If your small business website got hacked, take a breath. It feels personal, and it feels urgent, because it is both. But this is a fixable problem, and thousands of business owners have walked through it and come out the other side with a cleaner, safer site than they started with.
The most important thing right now is order of operations. Doing the right things in the right sequence limits the damage, protects your customers, and gets you back online faster. Here is exactly what to do, starting with the first hour.
First, confirm it was actually hacked
Not every broken website is a hacked website. Before you go into emergency mode, rule out the ordinary causes. A site that will not load at all is more often a hosting or domain problem, and we cover that in how to figure out why your website is down.
Signs that point to a real hack:
- Your site redirects visitors to a different website, often something spammy or adult. This one has its own playbook in fixing a website that redirects somewhere else.
- New pages or posts you did not create, often full of pharmacy, casino, or knockoff-product links.
- A warning in Google results under your listing, such as "This site may be hacked" or "This site may harm your computer."
- Your browser shows a red warning screen before letting anyone visit.
- You are locked out of your own admin login, or you see admin users you never created.
- Customers tell you their antivirus flagged your site, or they got strange emails that appear to come from you.
If one or more of these is happening, treat it as a hack and keep going.
The first hour: contain the damage
You do not need to understand how the attack happened yet. You just need to stop it from spreading. Work through these steps in order.
1. Change your passwords, starting at the top
Change the password for your hosting account first, then your website admin login, then your domain registrar, then the email address connected to all of them. Attackers often get in through one account and use it to reach the others. Use long, unique passwords, and turn on two-factor authentication anywhere it is offered.
2. Contact your hosting company
Call or open a support ticket and say plainly: "My site has been hacked." Good hosts deal with this every day. Ask them three things: can they take the site offline or put up a maintenance page, do they have malware scanning they can run, and what backups do they have and from when. If you are not sure who your host even is, this plain-English guide to web hosting explains how to find out.
3. Take the site offline if visitors are at risk
This feels painful, but a maintenance page for a day is far better than infecting your customers' computers or letting an attacker collect their information. If your site takes payments or stores customer details, taking it down while you clean up is the responsible move.
4. Scan your own computer
Sometimes the website was not the way in. If your laptop has malware that logged your keystrokes, the attacker captured your password when you typed it. Run a full antivirus scan on any computer you use to log in to the site before you type your new passwords anywhere.
Write everything down as you go. Note when you first noticed the problem, what you saw, and every step you take. If you later need help from your host, a security professional, or a payment processor, a simple timeline saves hours of back-and-forth.
Cleaning up: getting back to a safe site
Once things are contained, you have two paths back to a clean site. Which one you take depends mostly on your backups.
| Your situation | Best path |
|---|---|
| You have a clean backup from before the hack | Restore the backup, then immediately update everything and change passwords again |
| Your backups are also infected, or you have none | Manual cleanup: your host's malware removal, a security plugin scan, or a professional cleanup service |
| The site is old, neglected, and was due for a refresh anyway | Rebuild fresh on a clean setup rather than scrubbing an outdated site |
Restoring from a backup
This is the fastest clean recovery, with one catch: you need to restore a version from before the compromise, and hacks often sit quietly for weeks before you notice. If your only backup is from three days ago and the hack started a month ago, restoring just reinstalls the attacker's back door. Ask your host how far back their backups go. If this experience taught you that your backup habits were thinner than you thought, here is how to back up your website properly going forward.
Manual cleanup
If a clean backup is not available, the site needs to be scrubbed. On WordPress sites, which are the most common hacking target simply because WordPress powers so much of the web, this usually means running a reputable security scanner, removing injected files and unknown admin users, and reinstalling the core software, themes, and plugins from fresh copies. If your site runs on WordPress and terms like plugins and themes feel foreign, this starter guide to WordPress will make the conversation with your host much easier. For anything involving stolen customer data or payment information, bring in a professional. That is not a DIY situation.
After the cleanup, tell Google
If Google flagged your site, the warning does not vanish on its own. In Google Search Console, use the Security Issues report to request a review once the site is clean. Reviews usually process within a few days. If you have never set it up, Search Console takes about ten minutes to configure and is worth having regardless.
Keeping it from happening again
Most small business hacks are not targeted. Automated bots crawl the web probing millions of sites for the same handful of weaknesses: outdated software, weak passwords, and abandoned plugins. That is actually good news, because closing those doors takes you off the easy-target list.
- Update everything, on a schedule. Outdated plugins and themes are the single most common way in. A monthly website maintenance routine handles this in under an hour.
- Use two-factor authentication on hosting, domain, admin, and email accounts.
- Delete what you do not use. Every inactive plugin, old theme, and forgotten admin account is an unlocked window.
- Keep automatic offsite backups with at least 30 days of history, so a slow-burning hack cannot poison every copy.
- Make sure HTTPS is active and current. An SSL certificate does not prevent hacks by itself, but it protects the data moving between your visitors and your site.
- Review who has access. Former employees, old contractors, and past designers should not still hold keys.
For a fuller picture of protecting your site over the long haul, see our complete guide to website security for small business.
When to call in help
Handle it yourself if the damage is limited to spam pages or a redirect, you have a clean backup, and your host is responsive. Call a professional if customer data may have been exposed, the site keeps getting reinfected after cleanup, you are locked out entirely, or the site processes payments. Reinfection in particular means a back door is still open somewhere, and finding it takes experience.
One more honest note: if this hack happened because the site sat untouched for years, the real fix is not just cleanup, it is a plan for ongoing care. Whether that is a maintenance habit you build yourself or a service that handles updates, backups, and monitoring for you, a website is not a set-it-and-forget-it asset.
Frequently asked questions
How do hackers get into small business websites?
Almost always through automated attacks, not a person targeting you. Bots scan for outdated plugins and software with known vulnerabilities, try common passwords against login pages, and exploit hosting accounts secured with reused credentials. The attacker usually does not know or care what your business is. Your site was simply reachable and had a door left open.
How long does it take to recover from a website hack?
With a clean backup and a cooperative host, many sites are back the same day. A manual cleanup typically takes a few days. If Google flagged the site, expect a few more days for the security review after cleanup before the warning disappears from search results. Rankings that dipped during the incident generally recover once the warnings clear.
Should I just delete the site and start over?
Sometimes, yes. If the site was old, rarely updated, and not performing well anyway, rebuilding on a clean, modern setup can be faster than scrubbing an infected one, and you end up with a better site. Keep your domain, since that carries your Google history, and rebuild the site on top of it. Just make sure the new setup includes the maintenance and backup habits the old one lacked.