Hosting · 4 min read

Hacked Website Recovery: A Calm Playbook for 2026

Confirm the breach, contain it, then decide whether to restore a clean backup or clean the site in place, in that order.

Hacked Website Recovery: A Calm Playbook for 2026 illustration

First, confirm it is actually a hack

Not every broken site is a breached one. Genuine compromise signs include admin accounts you never created, unfamiliar plugins or files, redirects sending visitors to spam domains, search results showing pages you never wrote, and browser or Search Console warnings. A white screen after an update is probably just a plugin conflict. Diagnose before you react, the responses are completely different.

Contain the damage immediately

Once confirmed, move fast on containment: change every password, hosting account, WordPress admins, database, FTP, and enable two-factor authentication while you are there. Take the site into maintenance mode if it is actively serving malware to visitors. Notify your host, whose logs and scanning tools can pinpoint the entry point and confirm whether neighboring services were touched.

Restore or clean? The central decision

Restoring a known-clean backup is faster and more trustworthy than cleaning, because malware hides well, one overlooked backdoor reopens everything. If you hold daily backups and can date the compromise, roll back to before it, then patch the vulnerability that let attackers in. SiteGround's daily backups with one-click restores on every plan make this the default path for its customers.

Cleaning in place is the fallback when backups are missing, too old, or already infected. It means comparing core files against fresh copies, removing unknown code, reinstalling every plugin and theme from source, and scanning repeatedly. Budget hours, not minutes, and consider professional cleanup if the site earns money, a partial clean is worse than none.

Close the door that let them in

Recovery without root-cause analysis is a countdown to the next incident. The usual suspects: an outdated plugin with a known flaw, a weak or reused password, a dormant account, or nulled themes carrying embedded malware. Update everything, delete unused software, audit user roles, and rotate credentials one more time after cleanup. Then request a review through Search Console if Google flagged the site.

Rebuild your safety net

Treat the incident as the argument for the setup you should have had: automatic daily backups, an off-host copy on a schedule, two-factor authentication on every admin account, and a host whose support answers fast when minutes matter, SiteGround's median first reply of 47 seconds in our testing is the standard we measure against. The best recovery plan is the one you never need twice.

Mentioned in this article: our test scores
SiteGround logo
SiteGroundBest for WordPress & support quality · from $2.99/mo
9.3Visit

Frequently asked questions

How do websites usually get hacked?
Overwhelmingly through known vulnerabilities in outdated plugins and themes, weak or reused passwords, and stolen credentials, automated bots scan the entire web for these constantly. Targeted attacks on small sites are rare. That is encouraging: routine updates and strong authentication eliminate the paths most attacks actually use.
Should I pay for professional malware removal?
If the site produces revenue, cleanup is beyond your comfort level, or reinfection keeps happening, yes, a thorough professional clean costs less than a lingering compromise. If you have solid recent backups, restoring and patching yourself is usually sufficient. The wrong answer is a quick surface clean that leaves a backdoor behind.
Will Google penalize my hacked site permanently?
No. Warnings and ranking suppression lift after cleanup: fix the site, then request a review through Search Console. Reviews typically resolve within days. Lasting SEO damage comes from leaving a compromise active for weeks, spam pages and malicious redirects accumulating in the index, not from the incident itself.

See our best hosting rankings

Related reading

Hosting

What Is an SSL Certificate? HTTPS Explained for 2026

The padlock in the address bar is a cryptographic ID card for your website, and in 2026 it should cost you nothing.

4 min read · February 18, 2026
Hosting

Website Backup Strategy for 2026: Daily, Off-Host, Tested

A real backup strategy has three parts: automatic daily copies, at least one stored off your host, and restores you have actually tested.

4 min read · February 15, 2026
Hosting

WordPress Security Guide 2026: Practical Hardening Steps

Most WordPress hacks exploit outdated software and weak logins, this checklist closes the common doors in about an hour.

4 min read · January 21, 2026
MC

Lead Reviewer

Maya Chen

Maya has reviewed consumer software and web services for nine years, previously leading testing at a major tech publication. She personally runs every speed benchmark and signs up for every service we review with unaffiliated accounts.