How to tell if your website has been hacked

A laptop showing an alert that a website has been hacked. A “Emergency Aid” notebook is also on the desk.

Dec 27, 2025

by Irene Koukia

Table of contents

You visit your website and something feels off. Maybe it's loading strangely, or you've received a worried message from a customer. Or perhaps Google has flagged your site with a security warning.

Website hacks are more common than most small business owners realize. Hackers target small business websites because they often have weaker security and less monitoring than larger sites. The good news is that catching a hack early makes recovery much easier and less expensive.

Here's how to tell if your website has been compromised, what to look for, and what to do about it.

Obvious signs your website has been hacked

Some hacks are immediately obvious. If you see any of these signs, your site has almost certainly been compromised.

Your website displays content you didn't create

You visit your site and find pages, posts, or content you never created. This might include pharmaceutical spam, gambling links, adult content, or links to suspicious websites. Hackers often add this content to exploit your site's search engine rankings.

Visitors see security warnings

When people try to visit your site, their browser displays warnings like “This site may be hacked” or “Deceptive site ahead”. Google displays these warnings when it detects malware or suspicious activity on your website.

You can't log into your website

If your admin username and password suddenly don't work, and you haven't changed them, someone may have locked you out of your own site. This is a serious sign that hackers have taken control.

Your website looks completely different

Your homepage has been replaced with a hacker's message, a different website entirely, or a blank page. This type of defacement is less common now but still happens.

Your hosting provider has suspended your account

You receive an email saying your hosting account has been suspended due to malicious activity or excessive resource usage. Hosting companies monitor for hacked sites and will suspend accounts that pose security risks.

Subtle signs that are easy to miss

Many hacks are designed to go unnoticed for as long as possible. These subtle signs require closer inspection but are just as serious.

Your website is suddenly much slower

If your site has become noticeably slower without any changes on your end, it could be running malicious scripts or being used to attack other sites. Hackers often use compromised websites as part of larger networks.

Strange new user accounts appear

Check your list of user accounts. If you see usernames you don't recognize, especially with administrator privileges, your site has likely been compromised. Hackers create backdoor accounts to maintain access even if you change your password.

Unexpected pop-ups or redirects

Visitors report seeing pop-ups you didn't create, or clicking links takes them to completely different websites. You might not see these yourself if the hack targets only certain visitors or specific browsers.

Your search results look wrong

When you search for your business in Google, the description or page titles show spam content, pharmaceutical terms, or adult content, even though your actual website looks normal. This is called SEO spam, where hackers hide malicious content that only search engines see.

Unknown files in your website directories

If you check your website files via FTP or your hosting control panel, you find files or folders you didn't create. These often have random names or are hidden in obscure directories.

Your website is sending spam emails

You or your customers receive spam emails that appear to come from your website or domain. Your contact forms might be hijacked to send spam, or hackers might be using your server to send bulk emails.

Analytics show strange traffic patterns

Your Google Analytics shows sudden spikes in traffic from unusual countries, or you're getting traffic to pages that don't exist on your site. This often indicates your site is being used for malicious redirects.

Unexpected changes to your files

Your website files show recent modification dates even though you haven't made any changes. Core WordPress files, plugins, or theme files that have been recently modified without your knowledge are red flags.

How to check if your website has been hacked

If you suspect something is wrong but aren't sure, here are practical steps to investigate.

Use Google's tools

Search for “site:yourwebsite.com” in Google and look through the results. Do you see pages or content you didn't create? Check Google Search Console for security issues. Google will notify you here if it has detected malware or suspicious activity. Use Google's Safe Browsing checker to see if your site is flagged.

Scan your website with security tools

Use a security plugin like Wordfence or Sucuri if you're on WordPress. These can scan for malware, suspicious files, and vulnerabilities. Online scanners like Sucuri SiteCheck or VirusTotal can check your site from the outside. Check your hosting control panel. Many hosts include security scanners in cPanel or their custom dashboards.

Review your user accounts

Log into your website admin area and check all user accounts. Delete any accounts you don't recognize. Look for accounts with administrator privileges that shouldn't have them. Check when each account was last active.

Check your website files

Connect to your site via FTP or File Manager in your hosting control panel. Look for files or folders you don't recognize, especially in your uploads directory or root folder. Check modification dates on core files. If they've been recently changed and you didn't update anything, investigate further. Look for suspicious file names with random characters or hidden files starting with a dot.

Review recent file changes

Most security plugins and hosting providers keep logs of file changes. Review these for unexpected modifications. Pay special attention to changes to core files, .htaccess files, or configuration files.

Check your website's source code

Visit your website and view the page source (right-click and select “View Page Source”). Look for suspicious scripts, especially near the top or bottom of the code. Search for unfamiliar links or redirects. Be aware that some hacks are sophisticated enough to hide from view source, showing different code to different visitors.

Monitor your hosting resources

Log into your hosting control panel and check resource usage. Sudden spikes in bandwidth, CPU usage, or disk space can indicate malicious activity. Review server logs if you have access to them, looking for unusual patterns or requests.

What different types of hacks look like

Understanding common hack types helps you identify what's happened to your site.

Malware injection

Malicious code is added to your site's files or database. This might redirect visitors to other sites, display unwanted ads, or steal information. Often invisible to you but detected by browsers and security software.

