10 signs your website has been hacked - how to check and respond

Website hacking is more common than most site owners realize. According to Sucuri, over 90,000 websites are hacked every day, and most owners don't find out until Google displays a warning — or a customer calls to report it. The fallout includes lost traffic, damaged reputation, and potentially weeks of recovery work.

This guide covers 10 clear warning signs your site may have been compromised, along with actionable steps to verify and recover.

⚠️ Important: If you suspect your site has been hacked, do not immediately delete files or make changes. Take a backup first so you can examine evidence and compare clean vs. infected states.

Sign 1 — Website Content Changed Without Your Action

1

Defacement — Attackers Replacing Your Pages

The most obvious sign: you open your site and see content that isn't yours. Sometimes attackers leave a message like "Hacked by..." or replace pages with foreign-language content. In subtler cases, only hidden pages are altered — used for spam — while the homepage remains normal.

Sign 2 — Google Shows "This Site May Harm Your Computer"

2

Google Safe Browsing Malware Detection

Google Safe Browsing continuously scans websites. When it detects malware, phishing, or unwanted software, it shows a red warning page before visitors can access your site — instantly eliminating traffic and conversions.

Check your site status at: https://transparencyreport.google.com/safe-browsing/search?url=yourdomain.com

Sign 3 — Unexplained Server Slowness or High CPU/RAM Usage

3

Cryptomining or Bot Infections

Attackers often install cryptominers or DDoS bots on compromised servers, pushing CPU usage to near 100% continuously. Your site will slow to a crawl or become unresponsive. If your hosting provider reports resource overages with no obvious cause, investigate immediately.

Sign 4 — Unknown User Accounts Created

4

Ghost Admin Accounts in WordPress or DirectAdmin

Check WordPress Dashboard → Users → All Users for admin accounts you didn't create. Similarly, inspect DirectAdmin for unexpected email or FTP accounts. These backdoor accounts allow attackers to maintain persistent access even after you've cleaned up.

Sign 5 — Sudden Unexplained Traffic Drop

5

Google Deindexing or Ranking Penalties

When Google detects malware, it can remove affected pages from its index or apply ranking penalties overnight. If GA4 shows organic traffic plummeting over 50% with no known algorithm update, check Search Console immediately.

Sign 6 — Google Search Console Security Issues

6

Security Issues Panel in Search Console

Google Search Console has a dedicated "Security Issues" tab. When problems are detected, Google sends an email alert and shows which pages were flagged and why — hacked content, malware, deceptive pages, or harmful downloads.

Sign 7 — Strange Files on Your Server

7

PHP Shells and Hidden Backdoors

Attackers typically plant PHP shells in various directories. These files often have suspicious names like c99.php, r57.php, or shell.php, or disguise themselves as innocuous names like image.php inside an images folder.

Sign 8 — Suspicious Redirects

8

Redirecting Visitors to Gambling or Spam Sites

Attackers sometimes configure redirects only for mobile users or visitors arriving from Google, sending them to spam websites while desktop testing appears normal. Check using a mobile user agent or Google's Mobile-Friendly Test tool.

Sign 9 — Your Email Is Blocked or Blacklisted

9

Server Used as Spam Relay

Hackers frequently use compromised servers to send bulk spam, causing the hosting IP to land on email blacklists. Your business emails then fail to deliver or land in spam folders. Check at MXToolbox Blacklist Check.

Sign 10 — Your Hosting Provider Alerts You to Malware

10

Proactive Malware Detection from Hosting Support

Quality hosting providers run automated malware scanning and notify site owners when threats are found. Imunify360, used by AsiaGB, automatically scans and quarantines dangerous files before they cause harm.

How to Check If Your Site Has Been Hacked

ToolWhat It ChecksURL
Google Safe BrowsingMalware / Phishing statustransparencyreport.google.com
Sucuri SiteCheckMalware, blacklists, errorssitecheck.sucuri.net
Google Search ConsoleSecurity issues, index statussearch.google.com/search-console
MXToolbox BlacklistEmail IP/domain blacklistingmxtoolbox.com/blacklists.aspx
VirusTotalURL/file scan across multiple enginesvirustotal.com
Imunify360 DashboardServer-level malware detectionVia DirectAdmin Panel
💡 Tip: Run these checks at least monthly — don't wait for something to go wrong. Google Search Console and Sucuri SiteCheck are both free.

