Most hacked websites do not look hacked. The era of defaced homepages is largely over; a compromised site is worth far more to an attacker while it looks completely normal, quietly serving spam links, hosting phishing pages in a forgotten subdirectory, or redirecting a slice of visitors somewhere profitable. Site owners routinely discover a compromise weeks or months after it happened, usually from an embarrassing outside source: a customer, a browser warning, or a plummeting traffic graph.
Here are the signs worth knowing, how to confirm a suspicion, and what to do in the first hours if you find something.
The signs, from loud to quiet
Warnings other people see first
- Browser interstitials. Chrome or Safari showing "Deceptive site ahead" or "This site may harm your computer" means Google has already flagged you, and traffic is already collapsing.
- Search result labels. Google appending "This site may be hacked" to your listings, or your pages suddenly ranking for pharmaceuticals and casinos.
- Blacklist appearances. Your domain or IP turning up on spam and malware blocklists, which also torpedoes your email deliverability.
Changes on the site itself
- Content you did not write. Spam keywords, hidden links in the footer, new pages you never created (check Google with a
site:yourdomain.comsearch for anything unfamiliar). - Redirects that only hit some visitors. A classic trick: mobile visitors arriving from Google get redirected to a scam site, while the owner, typing the URL directly on desktop, sees everything as normal.
- New admin users, plugins or files. An administrator account you do not recognise, or PHP files with odd names in upload directories.
Behavioural tells
- Traffic anomalies. A sudden ranking drop, or the opposite: unexplained traffic to pages that should not exist.
- Resource spikes. Hosting suddenly slow or hitting CPU limits because the server is busy sending spam or mining.
- Email trouble. Messages bouncing or landing in spam because the compromised server got your domain blocklisted.
How to confirm it
- Check Google's verdict. Search Console (if the site is verified) shows security issues explicitly, and the Safe Browsing status page gives a public answer for any URL.
- Search yourself the way strangers find you. A
site:search plus obvious spam terms, and a visit from a mobile device via a search result click, catches cloaking and conditional redirects that a direct visit never will. - Scan the site. Run a malware scan against the live site, and if you have server access, look for recently modified files, unfamiliar scheduled tasks and unknown admin accounts.
- Check what changed. If you run content monitoring, its change history often pinpoints both what was injected and when, which shortens the whole investigation.
The first hours: contain, clean, prove it
- Change every credential. CMS admins, hosting panel, FTP/SSH, database. Assume they are all burned; attackers plant multiple ways back in.
- Take stock before you wipe. Note what you found and when; if personal data may be involved you will need this record.
- Clean or restore. The most reliable route is restoring from a backup that predates the compromise, then immediately patching whatever let the attacker in (an outdated plugin is the usual suspect). Cleaning in place is possible but easy to get wrong; compromised sites that "come back" were usually never fully cleaned.
- Close the door. Update the CMS, themes and plugins, remove anything unused, and rotate API keys and integration secrets the site held.
- Request reviews. Once clean, request a Safe Browsing review via Search Console and delisting from any blocklists, and monitor until the flags clear.
- Consider your legal duties. If personal data was accessible, UK GDPR may require reporting to the ICO within 72 hours of becoming aware, and telling affected users if the risk to them is high. Our website compliance guide covers where these duties come from.
Finding out in hours instead of months
Every part of the recovery above gets cheaper the earlier the compromise is caught, and this is one problem an uptime check will never see: the hacked site is up the entire time. Detection is a layered job:
- Malware monitoring checks Google's threat lists for your domain twice a week, so you hear about a flag from an alert, not from a customer.
- DNS monitoring and admin-account alerts from the WordPress plugin catch the changes attackers make to keep their access.
- Content checks alert when a keyword you choose appears on a page, so a rule for the spam words attackers favour can catch injected text, and visual monitors show when a key page changes.
- Security scans find the weaknesses, the outdated software and exposed services, before someone else does.
TLDTrack does all of this from one dashboard, alongside the uptime, SSL and DNS layers covered in our complete guide to monitoring client websites. For an agency, the difference is stark: "we detected and fixed it the same day" is a story that builds trust; "your customer found it" is one you only get to tell once. Once a site is clean, our guide to monitoring a website after a hack lists exactly what to switch on.
