Start your 7-day free trial, card not charged until it ends

Security

How to Know If Your Website Has Been Hacked (and What to Do Next)

· 8 min read

You can usually tell a website has been hacked from a browser warning, odd search results, a new admin account, changed DNS records or pages you did not write. Most hacked sites look normal, so here are the signs, how to confirm one, and what to do in the first hours.

By the TLDTrack team, part of FullyCoded, a working UK web agency.

Most hacked websites do not look hacked. The era of defaced homepages is largely over; a compromised site is worth far more to an attacker while it looks completely normal, quietly serving spam links, hosting phishing pages in a forgotten subdirectory, or redirecting a slice of visitors somewhere profitable. Site owners routinely discover a compromise weeks or months after it happened, usually from an embarrassing outside source: a customer, a browser warning, or a plummeting traffic graph.

Here are the signs worth knowing, how to confirm a suspicion, and what to do in the first hours if you find something.

The signs, from loud to quiet

Warnings other people see first

  • Browser interstitials. Chrome or Safari showing "Deceptive site ahead" or "This site may harm your computer" means Google has already flagged you, and traffic is already collapsing.
  • Search result labels. Google appending "This site may be hacked" to your listings, or your pages suddenly ranking for pharmaceuticals and casinos.
  • Blacklist appearances. Your domain or IP turning up on spam and malware blocklists, which also torpedoes your email deliverability.

Changes on the site itself

  • Content you did not write. Spam keywords, hidden links in the footer, new pages you never created (check Google with a site:yourdomain.com search for anything unfamiliar).
  • Redirects that only hit some visitors. A classic trick: mobile visitors arriving from Google get redirected to a scam site, while the owner, typing the URL directly on desktop, sees everything as normal.
  • New admin users, plugins or files. An administrator account you do not recognise, or PHP files with odd names in upload directories.

Behavioural tells

  • Traffic anomalies. A sudden ranking drop, or the opposite: unexplained traffic to pages that should not exist.
  • Resource spikes. Hosting suddenly slow or hitting CPU limits because the server is busy sending spam or mining.
  • Email trouble. Messages bouncing or landing in spam because the compromised server got your domain blocklisted.

How to confirm it

  1. Check Google's verdict. Search Console (if the site is verified) shows security issues explicitly, and the Safe Browsing status page gives a public answer for any URL.
  2. Search yourself the way strangers find you. A site: search plus obvious spam terms, and a visit from a mobile device via a search result click, catches cloaking and conditional redirects that a direct visit never will.
  3. Scan the site. Run a malware scan against the live site, and if you have server access, look for recently modified files, unfamiliar scheduled tasks and unknown admin accounts.
  4. Check what changed. If you run content monitoring, its change history often pinpoints both what was injected and when, which shortens the whole investigation.

The first hours: contain, clean, prove it

  1. Change every credential. CMS admins, hosting panel, FTP/SSH, database. Assume they are all burned; attackers plant multiple ways back in.
  2. Take stock before you wipe. Note what you found and when; if personal data may be involved you will need this record.
  3. Clean or restore. The most reliable route is restoring from a backup that predates the compromise, then immediately patching whatever let the attacker in (an outdated plugin is the usual suspect). Cleaning in place is possible but easy to get wrong; compromised sites that "come back" were usually never fully cleaned.
  4. Close the door. Update the CMS, themes and plugins, remove anything unused, and rotate API keys and integration secrets the site held.
  5. Request reviews. Once clean, request a Safe Browsing review via Search Console and delisting from any blocklists, and monitor until the flags clear.
  6. Consider your legal duties. If personal data was accessible, UK GDPR may require reporting to the ICO within 72 hours of becoming aware, and telling affected users if the risk to them is high. Our website compliance guide covers where these duties come from.

Finding out in hours instead of months

Every part of the recovery above gets cheaper the earlier the compromise is caught, and this is one problem an uptime check will never see: the hacked site is up the entire time. Detection is a layered job:

  • Malware monitoring checks Google's threat lists for your domain twice a week, so you hear about a flag from an alert, not from a customer.
  • DNS monitoring and admin-account alerts from the WordPress plugin catch the changes attackers make to keep their access.
  • Content checks alert when a keyword you choose appears on a page, so a rule for the spam words attackers favour can catch injected text, and visual monitors show when a key page changes.
  • Security scans find the weaknesses, the outdated software and exposed services, before someone else does.

TLDTrack does all of this from one dashboard, alongside the uptime, SSL and DNS layers covered in our complete guide to monitoring client websites. For an agency, the difference is stark: "we detected and fixed it the same day" is a story that builds trust; "your customer found it" is one you only get to tell once. Once a site is clean, our guide to monitoring a website after a hack lists exactly what to switch on.

01 · Questions

Frequently asked questions

Will Google tell me if my website has been hacked?

Sometimes, eventually. If the site is verified in Search Console you will get security issue notifications, and Google may flag the site in Chrome and label it in results. But that detection can take weeks, and by the time it happens your traffic is already being punished. Treat Google as a backstop, not as your detection system.

My website looks completely normal. Could it still be hacked?

Yes, and that is the most common case. Attackers use cloaking (spam content shown only to search crawlers), conditional redirects (only mobile visitors from search get sent elsewhere) and hidden pages in subdirectories, precisely so the owner sees nothing. Check with a site: search on Google, visit via a search result on a phone, and watch for content and script changes you did not make.

Do I have to report a hacked website?

If personal data was accessible, UK GDPR requires reporting the breach to the ICO within 72 hours of becoming aware, unless the risk to individuals is unlikely, and telling affected people directly when the risk is high. If card payments are involved, your payment provider's rules add further obligations. A hack that touched no personal data has no general reporting duty, but keep records of what you found either way.
Mark Grice, founder of TLDTrack

Mark Grice, founder of TLDTrack. Runs FullyCoded, a Cornwall web agency, and built this to keep 500+ client sites in front of him every day.

What happens next

Put this on autopilot

Do it yourself

Start your free trial

TLDTrack runs every check in this guide automatically across all your client sites and alerts you the moment something changes. Your card is not charged for 7 days.

Start your free trial

Talk it through

Arrange a call with Mark

If you would rather talk through how this works across every site you look after, we can go through it together.

Book a call

See every check TLDTrack runs