How to tell if your website has been hacked and what to do next
Most website breaches are not announced by a dramatic defacement or an immediate system failure. Attackers prefer to stay hidden — quietly extracting data, sending spam, or using your server's resources while your site continues to operate normally.
Warning signs your website has been hacked
Your website is sending spam emails. If contacts report receiving unsolicited emails from your domain, or your domain appears on email blacklists, your server may have been compromised.
Google is showing warnings in search results. If visitors see a "This site may be harmful" warning, Google has detected malicious content on your site.
Your site is redirecting visitors. If visitors arriving from search engines are being redirected to other websites, your site has almost certainly been compromised — a common technique called SEO spam.
New admin accounts you did not create. Check your CMS for admin-level accounts you do not recognise. Attackers often create backdoor accounts to maintain access.
Unexpected files on your server. Unfamiliar PHP files, particularly in upload directories, are a strong indicator of compromise — often web shells that allow remote server control.
Your site is slower than usual. A sudden drop in performance can indicate your server's resources are being used for cryptocurrency mining or spam.
Customers reporting suspicious activity. If customers say their accounts were accessed without their knowledge, your customer data may have been extracted.
What to do if your website has been hacked
Take the site offline immediately to stop the attack continuing and prevent further harm to visitors.
Contact your hosting provider — they have incident response procedures and can help identify what happened.
Assess what data was affected to understand your GDPR obligations.
Report to the ICO if personal data was affected. Under UK GDPR you must report within 72 hours of becoming aware.
Change all passwords immediately — every admin, hosting, database, FTP, and email account.
Restore from a clean backup taken before the compromise.
Patch the vulnerability that allowed the compromise — otherwise the site will be compromised again.
Get a security test after recovery. Yrzo AI runs 44 automated checks and delivers a report in under 20 minutes to confirm the vulnerability is fixed and no others exist.
How to prevent it happening again
Keeping software updated, using strong passwords with two-factor authentication, and regular security testing prevent most attacks. Yrzo AI scans your website for the vulnerabilities that lead to compromise for £399.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →