Running an online business has its ups and downs. But nothing is more worrying than discovering your website has been hacked and blacklisted. Don’t panic — here’s what to do.
Step 1: Acknowledge the Problem
A compromised system means lost revenue, lost authority and trust, and hours of recovery work. Don’t ignore it — the longer you wait, the more damage.
Step 2: Assess the Damage
Determine the type of hack:
- SQL Injection: Malicious SQL code injected to extract data or take control
- Cross-Site Scripting (XSS): Malicious code executed by unsuspecting visitors
- DDoS Attacks: Overwhelm the site with traffic, shutting it down
- Malware: Software designed to damage, disrupt, or steal information
Step 3: Take Your Website Offline
Options:
- Disable your website from your hosting control panel
- Take your server offline (physically shut down)
- Use a firewall to block traffic
- Create a temporary HTML landing page with a maintenance message
Step 4: Remove the Malware
Identify the hack type and remove the malware. Use security scanning tools like sitecheck.sucuri.net.
Step 5: Change All Passwords
Change all login credentials — website, hosting, and any third-party services. Use strong, complex passwords.
Step 6: Install Updates and Patches
Update all software, plugins, and components. Install all security patches.
Step 7: Request a Review
Contact blacklist authorities (McAfee, Google Safe Browsing via Google Search Console) and request a review.
Step 8: Monitor Your Website
Watch for any further signs of malicious activity. Consider a security plugin for ongoing monitoring.
Step 9: Implement Preventative Measures
Strong passwords, regular updates, firewalls, antivirus software — prevention is key.
Step 10: Inform Your Users
Be transparent about what happened and what steps you’ve taken. Honesty rebuilds trust.
Prevention Is Better Than Cure
One way to ensure your website stays secure is with a professional support and maintenance service. We update your site, monitor for suspicious activity, and back everything up. If your site does get hacked, cleanup and delisting is included at no extra cost.
Don’t wait until it’s too late — contact us to learn about our support and maintenance service.