How do you know your website has been hacked?
Some hacks are obvious, like a defaced homepage. Most are not, because attackers profit more when the owner does not notice. Spam pages and redirects are often shown only to Google or only to visitors arriving from search on a phone, so you may browse your own site and see nothing wrong.
The most common clue in India is a customer saying “your site opened a betting page” or “Google shows Japanese text under your name”. Others show up in tools: a warning email from Google Search Console, a “This site may be hacked” label in search results, a red “Deceptive site ahead” screen in Chrome, or a hosting suspension notice for sending spam or using too many resources.
Search Google for site:yourdomain.com and scroll. Pages you never created, especially in another language or about medicines, loans or gambling, are a strong sign. Checking in a private window on your phone, arriving through a Google result, catches mobile-only redirects that a direct visit hides.
- Redirects to gambling, adult or scam pages, often only on mobile
- Unknown pages in Google results, frequently in Japanese or full of product spam
- Warnings in Search Console, Chrome or antivirus software
- New admin users you did not create, or your own login no longer working
- Hosting suspension, sudden server load or outgoing spam email
- Unfamiliar files in upload folders, or code at the top of theme files
What to do in the first hour after your website is hacked
Contain first, clean second. The instinct is to start deleting suspicious files, but that destroys evidence of how the attacker got in and often misses the backdoor they left for themselves.
Change passwords in this order: hosting control panel, email accounts on the domain, database, FTP or SFTP, and every website admin account. Use new, unique passwords and turn on two-factor authentication wherever it exists. If you shared the hosting login with an old developer, this is the moment it stops working for them.
Next, take a full backup of the infected site, both files and database, and keep it separate. It will be needed to trace the attack. Then limit the damage: put the site in maintenance mode, or ask your host to restrict it, especially if it is redirecting visitors or sending spam. If you run an online store, pause checkout until card and payment pages are verified.
Finally, write down what you saw and when, with screenshots. That timeline helps the cleanup and any report you may need to make.
- Change all passwords and enable two-factor authentication
- Back up the infected site before touching anything
- Maintenance mode or host-level restriction
- Pause checkout on stores
- Screenshots and a short timeline of what you noticed
Hacked website repair, step by step: how a proper cleanup runs
A thorough cleanup follows a fixed order so nothing is skipped. Here is the sequence we use for most sites.
1. Snapshot and inventory
Copy the infected site to an isolated environment, list every file with its modification date, and export the database.
2. Replace, do not repair, core files
Core CMS files, themes and plugins from public sources are replaced with fresh official copies rather than edited line by line.
3. Hunt custom code and uploads
Your own theme and custom code are compared against the last known good version; executable files in upload folders are removed.
4. Clean the database
Injected scripts in posts, options and widgets are removed; unknown admin users deleted; site URLs checked.
5. Server-level checks
Web server rules such as .htaccess, scheduled cron jobs, and other sites on the same hosting account are reviewed.
6. Close the entry point
The vulnerable plugin, weak password or exposed file is fixed, updated or removed.
7. Rotate secrets
Passwords, API keys and authentication salts are changed again after cleanup, since the attacker may have copied them.
8. Search and warning cleanup
Spam URLs return proper not-found responses, sitemaps are resubmitted and Google is asked to review.
Finding how the attacker got in
Hacked website repair without a root cause is a temporary fix. If the hole stays open, automated bots find it again, often within days, and the owner concludes the cleaner did a bad job.
The usual entry points on small business sites are predictable. An outdated plugin or theme with a published vulnerability. A nulled, meaning pirated, premium theme or plugin that came with a backdoor built in. A weak or reused admin password guessed by bots. An old developer’s FTP account never removed. A second, forgotten website on the same hosting account that was hacked first and infected its neighbours. Occasionally, a compromised computer that saved the FTP password.
We trace it using the evidence you preserved: server access logs around the time the first malicious files appeared, file modification dates, plugin version histories and login records. We then write a short, plain-language note on what happened and what changed to prevent it. That note is useful to you, to your host and to any future developer.
Why hacked website cleanup must include the database
Many cleanups replace files and stop there. On database-driven sites such as WordPress, attackers often hide their code in the database too, where file scanners never look.
Common hiding places include script tags injected into post and page content, widget and theme settings that load an external JavaScript file, altered site URL settings that redirect visitors, extra administrator accounts with innocent-looking names, and scheduled tasks stored in the options table that recreate malicious files every few hours. That last one explains a very frustrating pattern: the site looks clean in the evening and is reinfected by morning.
