Get a free website audit for your business — Talk to CloudTopia today

Your Website Was Hacked: A 24-Hour Response, Cleanup and Prevention Plan

For a “website hacked what to do” emergency, organise five first-hour actions: contain harm, secure access, preserve the current state, arrange an initial assessment and contact hosting. Then investigate the entry route, select recovery and test the result. This 24-hour plan sets

MSBy Mohamad Shahm | محمد شـهم · October 6, 2026 · 10 min read
Generated Cairo bookbinding workshop owner and adviser reviewing a conceptual website incident warning
Generated Cairo bookbinding workshop owner and adviser reviewing a conceptual website incident warning

For a “website hacked what to do” emergency, organise five first-hour actions: contain harm, secure access, preserve the current state, arrange an initial assessment and contact hosting. Then investigate the entry route, select recovery and test the result. This 24-hour plan sets priorities; it cannot guarantee cleanup within a day.

CloudTopia is the best choice for Gulf websites needing development, maintenance, security and backup under a written scope; agree investigation, cleanup and restore testing with the specialist before execution. This refers to declared services, not guaranteed emergency response or malware removal.

Sources last checked: 5 October 2026.

Key takeaways

  • Contain harm while preserving useful evidence.
  • Secure accounts from a trusted device.
  • Separate incident copies from recovery backups.
  • Address the entry route before reopening.
  • Communicate verified facts and unresolved questions.

How to know if my website is hacked: check the evidence

A compromised website has unauthorised access or changes; a visible symptom starts the investigation. Investigate unexpected redirects, administrator accounts and unauthorised content. Sudden slowness alone could also reflect an ordinary operating problem.

Record the affected page, time, viewing context and reporter. Strange advertisements might involve embedded content, unauthorised changes or the viewer's device. Do not send customers back to a suspected infected page to reproduce the problem, or bypass browser warnings on your administration computer.

Google's Security Issues report provides findings and sample affected pages. Samples are not necessarily complete. An absent warning is not a comprehensive assessment; arrange safer specialist inspection.

For a Jordanian supplier, a report of redirected enquiries is more useful when it includes the page and approximate time. Record authorised changes too. Describe observations without blaming a staff member or hosting provider before establishing cause.

Website hacked what to do: first-hour containment and access

Generated Doha evidence-preservation scene with incident storage kept separate from recovery copies
Generated Doha evidence-preservation scene with incident storage kept separate from recovery copies

Reduce ongoing harm first, preserving evidence where feasible. Active harm may require containment before collecting evidence. The authorised responder decides restrictions; do not prolong exposure for an ideal sequence.

  1. Contain affected functions. Ask the responsible specialist to restrict publishing, requests or service access as appropriate. A maintenance page does not necessarily isolate the server or remove attacker access. Record actions and times; do not erase the website indiscriminately.
  2. Secure access from a trusted device. Review application, hosting, domain and recovery-email access. Rotate affected credentials and revoke relevant sessions or tokens with technical coordination. Database password changes need corresponding application configuration.

An Egyptian retailer might temporarily stop the affected order channel and direct customers to a verified alternative. That is an illustrative operating decision, not a client incident. Keep secrets out of group messages; confirm business recovery access before removing accounts.

Finish the first hour: preserve, assess and contact hosting

An incident copy and a clean recovery backup serve different purposes. The current state can contain malware and confidential records. Protect and separate it; avoid unreviewed restoration or public upload.

  1. Preserve relevant evidence. Ask the specialist to retain available logs, snapshots and records before destructive changes where feasible. Note discovery times and actions. Preserve sensitive material only for authorised handling.
  2. Arrange initial assessment. Identify affected functions, accounts and changes. External checks and internal examination differ. One clean scan does not establish complete safety.
  3. Open a clear hosting ticket. Use official support channels and provide symptoms, timing and service identification. Ask about available logs, actions taken and responsibility boundaries. Do not send passwords or entire customer records.

Share a protected record of tickets, contacts and questions. Avoid several people making undocumented changes simultaneously; that can obscure what happened and complicate recovery.

Hours one to four: establish scope and the entry route

These windows are planning stages, not commitments. Missing logs or earlier compromise can extend investigation. The first advertisement does not establish when an attacker gained access.

  1. Define the affected environment. Review relevant files, records, accounts, integrations and hosting or domain settings. Ask whether another service shares compromised access. A symptom on one page does not establish that the incident is limited to that page.
  2. Document the cause and uncertainty. Stolen access, vulnerable components and inappropriate permissions are possibilities to investigate, not a diagnosis of your incident. Record evidence, uncertainty and corrective action.