SEO spam

Hackers add hidden links and content to boost rankings for spam websites. You might not see it on your site, but it appears in search results or in your page source code. Common for pharmaceutical spam, gambling sites, or adult content.

Backdoor access

Hidden files or code that let hackers return to your site even after you've cleaned it. These are often disguised as legitimate files with names similar to your theme or plugin files.

Phishing pages

Fake login pages added to your site that steal credentials for banks, PayPal, or other services. Your site might be hosting these without your knowledge, damaging your reputation and potentially making you legally liable.

Defacement

Your homepage is replaced with the hacker's message or imagery. Less common now but still happens, usually to make a statement rather than for financial gain.

Brute force attack

Repeated attempts to guess your admin password. You might see this in your security logs before a successful breach. Not a hack yet, but a sign someone is trying.

What to do if your website is hacked

If you've confirmed your site is compromised, act quickly to minimize damage.

Don't panic, but do act quickly

Take a breath. Most hacks are fixable, but time matters. The longer a hack goes unaddressed, the more damage it can cause and the harder it becomes to clean.

Change all passwords immediately

Change your WordPress admin password, hosting control panel password, FTP/SFTP passwords, and database password. Use strong, unique passwords for each. If you use the same password elsewhere, change those too.

Take your site offline temporarily

If the hack is severe, consider putting up a maintenance page while you clean the site. This protects visitors from malware and prevents further damage to your reputation.

Scan and clean your site

Use security plugins to scan and attempt to remove malware. Manually review and clean infected files if you have the technical knowledge. Restore from a clean backup if you have one from before the hack. Consider hiring a professional if the hack is complex or you're not confident cleaning it yourself.

Check for backdoors

After cleaning, scan again specifically for backdoor files that would let hackers return. Review all user accounts again and delete any suspicious ones. Check for scheduled tasks or cron jobs you didn't create.

Update everything

Update WordPress core, all plugins, and your theme to the latest versions. Delete any plugins or themes you're not using. Outdated software is the most common entry point for hacks.

Review your security

Install a reputable security plugin if you don't have one. Enable two-factor authentication for admin accounts. Limit login attempts to prevent brute force attacks. Change your database prefix if you're still using the default “wp_”. Ensure your hosting has adequate security measures in place.

Submit your site for review

If Google flagged your site, request a review through Google Search Console after cleaning. This removes security warnings. Check if your site has been blacklisted on other services and request removal.

Monitor closely

Watch your site carefully for the next few weeks. Run regular security scans. Monitor your analytics for unusual traffic. Check your files periodically for unexpected changes.

How to prevent future hacks

Prevention is always easier and cheaper than recovery.

Keep everything updated

Set WordPress, plugins, and themes to auto-update when possible, or check for updates weekly. Subscribe to security notifications for the plugins you use. Delete plugins and themes you're not actively using.

Use strong passwords and two-factor authentication

Use a password manager to create and store complex, unique passwords. Enable two-factor authentication for all admin accounts. Never use “admin” as a username.

Install a security plugin

Use a reputable security plugin like Wordfence or Sucuri. Configure it to scan regularly and alert you to issues. Enable firewall protection if available.

Backup regularly

Set up automatic daily or weekly backups. Store backups off-site, not just on your web server.

Test your backups periodically to ensure they work.

Choose secure hosting

Use a reputable hosting provider with good security practices. Ensure they offer SSL certificates, regular server updates, and malware scanning. Consider managed WordPress hosting for additional security layers.

Limit user access

Only give people the minimum access level they need. Regularly review and remove user accounts for people no longer involved with your site. Use strong passwords for all accounts, not just admin.

Monitor your website

Set up uptime monitoring to alert you if your site goes down. Review your security logs regularly. Check Google Search Console weekly for security issues.

When to call for professional help

Some situations require expert assistance. Consider hiring a professional if you can't access your site at all, the hack keeps returning after you clean it, your hosting provider has suspended your account, you're seeing legal threats related to the hack, you don't have technical knowledge to clean the site safely, or your site handles sensitive customer data or transactions.

Professional security services can thoroughly clean your site, identify all entry points, implement stronger security measures, and provide ongoing monitoring.

The bottom line

Most website hacks are preventable with basic security practices. Regular updates, strong passwords, security plugins, and reliable backups stop the majority of attacks before they happen.

If your site does get hacked, catching it early makes recovery much easier. Regular monitoring and knowing the warning signs help you respond quickly and minimize damage.

Your website is a valuable business asset. Protecting it should be part of your regular business maintenance, just like locking your doors or backing up your financial records.

Irene Koukia as a speaker at the BP19 conference

I've always been drawn to the moment when something clicks for a business, when the right words, the right positioning, the right presence online suddenly make everything make sense. Lavender Giraffe grew out of years in hospitality, coaching, translation, and marketing strategy, and a conviction that businesses deserve more than cookie-cutter solutions. I work in English, German, and Greek, and the cross-cultural side of my work is something I genuinely love. Athens is home, but my clients are spread across the EU and UK.

Found this useful?

Get more like it every first Monday of the month. The Lavender Giraffe Newsletter covers practical web design, SEO, and digital marketing tips for business owners and marketing managers.