We search the database for script injections, encoded strings and unfamiliar external domains, review every user with elevated rights, and check stored scheduled events. On stores, we also look at order and customer tables for signs that data was accessed, because that affects whether customers need to be told.
- Posts, pages and widgets scanned for injected scripts
- Site URL and home URL settings verified
- Administrator list reviewed; unknown accounts removed
- Stored scheduled events checked for reinfection jobs
Hacked WordPress repair: the most common case
WordPress is not insecure by itself, but its popularity and plugin ecosystem make it the most attacked platform, and small business sites often run many plugins that nobody updates.
For WordPress we use WP-CLI to verify core files against official checksums and reinstall any that differ. Plugins from the official directory are checked and reinstalled the same way; premium plugins are reinstalled from the vendor’s original package, and nulled ones are removed outright. We look for PHP files in the uploads folder, which should normally hold only media, and inspect the must-use plugins folder, which attackers like because it loads silently. The authentication keys and salts in wp-config.php are regenerated, which logs out every session including the attacker’s.
Afterwards we reduce the attack surface: remove unused plugins and themes, disable the built-in file editor, restrict XML-RPC if nothing needs it, limit login attempts, and move to a supported PHP version. Our WordPress help for small businesses page covers routine upkeep that keeps sites out of this situation.
Removing Google’s hacked warning and spam pages from search
Once the site is clean, Google needs to see that it is clean. This part of hacked website repair is often skipped, which leaves warnings and spam results in place long after the malware is gone.
In Google Search Console, the Security Issues report shows what Google detected, such as hacked content, malware or deceptive pages. After fixing everything listed, you request a review from that report and describe what was done. Reviews can take from a few days to a few weeks depending on the type of issue. Requesting a review before the site is truly clean usually leads to rejection and a longer wait.
Spam pages need their own treatment. The injected URLs should return a 404 or 410 response so Google drops them over time; for urgent cases the Removals tool can temporarily hide them from results. For cloaked spam, where Google sees different content from visitors, the URL Inspection tool shows what Googlebot actually receives. We then resubmit a clean sitemap. Recovery of rankings varies and cannot be guaranteed, but a clean site with no spam pages is the only starting point. Longer-term search work is covered on technical SEO freelancer.
Restore a backup, clean the site, or rebuild it?
There are three routes, and the right one depends on how old the site is, whether you have a clean backup, and how often it has been hacked before.
Restore from backup
Fast when you have a backup from before the infection and know the date it started. You still must close the entry point and update everything, or the restored site is reinfected by the same route.
Clean in place
Right when there is no reliable backup, the site has recent content you cannot lose, and the codebase is reasonably current.
Rebuild clean
Better when the site runs nulled themes, an abandoned CMS version or has been reinfected repeatedly. A fresh static site starting at ₹10,000 removes most of the attack surface, since there is no admin panel or plugin layer to exploit.
Beware of backups that are already infected. Attackers often sit quietly for weeks before acting, so the most recent backup may contain the backdoor. We check backups for known indicators before restoring them.
How much does hacked website repair cost in India?
Cleanup quotes across the market vary widely, and the gap usually reflects depth. A quick scan-and-delete service is cheap and often temporary. A cleanup that includes database work, root-cause tracing, search cleanup and hardening takes longer and is more likely to last.
We quote after a first look, because the size of the job only becomes clear once we see the files, logs and database. The quote separates containment, file cleanup, database cleanup, search cleanup and hardening into lines, so you see where effort goes. Nothing is billed until you approve it in writing.
Two figures are fixed starting points. If repair is not worth it, a clean rebuild of a business site starts at ₹10,000 (US$150) and takes 1–2 weeks, including two months of free maintenance. For ongoing protection after cleanup, monthly care starts at ₹8,000/mo (US$120/mo), covering updates, backups and monitoring. Online stores, where checkout integrity matters, may justify a rebuild on our store plan starting at ₹50,000.
Hosting suspension, spam email and blacklists
Hacks often reach beyond the website. A compromised site can send thousands of spam emails from your server, which gets your domain’s email flagged by other providers and your hosting account suspended.
If your host has suspended the account, they usually want a cleanup and an explanation before restoring it. We can prepare that explanation from the cleanup notes and work with the host to bring the site back, sometimes on a temporary clean copy while the main account is reviewed.
For email, check that your domain has correct SPF, DKIM and DMARC records, which help receiving servers tell your real mail from forged messages. If your domain or server IP appears on public blocklists, most have a delisting process once the source of spam is fixed. If you use Google Workspace or Microsoft 365 for mail, change those passwords too, because attackers sometimes pivot from the website to the mailbox. Our hosting and business email setup page covers moving to cleaner hosting if the current one keeps causing trouble.
