A compromised site can be repaired, but in order: observe, isolate, clean, close the door. Cleaning alone is useless if the door stays open — that is why so many sites are reinfected within the week.
The signs
| What you observe | What it indicates |
|---|---|
| Pages or links you did not write | Content injection, often invisible to you and visible to search engines |
| The site redirects elsewhere, but only from a search engine | Conditional redirect: it spares the administrator |
| A warning from the browser or a search engine | The site is already publicly flagged |
| Unknown administrator accounts | An access was created to last |
| Recent files you do not recognize | Hostile code dropped |
| A sudden rise in consumption | The site is serving something other than you |
| Your messages are massively rejected | The domain is being used for mailings |
The four moves, in order
- Observe and note. The date, the affected pages, the addresses concerned. Delete nothing before looking: what remains helps understand how it got in.
- Isolate. Take the site offline or into maintenance. A compromised site harms its visitors and its own reputation with every passing minute.
- Clean. Restore an earlier healthy copy, then update immediately.
- Close. Change all the passwords, delete the unknown accounts, remove what serves no purpose.
Why restoring is not enough
The exploited flaw is almost always older than the intrusion: it is therefore in the backup too. Restoring without updating amounts to reinstalling the open door.
Choose a date before the first signs, then, right away and before putting anything back online:
- update the content management system, the theme, and all the extensions;
- change the password of every administrator account;
- change the database password and carry it into the configuration file;
- change the file transfer credentials;
- delete unused extensions and themes — a deactivated theme remains an accessible file on the server.
An extension abandoned by its author will never receive a fix. It is not free software: it is a debt.
Letting us know
Report it to us, even if you know what to do. A compromised site does not concern you alone: it can be used to attack third parties, to send fraudulent mail, or to consume the machine's shared resources.
Our terms of service provide that a service may be suspended when urgency requires it, to protect the other customers and the infrastructure. A customer who reports their own incident is always in a better position than one at whose place it is discovered.
In the ticket, state the domain, the date of the first signs, what you have already done, and whether third parties' personal data may have been exposed.
Afterwards
- Watch the site for a few weeks: reinfections happen early.
- Keep a clean copy away from the hosting — see Understanding backups.
- If your visitors' personal data may have been exposed, you have, as data controller, obligations of your own under the GDPR. Our privacy policy describes what falls to us; the rest falls to you.