Business Security

Website Hacked? Recovery Sequence for Small Business Sites

By Aqui Tem Achadinhos Editorial · Updated September 20, 2026
Website Hacked? Recovery Sequence for Small Business Sites

A hacked website costs money in three separate ways — lost visitors, lost search rankings, and the cost of repair. The recovery order matters, because the wrong first step can destroy evidence you need.

First 15 minutes: contain, do not clean yet

  1. Do not delete anything yet. Deleting compromised files can remove the evidence needed to find how the attacker got in — and the same hole stays open.
  2. Change your hosting and admin passwords from a clean device. Assume every credential on the site is compromised.
  3. Enable or verify two-factor authentication on hosting, CMS admin and domain registrar. The registrar is the one people forget — and losing the domain is the worst-case outcome.
  4. Take a full backup of the current infected state, for forensic reference, before you change anything.
  5. Check the domain's DNS records for anything you did not add.

How the site was probably compromised

VectorFrequencyHow to check
Outdated plugin, theme or CMS versionVery commonVersion numbers vs. the vendor's latest release
Stolen admin credentialsVery commonLogin logs, unfamiliar IPs or users
Nulled / pirated themes and pluginsCommonCompare files against the official release
Compromised hosting accountLess commonNeighbouring sites on the same server affected too
Cross-site scripting in a formLess commonInjected code in user-submitted content

Step 2: check what the search engines already know

Before you fix anything, document the current state — including any warning page Google shows. That warning appears when Google detects malware or phishing, and it is your most urgent business problem because it blocks all search traffic, not just a portion.

SignalWhere to look
"This site may be hacked" warningGoogle Search Console → Security Issues
Manual actionSearch Console → Manual Actions
Indexed spam pagesSearch site:yourdomain.com and look for unexpected URLs
Unfamiliar content in search resultsGoogle's cached version of your pages

Step 3: clean correctly

Cleaning means more than deleting the suspicious file, because the attacker almost always leaves more than one of them:

⚠️ The lesson of every reinfection

If a site is reinfected within days, the cleanup missed the entry point, not the malware. Removing payloads without patching the vulnerability is the most common cause of repeat compromise — and the second infection always costs more than the first.

Step 4: request a review

Once the site is genuinely clean, submit a review request in Search Console. Be specific about what was infected, what you removed, and what you changed to prevent recurrence. Vague submissions get rejected, and each rejection costs days of lost traffic.

Step 5: prevent the next one

See Sucuri website security →

Check firewall and malware removal plans · Affiliate link — we may earn a commission at no extra cost to you.