You find a page redirecting to a pharmacy site, a browser warning in red, an administrator account nobody created, or an email from your host saying the account is sending spam. The instinct is to start deleting things. Resist it for a few minutes. Cleaning up in the wrong order destroys the evidence of how the attacker got in, and a site cleaned without closing that door is usually back in the same state within days.
1. Contain it
Stop the site harming visitors while you work. The quickest way is to password-protect the whole site folder with cPanel's Directory Privacy, which hides everything behind a login without changing a single file. The folder protection guide shows how. Tell your host what you have found; many will scan the account for you and can see things you cannot.
2. Keep a copy of the damaged site
Before changing anything, take a full backup of the account as it is now and download it. It feels backwards to back up a hacked site, but this copy is your evidence, and it holds any content created since your last clean backup. Label it clearly as infected and never restore from it.
3. Change every password
Assume all of them are known. Change, from a computer you trust:
- The cPanel login and any extra FTP accounts. Delete FTP accounts you do not use.
- Every administrator password in the content system.
- The database user's password, then update it in the site's configuration file.
- Email passwords for mailboxes on the account.
- Any API keys stored in the site's settings, such as for payment or mailing services.
In WordPress, also replace the secret keys in wp-config.php with freshly generated ones. That signs out every logged-in session, including the attacker's.
4. Look for what was changed
You are looking for three things: files that were added or altered, accounts that were created, and tasks that were scheduled.
Files. In a terminal, list PHP files changed in the last two weeks:
find ~/public_html -name "*.php" -mtime -14 -printf "%TY-%Tm-%Td %TH:%TM %p\n" | sort
Compare the dates against when you last updated anything. Files that changed on a day you did nothing are suspects, as are PHP files in places that should hold none, such as upload and image folders, and files with random-looking names.
.htaccess. Open every .htaccess file, including in subfolders. Redirect rules you did not write, especially ones that mention search engines or mobile devices, are a common way to send only some visitors to another site so that the owner does not notice.
Users. Check the content system's user list for administrators you do not recognize, and cPanel for FTP accounts, email accounts and forwarders you did not create.
Scheduled jobs. Open Cron Jobs in cPanel. An unfamiliar job is how malicious code reinstalls itself after you delete it.
Scan. cPanel's Virus Scanner, or the malware scanner your host provides, will flag known malicious files. It will not catch everything, so treat a clean scan as encouraging, not as proof.
5. Work out how they got in
The access log around the time of the first suspicious file change usually shows it. Common entry points:
- A plugin or theme with a published vulnerability that had not been updated.
- A reused or weak password, often on an old account nobody remembered.
- A forgotten copy of the site, such as an old test folder, running outdated software.
- An infected computer that had the FTP or admin password saved.
If you cannot find the door, assume it is the oldest software on the account and update or remove all of it.
6. Restore clean, do not scrub
Hunting through thousands of files for every altered line is slow and you will miss some. The reliable route is to replace everything with known-good copies:
- Restore files and database from a backup made before the earliest suspicious date.
- If there is no clean backup: delete the content system's core files, plugins and themes, and reinstall each from its official source. Keep only the uploads folder and the configuration file, and inspect both by hand for anything that should not be there.
- Immediately update everything to current versions and remove whatever you identified as the entry point.
- Add back, by hand, any posts or records created between the backup date and the hack, taken from the infected copy's database and checked as you go.
7. Reopen and get the warnings removed
Remove the temporary password protection and check the site in a private window, from a phone as well as a computer, and by clicking a result in a search engine, since some infections only show to visitors arriving from search. If Google showed a warning, open Search Console, go to Security Issues, and request a review once the site is clean. If your host suspended outgoing mail, tell them what you found and fixed.
8. Tell people if their data was exposed
If the site held personal information such as customer accounts, addresses or order details, you may have a legal duty to notify the people affected and sometimes a regulator. The rules depend on where you and they are. Get advice early; do not wait to see whether anyone notices.
Afterwards
- Keep the infected backup for a month in case you need to recover something, then delete it.
- Watch the file-change dates and the user list weekly for a while. A reinfection in the first fortnight means the door was not closed.
- Work through the security checklist so the same route cannot be used again.
Common questions
Should I just delete the account and start again?
If the site is small and you have the content elsewhere, a fresh account with freshly installed software is the cleanest fix of all. Change the passwords first regardless.
Could the hack have come from another site on the same server?
On properly configured hosting, accounts are isolated from each other, so this is rare. Other sites within your own account are a different matter: they share the same files and permissions, and one outdated site can be used to infect the rest.
Do I have to pay someone to clean it?
Not necessarily. If you have a clean backup and can follow the steps above, you can do it yourself. A cleanup service is worth the money when there is no backup, or the site earns enough that every hour offline is expensive.