Take it offline first, so it stops harming visitors while you work. Change every password connected to the site. Then find out how they got in, because if you only clean up, they'll be back, and there may be more than one way in. Restore from a backup made before the hack, apply every update, and ask Google to review the site so its warnings are lifted. If customers' personal information may have been accessed, you may also have to tell them.
What's the problem
Your site redirects visitors to spam or scams, shows pages you didn't write, triggers browser warnings, or appears in Google with "This site may be hacked". Your host may have suspended it. Customers are asking what's going on.
Why it happens
- Outdated software. An old content management system, plugin, theme, framework or package with a published vulnerability. This is the most common way in.
- Stolen or weak passwords. For the admin panel, the hosting account, file transfer, or the database.
- An infected admin computer. Malware on a computer used to manage the site can capture passwords as they're typed.
- More than one door. Attackers often leave several ways back in, so fixing one hole doesn't end it.
How to fix it
- Take the site offline, or put up a holding page, so it stops serving harmful content.
- Change every password: hosting, admin users, database, file transfer, email, and any API keys the site uses.
- Back up the hacked site as it is, for investigation, before you change it.
- Find how they got in. Check what's outdated, look at server logs around when it started, and scan the computers used to manage the site.
- Restore a backup from before the hack, or rebuild from clean code. Check the backup's date first, since some hacks sit unnoticed for weeks.
- Update everything (system, framework, plugins and packages), and remove anything unused.
- Bring it back online and request a review in Google Search Console so warnings are removed.
- Work out whether personal information was accessed. If it was and you're covered by the Privacy Act, you may have to notify. See do I have to report a data breach.
When to call Preventionlabs
Containing a live hack and investigating it is incident response, and that isn't a service we offer. If it's happening now, take the steps above, or bring in an incident response firm. Call us when the hack was the symptom: a site so far out of date, or so fragile, that cleaning it just means waiting for the next one. A resurrection gets it running on maintained dependencies and protected to MVP level, then hands it back with notes on how to keep it that way.
Submit your project for a free assessmentFree assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.
Sources
- web.dev (Google): Quarantine your siteweb platform guidance
Take your site offline so that it no longer serves content to users.
- web.dev (Google): Identify the vulnerabilityweb platform guidance
Because there may be multiple, independent hacks in place, even if you're able to find and fix one vulnerability, we recommend continuing to search for others.
- web.dev (Google): Clean and maintain your siteweb platform guidance
First, check that your backup was created before your site was hacked.
- Google Search Help: "This site may be hacked" messagesearch engine docs
You'll see the message "This site may be hacked" when we believe a hacker might have changed some of the existing pages on the site or added new spam pages.
- OAIC: About the Notifiable Data Breaches schemeAustralian privacy regulator
Under the Notifiable Data Breaches (NDB) scheme any organisation or agency the Privacy Act 1988 covers must notify affected individuals and the OAIC when a data breach is likely to result in serious harm to an individual whose personal information is involved.