point, rotates every credential, and verifies; anything less and it returns in days.
There's also a clock running: while infected, your site may be attacking your own visitors, your host may suspend the account, and Google's "deceptive site" flag — once applied — takes days-to-weeks of clean history to fully lift. Early, proper action is dramatically cheaper than late action.
What not to do
- Don't log in or type passwords from a device you don't trust — and if the site itself may be compromised, assume its login page could be watched.
- Don't delete suspicious files or the database in a panic — you can destroy both the evidence of how they got in and your ability to recover cleanly.
- Don't just restore a backup and call it fixed: if the entry point (vulnerable plugin, stolen password) still exists, reinfection is near-certain — and the backup itself may already contain the malware.
- Don't pay any ransom pop-up or unsolicited 'we noticed your site is hacked' contact — the second group is overwhelmingly scammers who monitor infected sites.
- Don't keep it quiet if the site handles customer data or payments — depending on where you operate, you may have notification obligations, and your payment processor will care.
When to get help
A suspected hack is the clearest case on this whole site for professional help. Proper incident response — finding every backdoor, closing the entry point, rotating credentials, requesting Google review — is specialist work with real consequences for doing it halfway. If your site takes payments or holds customer data, treat it as urgent today, not this weekend. What you can do meanwhile: the documentation above, changing your own passwords from a clean device, and confirming backup dates — all of which make the professional's job faster and cheaper.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
Can you tell for sure if my site is hacked?
Not from the outside alone. External signs (spam pages in Google, redirects, warnings) justify investigation; confirmation comes from examining files and logs. External scanners plus a site:yourdomain.com search get you a strong preliminary answer safely.
Why does my site look fine to me but redirect other people?
By design — malware commonly targets only search-engine visitors, only mobiles, or only first visits, so the owner sees a healthy site while customers get redirected. Test from a Google result on a phone in a private window to see what victims see.
Should I just delete everything and start over?
Not as a first step. You'd lose recoverable content and the evidence of the entry point — and if you rebuild with the same vulnerable plugin or password, you're re-hacked in a week. Clean properly or rebuild deliberately, but decide with information, not panic.
How do hacked sites usually get hacked?
Overwhelmingly: outdated plugins/themes with known vulnerabilities, weak or reused passwords, and cross-contamination from other sites on the same hosting account. That's also the prevention list — update, use strong unique passwords, and isolate sites.
How long does the Google 'deceptive site' warning last after cleanup?
You request a review through Search Console after cleanup; approval typically takes hours to a few days. The warning lifting fully depends on Google re-verifying — one more reason cleanup has to be complete, since a failed review restarts the clock.
Will my customers' data be affected?
It depends what the site stores. A brochure site holds little; a store or membership site may expose names, emails, or payment flows. If customer data may be involved, take it seriously — professional assessment isn't optional at that point.