The first hour after you suspect a website compromise is the most important window for evidence preservation and damage control. Acting too quickly — deleting files, restoring backups, or changing everything at once — can make it harder to understand what happened and whether the issue is fully resolved. Acting too slowly, especially if customer data or payment processing is involved, creates a different set of risks. This guide walks through a calm, ordered approach.
What to screenshot and record
Before touching anything on the site, document what you are seeing. Take screenshots of the affected pages, noting the exact URL, the browser you used, and the time. If visitors or clients reported the issue to you, save those messages — they can help establish when the problem started and what it looked like from outside the admin panel.
If your site is redirecting to another URL, note the destination URL. If there is unexpected content (spam text, injected links, foreign-language pages), capture it. If Google or a browser is showing a warning, screenshot that warning message and check Google's Safe Browsing transparency report for your domain.
Download a copy of your recent server access logs if you can access them through your hosting control panel. These logs record every request to your server and may show when the attack occurred, what files were accessed, and where requests originated. Logs are often rotated and overwritten after a few days, so saving them early is important.
Which passwords to rotate first
If you have strong reason to believe compromise has occurred, begin rotating credentials — but in a deliberate order. Start with the most privileged accounts: your hosting control panel login, then your WordPress admin account, then your FTP or SFTP credentials, then your database password. Each of these represents a level of access that could be used to re-infect the site even after a cleanup.
Change passwords using a device you are confident is clean (not the same device where you may have stored credentials that are now compromised). If you use a password manager, update it at the same time. Enable multi-factor authentication on your hosting account and WordPress admin if it is not already active.
Do not share new credentials via email until you are confident the email account has not been compromised — particularly if the attacker may have had access to your admin email address, which is often the email connected to your WordPress account.
When to involve hosting support
Contact your hosting provider early if the issue involves files you cannot access through the WordPress admin, if there are PHP files in unexpected locations, or if you receive automated messages from the host about spam, resource spikes, or suspended accounts. Hosting support often has server-level visibility that you do not — they can check whether malicious processes are running, whether mail queues are backed up with outbound spam, and whether the issue is isolated to your site or affects other accounts on the same server.
If customer payment data, personal information, or sensitive business records may have been exposed, this changes the urgency and the scope of what you need to do. In Australia, a data breach involving personal information that is likely to cause serious harm triggers notification obligations under the Notifiable Data Breaches scheme. Your hosting provider cannot make that assessment for you — that requires a conversation with a lawyer or your privacy officer.
- Screenshot everything before making any changes to files or settings.
- Download access logs from your hosting control panel — they are often overwritten within days.
- Rotate hosting, WordPress admin, FTP, and database credentials — in that order.
- Contact hosting support if you see PHP files in unexpected places or receive spam warnings.
- If customer data may be involved, seek legal advice about notification obligations before acting.
- Keep a written timeline of every action you take — this is your incident record.
A calm first-hour checklist helps avoid evidence loss, duplicate damage, and rushed mistakes.
Check hacked website symptoms