Security Basics7 min read21 September 2026

My Website Has Been Hacked: What to Do Right Now (UK Guide)

If your UK business website has been hacked, the next few hours matter. Here is exactly what to do, in what order, to contain the damage and recover quickly.

By Yrzo AI — UK cybersecurity specialists

My website has been hacked: what to do right now

Discovering that your website has been hacked is one of the most stressful experiences a business owner can face. The next few hours matter enormously — both for containing the immediate damage and for satisfying your legal obligations.

Here is exactly what to do, in the right order.

Step 1: Take the site offline immediately

Your first action should be to take the site offline. Contact your hosting provider and ask them to suspend the site, or use your hosting control panel to do it yourself. A compromised site that remains live can continue to spread malware to your visitors, send spam, or participate in attacks on other websites.

Put up a simple maintenance message if possible, or let the hosting provider's default offline page show. The priority is stopping any ongoing harm, not maintaining your online presence.

Step 2: Do not delete anything yet

The instinct when something goes wrong is to clean up immediately. Resist this. The evidence of how the attack happened — access logs, modified files, injected code — is what you need to understand the breach and prevent it from happening again. Your hosting provider may also need this evidence.

Take a snapshot or backup of the current compromised state before cleaning. Your hosting provider can usually help with this.

Step 3: Assess what data may have been affected

This is your most important legal obligation. Under UK GDPR, if personal data has been accessed, altered, or destroyed as a result of the breach, you have obligations that include a potential requirement to notify the ICO within 72 hours.

Ask your developer or hosting provider: what data does this site hold? What databases were accessible? Were customer records, email addresses, payment details, or other personal data stored in a way that an attacker could have accessed?

Step 4: Contact your hosting provider

Your hosting provider has likely seen this before. They can help you understand what happened, provide access logs that show the attack, and assist with the recovery. Tell them you have been hacked and ask for their incident response procedure.

Step 5: Consider your ICO obligations

If the breach involved personal data — and most business websites hold some, even just email addresses from contact forms — you need to assess whether you are required to notify the ICO.

Not all breaches require notification. The threshold is whether the breach is likely to result in a risk to the rights and freedoms of individuals. If customer payment data, health information, or large volumes of personal data were exposed, notification is almost certainly required within 72 hours.

Document your assessment even if you decide not to notify — you need to be able to demonstrate that you made a considered decision.

Step 6: Identify and fix the vulnerability

Once the site is offline and evidence preserved, find out how the attacker got in. Common entry points include outdated plugins with known vulnerabilities, weak admin passwords, insecure file upload functionality, and SQL injection vulnerabilities in forms.

Your developer should be able to identify the entry point from the access logs and modified file timestamps.

Step 7: Clean the site and harden security

Restore from a clean backup if one exists from before the breach. If not, manually remove all malicious code — your developer or a specialist malware removal service can do this.

Before going live again, fix the vulnerability that was exploited and address any other weaknesses identified during the recovery.

Step 8: Scan before relaunching

Before bringing the site back online, run a security scan to confirm the vulnerability has been fixed and no other weaknesses remain. Yrzo AI runs 44 automated security checks in under 20 minutes — including the type of vulnerability that likely caused the breach — and confirms the fix is live before you relaunch. Starting at £399.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →