Your website is most likely hacked if visitors are being redirected to betting, pharma or "loan app" pages, Google shows "This site may be hacked" under your listing, or a site:yourdomain.com search shows pages you never made. The fastest way to confirm is the free Security Issues report in Google Search Console. If it is hacked, don't panic and don't just delete random files: back up, change every password, then clean the site properly or get help.
This guide is written for business owners, not developers. Most hacked sites we hear about in India are WordPress sites on shared hosting with an old plugin or theme, so many of the examples below use WordPress. The checks work for any website.
Common signs your website has been hacked
- Redirects: customers say your site opens a different website, often only on mobile or only when they click from Google. Attackers do this on purpose so the owner doesn't notice.
- Spam in Google: your Google results show Japanese or Chinese text, "online casino", "cheap medicines" or thousands of pages you didn't create.
- Browser or Google warnings: Chrome shows a red "Dangerous site" screen, or Google shows "This site may be hacked".
- Unknown admin users in WordPress (Users → All Users) or new FTP/cPanel accounts.
- Hosting complaints: your host suspends the account, warns about malware, or says your site is sending spam emails.
- Strange files or code: new
.phpfiles in the uploads folder, unfamiliar code at the top ofindex.phpor.htaccess. - Sudden slowness or high resource use with no increase in real visitors.
- Your contact or payment form behaves differently, or customers report fake payment pages.
How to check if your website is hacked (free checks)
- Google Search Console → Security Issues. If you have verified your site in Search Console, open the Security Issues report. It lists hacked content, malware and deceptive pages Google has found, with sample URLs. If you haven't added your site yet, do it now; it's free.
- Google Safe Browsing site status. Enter your domain in the Google Transparency Report site status tool to see if Google currently flags it as unsafe.
- Search Google for spam on your domain. Type
site:yourdomain.comand scroll through the results. Then trysite:yourdomain.com casino,site:yourdomain.com viagraorsite:yourdomain.com loan. Any results you didn't create are a strong sign of a "spam injection" hack. - Test like a visitor. Open your site on a phone using mobile data (not office Wi-Fi), in a private/incognito window, and by clicking your own listing in Google. Many redirect hacks only trigger this way.
- Check admin users. In WordPress, look at Users and sort by role. Also check your hosting panel for extra FTP accounts, email accounts and cron jobs you didn't set up.
- Look for recently changed files. In cPanel File Manager or via FTP, sort by "last modified". Core files and old plugin files suddenly changing on the same date is suspicious. PHP files inside
wp-content/uploadsshould normally not exist. - Read the hosting logs. Your host's access logs (cPanel → Metrics → Raw Access or Visitors) can show repeated hits to
wp-login.php,xmlrpc.phpor an odd file name. That often shows how they got in. - Run an external scan. Our free website scanner checks for outdated WordPress and libraries, exposed files such as
.env,.gitand backups, missing security headers and SSL problems. It's non-destructive, but it only sees what is visible from outside, so a "clean" scan does not prove a site isn't hacked.
What to do immediately if your website is hacked
- Take a full backup first (files and database), even though it's infected. You may need it as evidence and to see what changed.
- Change every password: hosting/cPanel, WordPress admins, FTP/SFTP, database user, domain registrar and the email accounts linked to them. Turn on two-factor login wherever it's offered.
- Remove unknown admin users and unknown FTP accounts, cron jobs and email forwarders.
- Put the site in maintenance mode if it is redirecting customers or showing fake payment pages, so more people aren't harmed.
- Restore or rebuild from a known-good copy. The safest clean-up is: a fresh copy of WordPress core, fresh copies of plugins and themes from the official source, then your own content and uploads after checking them. Remove plugins you don't use and anything "nulled" (pirated).
- Update everything and find the entry point, usually an outdated plugin, a weak password or a leftover file manager or backup script. If you don't fix the cause, it will happen again.
- Ask Google for a review from the Security Issues report once the site is clean.
- Check customer data. If customer data such as names, phone numbers or payment details may have been accessed, read our DPDP website security checklist on breach reporting. Under the CERT-In directions of 28 April 2022, companies (body corporates), service providers, intermediaries, data centres and government organisations must report incidents such as website defacement, unauthorised access and data breaches to CERT-In within 6 hours of noticing them (by email to incident@cert-in.org.in).
When to call an expert (malware removal)
You can often handle a simple case yourself if you have a clean backup from before the hack. Get professional help if:
- the hack comes back after you cleaned it (there's a hidden backdoor);
- you have no clean backup, or the database itself contains injected code;
- it's an online shop, school portal, hospital or any site holding customer data;
- your hosting account is suspended or your domain is on email blacklists;
- you need a written report for your bank, payment gateway, client or auditor.
Our team handles WordPress malware removal, hardening and incident response. You can contact us with your domain name and what you are seeing. Please don't send passwords by email or WhatsApp; we'll arrange safe access.
How to stop your website from getting hacked again
- Update weekly: WordPress core, plugins and themes. Delete what you don't use.
- Use only official plugins and themes. "Free premium" (nulled) downloads often come with a backdoor already inside.
- Strong, unique passwords and two-factor login for every admin, especially your hosting panel and domain registrar.
- Automatic off-site backups kept for at least 30 days, so you can go back to a date before the infection.
- Limit admin accounts. Staff who only write posts don't need Administrator rights.
- Don't leave files lying around: old backups (
backup.zip),.env,.git, installer scripts and test pages are often found and used by attackers. - Turn on HTTPS and security headers and keep an eye on your Search Console messages.
- Scan regularly. Run our free scanner after every big change, or use our Annual Monitoring plan (₹5,999/year) if you'd like ongoing checks. See pricing.
A hacked website can also be used to send fake emails "from" your business. Check that your domain has SPF, DKIM and DMARC set up correctly using our SPF, DKIM and DMARC guide. If you're wondering how much a proper audit costs, see website security audit cost in India.
Frequently asked questions
Kaise pata kare ki website hack hui hai ya nahi?
Google par site:aapkadomain.com search karke dekhiye ki koi spam ya casino pages to nahi dikh rahe. Phone par mobile data se site kholiye aur Google Search Console ka Security Issues report check kijiye. Agar redirect, ajeeb pages ya unknown admin users dikhen, to site hack hone ki sambhavna kaafi zyada hai.
Website hack ho gayi, ab kya kare?
Ghabraiye mat. Pehle site ka backup lijiye (evidence ke liye), phir hosting, WordPress admin, FTP aur database ke saare passwords badaliye. Unknown admin users hataiye, Google Search Console mein Security Issues dekhiye, aur site ko clean backup ya fresh install se restore kijiye.
Why does my WordPress site redirect to another website only on mobile?
Many redirect hacks show the spam page only to mobile visitors or only to people coming from Google, so the owner who types the address directly sees nothing wrong. Test from a phone on mobile data and by clicking your own result in Google search.
Will deleting the bad files fix a hacked website?
Usually not by itself. Attackers often leave backdoors, extra admin users or database injections, so the hack returns in a few days. You need to find how they got in, remove every backdoor and update or replace the vulnerable plugin or theme.
How long does Google take to remove the "This site may be hacked" warning?
After you clean the site, request a review from the Security Issues report in Google Search Console. Google says reviews can take from a few days to a few weeks depending on the issue type.
Is my hosting company responsible for cleaning my site?
Most shared hosting plans only protect the server, not your website files and plugins. Some hosts offer a paid clean-up, but check your plan; in most cases the site owner is responsible for keeping the website software updated.
This guide is general information, not legal advice. If you have lost money to fraud, call 1930 immediately or report at cybercrime.gov.in.