Business Software

Your Website Has Been Hacked: What to Do First

Published 23 Jul 2026 · 2 min read

Affiliate disclosure: this article contains affiliate links. If you buy through them, UAE Info Portal may earn a commission at no extra cost to you.

You discover it through a browser warning, a customer message, or spam apparently sent from your domain. A compromised website feels catastrophic, and the instinct is to start deleting suspicious files. That instinct usually extends the incident, because attackers leave more than one way back in and manual cleaning almost never finds all of them.

What matters here

  • Restore, do not clean — a known-good backup beats hunting for injected code.
  • Change every password afterwards — hosting, admin, database, and email.
  • Patch before returning to service — restoring onto the same vulnerability invites a repeat.
  • Find the entry point — otherwise you will do this again next month.

The main options

Take the site offline or into maintenance mode first, then restore from a backup predating the compromise — this is where hosting with reliable automated backups earns its cost, and where sites without them face a rebuild. On managed WordPress hosting, restore and then apply every outstanding update before going live again, since unpatched software is the usual entry route. Change credentials across your hosting account, site admin and email. If your site was built with a builder rather than WordPress, this class of compromise is far less likely — there are no plugins to exploit, which is a genuine security advantage.

A caution on repeat compromises

If a site is compromised twice, the entry point was never closed — commonly an outdated plugin, a leaked password, or another neglected site sharing the same hosting account. That last one catches businesses out constantly: the forgotten campaign site nobody has updated in three years is frequently how the maintained site gets reached.

How to choose

Once recovered, do the three things that prevent recurrence: updates on a monthly rhythm with backups verified, unique passwords on every account, and a decision about every other site on the hosting plan — maintained, retired, or moved off. Businesses that do this after their first incident generally do not have a second.

Frequently Asked Questions

Should I try to clean the site myself?

Restoring a known-clean backup is faster and considerably more reliable. Attackers typically leave multiple ways back in, and manual cleaning tends to miss at least one.

What if I have no backup from before the compromise?

Then the site is rebuilt, which is slow and painful — and the strongest argument for hosting with automated backups you can restore yourself. Save what content you can, rebuild clean, and never repeat the situation.

How did they get in?

Usually outdated software, a weak or reused password, or an abandoned site on the same account. Targeted attacks on small businesses are rare; automated scanning for known vulnerabilities is constant.

Do I need to tell customers?

If customer data may have been exposed, take advice on your obligations and communicate promptly and plainly. If the compromise only affected site files, fix it, verify, and improve your practices quietly.

Rate this article

Log in to rate this article.

0.0 · 0 ratings

Comments (0)

No comments yet. Be the first to share your thoughts!

Log in to leave a comment.

Own a business?

List it on UAE Info Portal for free and reach more customers.

Get Started