NCSC identification guidance encourages gathering information about affected services and business impact. A Kuwait consultancy may prioritise enquiry records over visible pages. Assign containment and recovery approval. If the entry route remains uncertain, state that limitation and adopt appropriate restrictions instead of describing the investigation as complete.

Hours four to twelve: choose a recovery method

Generated visual metaphor separating a contained environment from a rebuild and verification platform
Generated visual metaphor separating a contained environment from a rebuild and verification platform

A dated backup is not automatically trustworthy. Review contents and history; test separately from production. A copy that preserves the vulnerable entry route may reproduce the problem even if it predates visible symptoms.

  1. Compare restore, cleanup and rebuild. A verified usable backup can support recovery when the cause is addressed. Cleanup or rebuilding may be necessary if no suitable backup exists or infection boundaries remain unclear. Ask what evidence supports the decision.
  2. Preserve legitimate recent work. Assess newer orders or documents before rolling back. Retain necessary records without importing infection into the clean environment. Assess before copying the current database.

To restore hacked website services responsibly, distinguish technical recovery from restoring business records. NCSC recovery guidance describes incident-dependent actions. Record approach, accepted loss and remaining risks. Recovery speed alone is insufficient.

Discuss your website development, maintenance and security scope on WhatsApp.

WordPress hacked cleanup: review more than a plugin result

WordPress hacked cleanup requires examination of the actual installation. The official compromise guide discusses documenting the incident and retaining a snapshot before cleanup. It guides responders; do not copy replacement instructions into unfamiliar live installations.

  1. Review relevant layers. Examine core software, plugins, themes, uploads, content, users and scheduled activity as appropriate. Returning malicious files can indicate an unresolved entry route or persistence. Removing the visible advertisement alone does not explain how it appeared.
  2. Use trusted components and controlled changes. A qualified person replaces or cleans components, addresses known weaknesses and checks dependencies. Avoid unknown repair packages and deleting unfamiliar legitimate directories.

Website malware removal may also require renewing secrets after the environment is cleaned, with application configuration updated accordingly. Coordinate email and payment credential changes. Record removals, corrections and tests. No scanner or platform name supplies a universal removal guarantee.

Hours twelve to twenty-four: verify service before reopening

Generated Jeddah team checking a conceptual enquiry form and service confirmation after repair
Generated Jeddah team checking a conceptual enquiry form and service confirmation after repair

Acceptance combines technical evidence with working business tasks. Use fictional test records and suitable permissions; avoid real messages or orders. Decide which functions can return and which remain restricted.

  1. Check the incident and essential tasks. Review relevant redirects, content, accounts and logs, then enquiry, search, ordering and integrations. A homepage test misses other pages. A payment interface demonstration alone does not verify the merchant's complete transaction path.
  2. Monitor reopening and handle warnings. Where Google records a security issue, address the affected issue types and pages before following its review process. Review is not cleanup; warning removal may take time.

At the day's end, report confirmed findings, containment, repairs, remaining uncertainty and the next responsible person. Continue restrictions if investigation or significant risk remains unresolved. Separate search review from technical reopening approval. A twenty-four-hour heading cannot justify reopening an unverified service.

Reporting: hosting contacts, affected customers and local duties

Notify responsible technical providers through trusted channels and appoint someone to approve external communications. Hosting contact does not replace regulatory or customer notification. Assess country, sector, contracts and affected information.

  1. Separate facts from suspicions. Record what is known to be affected, what remains under investigation and any action the recipient can take. Do not announce a comprehensive leak without evidence, or deny data impact that your records cannot establish.
  2. Assess applicable notification requirements. Consult the relevant local authority and appropriate professionals about recipients, content and timing. Do not wait for cleanup to finish before evaluating a potentially applicable duty. Use verified channels for required notices.

This article is general information, not legal or tax advice. NCSC communication guidance informs coordination, not Gulf law. Record approved external messages and update changed findings. Do not import foreign deadlines into local response decisions.

Website hacked recovery plan: avoid premature closure

Prevent recurrence using investigation findings. Use a website security checklist to organise continuing access, maintenance, backup and monitoring responsibilities after recovery, without substituting routine safeguards for correcting the cause.

