Discovering your site has been hacked is stressful, but a calm, methodical response limits the damage. The goal is to contain the breach, remove the malicious code, and close the hole that let the attacker in.
Contain the Damage First
- Take the site offline or enable maintenance mode to protect visitors.
- Change your cPanel password immediately.
- Change FTP, database, and admin passwords.
- Note the date you first noticed the problem.
Identify the Infection
- Run a malware scan in cPanel using the Virus Scanner or ImunifyAV.
- Check the Errors and Raw Access logs for unusual activity.
- Sort files by modification date in File Manager to spot recent changes.
- Look for injected spam, unknown admin users, or new PHP files.
Clean and Restore
You have two main options:
| Option | When to Use | | --- | --- | | Restore a clean backup | You have a backup from before the hack | | Manual cleanup | No clean backup is available |
If restoring a backup, choose one dated before the compromise, then immediately update everything.
Close the Hole
The attacker got in somehow, so fix the root cause:
- Update WordPress core, themes, and plugins to the latest versions.
- Delete unused or nulled plugins and themes.
- Set correct file permissions.
- Enable two-factor authentication on cPanel.
After Recovery
- Request a malware review if search engines flagged your site.
- Monitor logs closely for a few weeks.
- Keep regular backups going forward.
If you are unsure or the infection keeps returning, contact support on WhatsApp at +254 796 358081 for guidance before bringing the site back online.