Steps to Take After Your Site Is Hacked

Step 1 — Take Your Site Offline Temporarily

Enable maintenance mode or bring the site down to prevent visitors from being exposed to malware and to stop attackers from causing additional damage while you investigate.

Step 2 — Backup the Current State

Even with malware present, backup everything first. You'll need to compare the infected state with a known-clean backup to identify exactly what was changed.

Step 3 — Change All Passwords

  • FTP / SFTP credentials
  • DirectAdmin / Hosting Control Panel
  • MySQL database passwords
  • All WordPress admin accounts
  • Email accounts associated with the site

Step 4 — Scan and Remove Malicious Files

Use Imunify360 through DirectAdmin or a WordPress security plugin like Wordfence to scan the entire server. Remove or quarantine all threats. Find recently modified files with:

find /home/user/public_html -name "*.php" -newer /tmp/reference_date -ls

Step 5 — Restore From a Clean Backup

AsiaGB Hosting performs twice-monthly automated backups (on the 1st and 15th of each month). Contact support to restore from a backup predating the attack.

Step 6 — Request a Google Review

After cleaning up, go to Google Search Console → Security Issues → Request Review. Google typically processes review requests within 1–3 days.

How to Prevent Future Hacking Attempts

Security MeasureDetailsPriority
Keep CMS/Plugins UpdatedUpdate WordPress, plugins, and themes immediately when new versions release🔴 Critical
Use Strong PasswordsMinimum 16 characters with mixed numbers and special characters🔴 Critical
Enable 2FATwo-factor authentication for WordPress admin and DirectAdmin🔴 Critical
Limit Login AttemptsBlock brute force attacks by limiting failed login attempts🟡 High
Use SSL/HTTPSEncrypt traffic to prevent man-in-the-middle attacks🟡 High
Application Firewall (WAF)Block SQL injection, XSS, and common attack patterns🟡 High
Regular BackupsMaintain personal backups in addition to hosting backups🟢 Medium
Correct File PermissionsPHP should not have write access to directories unnecessarily🟢 Medium
How AsiaGB Hosting Helps: Every AsiaGB Hosting plan includes Imunify360 for automated malware scanning, twice-monthly backups (1st and 15th), and a support team ready to help if your site is compromised.

Hosting With Built-In Malware Protection

AsiaGB Hosting includes Imunify360, DirectAdmin Control Panel, and automatic backups — protecting your site and enabling fast recovery when needed.

View Hosting Plans

FAQ — Frequently Asked Questions About Website Hacking

How do I know if my website has been hacked?
Common signs include: unusual slowness, content changes you didn't make, Google warning messages, sudden traffic drops, unknown admin accounts, and your hosting provider alerting you to malware.
What should I do first if my website is hacked?
First, take your site offline temporarily to prevent further damage. Then backup the current state, change all passwords, scan and remove malicious files, then restore from a clean backup.
Are WordPress sites hacked frequently?
WordPress is a popular target due to its market share. Most attacks exploit outdated plugins, themes, or weak passwords. Regular updates and a security plugin significantly reduce risk.
Can good hosting help prevent hacking?
Yes, significantly. Hosting with Imunify360, server-level firewall, and automatic backups can detect and block malware before it causes damage. AsiaGB Hosting includes Imunify360 in every plan.
Will Google remove my ranking if my site is hacked?
Yes, Google may deindex pages with malware or spam content and show a warning, causing traffic to plummet. After cleanup, submit a review request via Google Search Console.
Should I change all passwords after being hacked?
Absolutely. Change FTP credentials, DirectAdmin/control panel password, MySQL database password, all CMS admin accounts, and email accounts associated with the website to cut off attacker access.

Summary

Website hacking can happen to anyone, but knowing the warning signs and having a clear response plan minimizes the damage. The 10 key signs to watch for are: defaced content, Google Safe Browsing warnings, abnormal server resource usage, unknown user accounts, sudden traffic drops, Search Console security alerts, strange server files, suspicious redirects, email blacklisting, and hosting malware alerts.

The best defense is keeping your CMS and plugins updated, using strong passwords with 2FA, and choosing hosting with built-in malware protection.