40% OFF Limited-time offer: 40% OFF website & system maintenance See maintenance plans
ZeyWeb
EN ع
SOS Help
Security

How to Recover a Hacked Website Without Making Things Worse

Discovering that your website has been hacked is stressful, but the actions you take in the first hour matter more than the panic. This guide walks through a calm, methodical recovery — the same order of operations our team follows on emergency incidents.

1. Confirm what you are actually seeing

Not every problem is a hack. A blank page, a billing suspension, or an expired certificate can look alarming but have simple causes. Before anything else, note the exact symptoms: unexpected redirects, spam content, a browser malware warning, or admin accounts you do not recognise. Screenshot everything — you will want this record later.

2. Contain before you clean

If customer data or payments may be affected, containment comes first. Put the site into maintenance mode, rotate the passwords you can safely reach, and disable any compromised admin accounts. Avoid the temptation to start deleting files immediately — you can destroy the evidence you need to understand how the attacker got in.

3. Preserve evidence

Take a full backup of the current (compromised) state before you change anything, including files and the database. It feels counterintuitive to back up a hacked site, but that snapshot is how a specialist identifies the entry point so the same door does not get used again.

4. Never share secrets through public channels

During an incident, be careful how you hand over access. Do not paste passwords, API keys, or server credentials into email or a public form. Use temporary accounts where possible, and remove them once the work is done. Every access grant should be logged.

5. Clean, then harden

Removing the malicious code is only half the job. The other half is closing the gap: updating outdated software, tightening file permissions, adding a web application firewall, and reviewing user accounts. A recovery that skips hardening usually leads to a repeat incident within weeks.

6. Restore carefully

Restore from a known-clean backup where you have one, and verify the restored site is genuinely clean before pointing traffic back to it. Then monitor closely for a few days.

If your site is compromised right now and you would rather have an expert drive the recovery, you can open an SOS request and we will connect you with someone quickly. Otherwise, this checklist will keep you moving in the right direction without making the situation worse.

Have a project or a problem to solve?

Send your requirements, hire a specialist, or reach our team when something needs urgent attention.

Send Your Project