Hacked Website Recovery: A Calm Playbook for 2026
Confirm the breach, contain it, then decide whether to restore a clean backup or clean the site in place, in that order.
First, confirm it is actually a hack
Not every broken site is a breached one. Genuine compromise signs include admin accounts you never created, unfamiliar plugins or files, redirects sending visitors to spam domains, search results showing pages you never wrote, and browser or Search Console warnings. A white screen after an update is probably just a plugin conflict. Diagnose before you react, the responses are completely different.
Contain the damage immediately
Once confirmed, move fast on containment: change every password, hosting account, WordPress admins, database, FTP, and enable two-factor authentication while you are there. Take the site into maintenance mode if it is actively serving malware to visitors. Notify your host, whose logs and scanning tools can pinpoint the entry point and confirm whether neighboring services were touched.
Restore or clean? The central decision
Restoring a known-clean backup is faster and more trustworthy than cleaning, because malware hides well, one overlooked backdoor reopens everything. If you hold daily backups and can date the compromise, roll back to before it, then patch the vulnerability that let attackers in. SiteGround's daily backups with one-click restores on every plan make this the default path for its customers.
Cleaning in place is the fallback when backups are missing, too old, or already infected. It means comparing core files against fresh copies, removing unknown code, reinstalling every plugin and theme from source, and scanning repeatedly. Budget hours, not minutes, and consider professional cleanup if the site earns money, a partial clean is worse than none.
Close the door that let them in
Recovery without root-cause analysis is a countdown to the next incident. The usual suspects: an outdated plugin with a known flaw, a weak or reused password, a dormant account, or nulled themes carrying embedded malware. Update everything, delete unused software, audit user roles, and rotate credentials one more time after cleanup. Then request a review through Search Console if Google flagged the site.
Rebuild your safety net
Treat the incident as the argument for the setup you should have had: automatic daily backups, an off-host copy on a schedule, two-factor authentication on every admin account, and a host whose support answers fast when minutes matter, SiteGround's median first reply of 47 seconds in our testing is the standard we measure against. The best recovery plan is the one you never need twice.
Frequently asked questions
How do websites usually get hacked?
Should I pay for professional malware removal?
Will Google penalize my hacked site permanently?
Related reading
What Is an SSL Certificate? HTTPS Explained for 2026
The padlock in the address bar is a cryptographic ID card for your website, and in 2026 it should cost you nothing.
Website Backup Strategy for 2026: Daily, Off-Host, Tested
A real backup strategy has three parts: automatic daily copies, at least one stored off your host, and restores you have actually tested.
WordPress Security Guide 2026: Practical Hardening Steps
Most WordPress hacks exploit outdated software and weak logins, this checklist closes the common doors in about an hour.