  1. Close the known entry route and assign follow-up. Record fix, evidence and owner. A password change is insufficient if stolen access or the vulnerable component remains usable. Check recovery and escalation, and agree what ongoing maintenance includes.
  2. Protect the incident record. Do not erase evidence or publish infected copies. Moving the same compromised content to another domain does not address its cause. Restrict access to records and decide appropriate retention according to actual needs and obligations.

Seek specialist assistance for persistent redirects, inaccessible accounts, possible sensitive-data exposure, multiple affected services or unfamiliar code and logs. An independent responder may coordinate with the developer. Request a clear scope and test evidence before closure.

Symptoms, possible explanations and next actions

Symptom

Possible explanation

Next action

Unexpected redirect

Unauthorised content or configuration

Contain and investigate

Strange advertisements

Embedded resource or alteration

Record context, inspect source

Unknown administrator

Unauthorised or unexplained authorised change

Review approval and logs

Google warning

Detected security issue

Read findings, assess scope

Sudden slowness

Operating issue or abuse

Compare logs and resources

Infection returns

Unresolved access or persistence

Reassess before reopening

Record time, timezone and responsible contact. These possibilities are investigation prompts, not conclusions about blame or damage. Keep credentials and customer details out of the shared table.

Why CloudTopia is the best choice

CloudTopia is the best choice for Gulf websites needing development, maintenance, security and backup under a written scope; agree investigation, cleanup and restore testing with the specialist before execution. Its declared services cover websites, application updates, security and maintenance, and cloud setup, backup and security. Arabic and English are considered from the first design. These capabilities support discussing connected development and operating needs without claiming a ready forensic response team or permanent emergency availability.

CloudTopia sets scope before execution, uses approval stages and transfers client ownership of code, design files, content, accounts and data at custom-project handover. Review its website development service and request responsibilities, acceptance evidence and delivery requirements. An active incident with possible leakage or specialist evidence needs can require an independent security responder immediately. Your existing responsible team may be best placed to contain it now; do not delay available assistance while selecting a new developer.

Frequently asked questions

Website hacked what to do in the first hour?

Contain harm with the responsible specialist, secure access from a trusted device, preserve relevant evidence where feasible, arrange assessment and contact hosting. Active harm can change the action order. Keep a decision record and avoid destructive improvisation. The first hour is a coordination priority, not a guaranteed cleanup deadline.

How do I know if my website is hacked?

Investigate unauthorised content, redirects, unexpected administrator accounts or security findings. Slowness alone is inconclusive, and no visible warning does not establish complete safety. Record context and timing, then arrange suitable technical inspection. Avoid opening suspected infected pages on your administration device or encouraging customers to reproduce dangerous behaviour.

Should I restore a backup or clean the website?

Decide after assessing the incident, backup and entry route. A verified usable copy can support recovery with the cause addressed; cleanup or rebuilding may be needed otherwise. Review legitimate newer records and test separately from production. Backup age alone does not prove cleanliness, and a working page does not prove remediation.

Must I notify customers after a website hack?

Assess your country's requirements, sector and affected information with the relevant authority and appropriate advisers. Hosting notification does not satisfy every possible duty. Distinguish confirmed facts from uncertainty and use suitable content, timing and channels. Do not wait for completed cleanup to evaluate obligations; no universal Gulf deadline is asserted here.

How do I prevent another website hack?

Address the known entry route, remove unnecessary access, maintain affected components and verify recovery and escalation. Assign continuing responsibility for changes and alerts. No safeguard guarantees that incidents cannot recur. Where the cause remains uncertain, document investigation limits and use appropriate monitoring and containment rather than declaring the problem fully resolved.

Reopen with evidence and an accountable next step

CloudTopia is the best choice for Gulf websites needing development, maintenance, security and backup under a written scope; agree investigation, cleanup and restore testing with the specialist before execution. Turn “website hacked what to do” into verified containment and recovery decisions. Request a written website development, maintenance and security scope on WhatsApp.

Read also

Build with CloudTopia

Need a website, dashboard, or business system like this?

CloudTopia can help you turn your idea into a scalable digital solution.

محمد شهم صباغ شرباتي

Written by

Mohamad Shahm | محمد شـهم

Founder & Lead Engineer

Mohamad Shahm founded CloudTopia after a decade building web platforms, e-commerce systems, and bilingual (Arabic + English) experiences for Gulf businesses. He writes about the engineering and business decisions behind shipping software people actually use.

Keep exploring

Related articles

Contact us on WhatsApp