Back to the blog
securityIT operationsincident response

My Website Got Hacked — What Do I Do Now?

Gatium csapatSeptember 6, 20263 min read

Most hacks aren't the end of the world — panicking causes more damage than the original incident. Step by step, what to do in the first hours and after.

My Website Got Hacked — What Do I Do Now?

If you've ever landed on this article by anxiously searching "my website got hacked, what do I do," this one is for you specifically. The good news: most hacks aren't the end of the world, and most of the damage can be properly repaired if you take the steps in the right order. The bad news: rushing — trying to fix everything at once, in a panic — often causes more damage than the original incident.

The first hours: stop the bleeding, don't try to heal the whole wound at once

The first and most important step is isolating the site — not necessarily taking it down completely, but stopping the problem from spreading or doing further damage. If your site is serving malicious code to your visitors, or sending out spam in your name, the primary goal is to stop that immediately — whether by temporarily putting the site into maintenance mode, or restoring a temporary version from an earlier, clean backup.

At the same time, change every credential connected to the site — admin password, hosting access, database, and if any API keys or integration secrets could be involved, those too. Don't limit this to the one account you suspect — after a successful breach, you don't know for certain what was accessed, so the safe default is to treat everything as if it were compromised.

The investigation: what's worth understanding before you restore

The biggest trap of rushing is that someone immediately restores an old backup and thinks that solves the problem — without ever figuring out how the attacker got in. If the entry point (an outdated plugin, a weak password, a vulnerable component) isn't identified and patched, the restored, "clean" site can get reinfected through the same hole within days — and this kind of repeat incident is far more damaging to your trust and your search rankings than a single one-off event.

During the investigation, it's worth checking the server logs — when the first suspicious entries appeared, from what IP addresses, which files were modified or created unexpectedly. If this gets too technically deep, that's the point where bringing in an outside specialist is faster and safer than trying it yourself — especially if customer data may have been involved, because from there legal obligations can come into play too.

Reporting and the lesson — the part many skip

If personal data may have been involved in the attack — a customer list, passwords, payment data — GDPR requires mandatory reporting to the authority within a set timeframe in certain cases. Many forget this, or deliberately avoid it, fearing the consequences — yet an unreported incident, if it later comes to light anyway, carries far worse consequences than a timely, good-faith report. If you're not sure whether personal data was involved, the safe approach is to clarify this with a legal or data protection expert, not decide it yourself.

The most important thing to do after an incident — and the one almost everyone skips — is a post-mortem: what exactly happened, why didn't we notice sooner, and what needs to change so it's caught faster next time, or doesn't happen at all. If there was monitoring but it didn't alert in time, that needs fixing. If there was no reliable backup, or the restore took longer than acceptable, that needs solving. An incident you learn nothing from will sooner or later repeat — just maybe with bigger damage next time.

A hacked website isn't a shame — what is, is the same mistake happening a second time, because no one learned from the first.

Finally, if your site also communicates with customers — newsletters, logins, orders — it's worth considering a short, honest notice to them too, especially if there's any chance their data was involved. This feels like a scary step at first, but in practice, customers tolerate an honest, quickly handled incident far better than finding out afterward, from another source, that something happened and you stayed quiet about it.


If you're dealing with an incident right now, or want to prevent it from ever getting this far, write to us urgently — we can help with both recovery and prevention.

Ready to talk through your project?

Let's discuss how to build an experience that not only looks great, but drives real growth for your product.

My Website Got Hacked: A Step-by-Step Guide | Gatium