Customer data, CERT-In and telling the people affected
If your site stores customer details, such as enquiry forms, accounts or orders, a hack is not only a technical problem. You may have duties to report it and to inform people whose data was exposed. This is general information, not legal advice.
CERT-In, India’s national computer emergency response team, issued directions in 2022 asking service providers, intermediaries, data centres, body corporates and government bodies to report certain cyber incidents, including website defacement and malicious code attacks, within six hours of noticing them. Whether and how this applies to a small business is a question for your legal adviser, but it is worth knowing it exists. The Digital Personal Data Protection Act, 2023 also requires organisations handling personal data to inform the Data Protection Board and affected people of a personal data breach.
On our side, we tell you plainly what evidence we found of data access, preserve the logs, and help you understand the technical facts so your adviser can decide what needs reporting. For stores, we check checkout pages for card-skimming scripts, which steal payment details as customers type.
How to stop your website from being hacked again
Most reinfections come from the same few gaps. Closing them is less about buying a security product and more about routine.
- Update CMS core, themes and plugins promptly; remove what you do not use
- Never install nulled or pirated themes and plugins
- Unique passwords plus two-factor authentication on hosting, admin and email
- Named accounts for each person; remove old developers and agencies
- SFTP instead of FTP; no shared logins pasted in chat groups
- Automatic off-site backups, with a restore tested at least once
- A web application firewall at the hosting or DNS level
- File-change and uptime monitoring with alerts
- Separate hosting accounts for separate sites, so one infection cannot spread
- A supported PHP version and HTTPS everywhere
If routine upkeep is not something your team will do, it is cheaper to pay for it than to pay for another cleanup. Our care plans start at ₹8,000/mo a month; see website maintenance freelancer for what they cover.
Red flags when choosing a hacked website repair service
A hacked site creates panic, and some services exploit it. Be careful with anyone who shows these signs.
- Promises a full cleanup in minutes without looking at the site
- Only runs a scanner and sends a green report
- Cannot explain how the attacker got in
- Wants your owner-level logins for hosting, email and domain registrar all at once, and plans to keep them
- Offers to “track down the hacker” for an extra fee
- Pushes you to pay in full before any first look
- Guarantees your Google rankings will return by a date; nobody can guarantee rankings
A good hacked website repair service asks questions first, preserves evidence, explains the entry point and leaves you with a list of changes. If you get a vague answer to “how did they get in?”, expect to be hacked again.
A worked example: a homestay site hit by the Japanese keyword hack
This is a hypothetical scenario to illustrate the process, not a real client case.
A family-run homestay in Kerala notices bookings drop. Searching for its name shows pages with Japanese text selling branded goods under its domain. The site runs WordPress, last updated two years ago, with a premium theme downloaded free from an unofficial site.
We would first have the owner change hosting, admin and email passwords, then take a full backup. Inspection would likely show a backdoor in the nulled theme, a hidden administrator account and a generator script creating thousands of spam pages. The cleanup: replace WordPress core from official sources, remove the nulled theme, delete the hidden account, clean injected options, make spam URLs return 410, and regenerate salts. Given the theme problem, we might recommend moving to a clean, fast static site starting at ₹10,000, with booking enquiries sent to WhatsApp, which also removes the admin panel attackers target. After Search Console review is requested and the sitemap resubmitted, spam results typically fade over the following weeks, though timing depends on Google.
Hacked website repair across India
Cleanup is done remotely with access to your hosting, so it makes no difference where you are. You share access through named accounts where possible, we work on the server, and you see progress in WhatsApp updates.
Our city pages describe the kinds of local business sites that are common there: Kottayam, Alappuzha, Udupi, Haridwar, Port Blair, Gaya, Muzaffarpur, Bikaner, Ajmer, Aligarh and Agartala. Overseas site owners can see countries we work with.
Website hack ho gayi? Turant kya karein
Sabse pehle hosting, email, database aur admin ke saare password badliye aur two-factor login on kijiye. Kuch bhi delete karne se pehle poori website ka backup le lijiye, kyunki usi se pata chalta hai ki hacker andar kaise aaya.
Phir files aur database dono ki safai, purane plugin update ya hatana, aur Google Search Console mein review request karna hota hai. Hum pehle site dekh kar itemised quote dete hain; approval ke baad hi kaam aur payment. Agar website bahut purani hai toh nayi saaf website ₹10,000 se ban sakti hai.