Skip to content

Hacked WordPress site: a runbook for the first hour

What to do in the first hour after you find your WordPress site has been hacked, in order. Write down what you see, protect visitors, keep a copy of the site as it is, lock the attacker out and tell the people who need to know. Cleaning comes after.

By
WP Ministry
Published

In short

  • Write down what you see and when, before anything changes.
  • If the site is harming visitors, ask your host to take it offline.
  • Keep a copy of the hacked site, files and database, before you clean or restore anything.
  • Change every password from a computer you have scanned, then replace the secret keys.
  • Tell your host first. For a store, tell your payment provider too.
  • Do not pay anyone who demands money.

You think your WordPress site has been hacked. This runbook covers the first hour: what to record, what to lock, who to tell, and what to leave alone until a copy of the site exists. Cleaning comes afterwards and has its own guide. Start by writing down what you are seeing.

In the first few minutes

  1. Step 1: Write down what you see

    WordPress's documentation treats these as clear signs: a search engine or a browser warns people away from the site, your host has disabled it, visitors' antivirus flags your pages, something happened that nobody did, such as a new user appearing, or the pages show content that is not yours. Record which you see, with screenshots. This comes first because everything after it changes the picture. Write down the time, your time zone, and what changed on the site recently.

  2. Step 2: Take the site offline if it is harming visitors

    If pages send visitors elsewhere, carry a warning or show content that is not yours, ask your host to take the site offline for the public. Every visit until then puts a person at risk, and going offline changes none of the site's files. Ask the host and do not rely on WordPress: its own maintenance mode ends by itself after ten minutes, and Google's guidance is that the response saying the site is down should come from outside the compromised site. Write down when it went offline.

  3. Step 3: Keep a copy of the site as it is

    Download every file and export the database, using your host's backup tool or its file manager and database screen. Do it before any cleaning: the copy is your evidence, and what you go back to if a cleanup removes something you needed. Label it as infected, keep it off the server, and never restore it over a working site. Ask your host for the access logs today, before the older ones are gone. Write down where the copy is kept.

  4. Step 4: Change every password from a clean computer

    Scan the computer first. WordPress's documentation warns that many break-ins begin on the owner's own machine, where malware captures logins. Then change the hosting account, SFTP, the database and every WordPress user who can log in, administrators first. This follows the copy because a new database password means editing wp-config.php. Write down which passwords you changed and when, never the passwords.

  5. Step 5: Log everyone out

    Replace the secret keys in wp-config.php. That forces off anyone still logged in, the attacker included. The salt generator makes a fresh set, and the malware removal guide shows where they go. Write down the time.

Find out what happened

In the first hour you need two answers: whether this is a break-in at all, and how far it reaches. How they got in comes later.

Not every broken site is a hacked one. A blank page straight after an update is a fault: use the runbook for a site that is down. Your host may be able to confirm which of the two you are looking at.

To see how far it reaches:

  • Ask your host whether other sites on the same account are affected.
  • Open the Security issues report in Google Search Console. If Google has flagged the site, the report lists what it found, under hacked content, malware and unwanted software, or social engineering.
  • Run a scanner if you have one, and treat its answer as partial. WordPress's own advice is that no single scanner is the best approach.

Bring it back

There are three routes back. The first is the surest when it is open to you.

  1. Restore a backup from before the break-in. It has to be older than the break-in, not older than the day you noticed. It brings back the same out-of-date plugin and the old passwords, so it is a start and not the end.
  2. Replace everything that has a clean original. WordPress, every plugin and every theme are deleted and installed fresh, and what is left is checked by hand.
  3. Hand it to someone who does this. The signs are further down.

Choose the first if you have a backup you trust. Choose the second if you do not and the site runs no custom code. How to remove malware from a hacked WordPress site has the steps for both, and for finding the way in.

Whichever route you take, the site goes back online only when it is clean, the way in is closed, and every password and the secret keys have been changed a second time. The first change was made while the attacker may still have had access.

Who to tell

  • Your host, first. Send what you wrote down. The host can confirm the break-in, check the rest of the account, supply logs and take the site offline.
  • Your payment provider, if the site is a store. Say that the store was broken into and ask what they need from you. If the site holds keys for the provider, treat them as seen and replace them. Stripe's documentation, for one, lists a compromised key as a reason to rotate it.
  • Everyone with a login. Tell them their password was reset, and ask them to scan their own computers before logging in again.
  • Your customers, depending on what the site holds. If it keeps accounts, orders or form entries, assume the attacker could read them. Whether you must notify those people or a regulator depends on where you and your customers are. In the United States, the Federal Trade Commission notes that every state has its own breach notification law. Ask a lawyer, and ask early.
  • Nobody who demands payment. Keep the message with your notes. The FBI does not support paying a ransom, and says that paying does not guarantee you get anything back.

Afterwards

  • Update WordPress, every plugin and every theme. Older versions are more open to attack.
  • Turn on two-factor authentication for every administrator.
  • Keep several recent backups, in more than one place and off the site's own server.
  • If Google flagged the site, select "Request Review" in the Security issues report once the whole site is clean. The warning is not lifted without a review.
  • Keep on file: your notes, the labelled copy of the hacked site, the host's messages and the date of each step.

The WordPress security guide covers what to tighten next.

When to hand it over

Get help when:

  • the site holds customer accounts, orders or payment details;
  • you have no backup from before the break-in;
  • you cannot log in to the dashboard or the hosting account;
  • the host has suspended the account and wants to know the site is clean;
  • the infection has come back after a cleanup.

Our malware removal service is a one-time clean-up with hardening, a blacklist removal request and a written report.

Common questions

How long can the site stay offline?

As short a time as the cleanup allows. Google's guidance on closing a site describes it as a measure for a few days at most, because a longer absence has significant effects on the site in search. Leaving a hacked site online is still the worse choice.

Someone emailed to say they hacked my site and wants money. Is it real?

A demand is not one of the signs. Check the site against the signs in the first step and ask your host. If there are none, you have an email and nothing more. If there are some, follow this runbook. Do not pay in either case.

How long does Google's warning stay after the site is clean?

Until Google has reviewed the site. Its help page says most reviews take several days or weeks, and that you are emailed when the review is complete.

More on this subject

Malware removal, done for you

Malware removal is $99. Full clean-up, hardening, blacklist removal request and a written report. 30-day re-clean guarantee. It starts with a free diagnosis.