Short answer
Change every password first, then take a copy of the site as evidence before cleaning anything. Find and remove the malicious files, update everything, and only then bring the site back. Restoring a backup without closing the original hole just gets you reinfected.
The part people skip is removing the attacker’s access — a hidden admin user, an added SSH key or a backdoor file in an unexpected folder. If you clean the visible damage but leave that, the site is reinfected within days.
Learn more
- My website has been hacked: what to doThe signs a site is compromised and a clear recovery order: contain, preserve, restore or clean, close the hole, and check search engines.
- How to clean a hacked WordPress siteA step-by-step recovery for a compromised WordPress site: contain it, restore or clean, close the way in, and check it’s clean afterwards.
- How to find malicious files on your websitePractical ways to spot injected and backdoor files: PHP where it shouldn’t be, recently modified files, obfuscated code and comparisons with clean copies.
Step-by-step
- Recover a hacked websiteAdvanced · 120 min · 9 steps