Skip to content
Soofi Websites · SEO · Marketing
August 4, 2026

Your website has been hacked. What actually happens next.

Most owners find out from someone else. A customer mentions the site “looked strange on their phone”. Google Search Console sends a security notice. Or the site simply stops appearing for its own name. By the time anyone notices, the problem is usually weeks old.

What a compromised site actually looks like

The films have this wrong. Nobody defaces a plumbing company’s website with a skull. An attacker who defaces your site loses the thing they broke in for, which is your domain’s reputation with Google. So the good ones hide.

In practice a compromise usually shows up as one of these:

  • Hidden text stuffed into a page. Paragraphs of links to gambling or pharmacy sites, pushed off-screen with a line of CSS so a human never sees them. Google does.
  • Cloaking. The site behaves normally for you, and redirects somewhere else for visitors arriving from a Google search on a phone. This is why “it looks fine to me” means very little.
  • Spam pages you never created. Hundreds of them, often in another language, all linking to each other.
  • A quiet back door. No visible symptom at all — just a file that lets someone back in whenever they want, including after you “fix” it.

Why you cannot see it

Two reasons. First, a lot of injected content is served only to logged-out visitors, or only to Google’s crawler, precisely so the owner does not trip over it. Second, if you have a caching plugin, you and your visitors may be looking at entirely different copies of the same page.

The reliable test is not to look at your site. It is to search Google for site:yourdomain.com and read the results. If there are pages in there you did not write, you have your answer.

Why editing the page does not fix it

This is the part that costs people the most time. You open the page in your page builder, hunt for the spam text, and it is not there. So you assume you have found nothing and move on.

What is happening is that the injected content sits underneath the layer you are editing. The page builder stores your page as structured data, and the malicious code is added after that data is turned into a web page, on its way out to the browser. Editing the page in the builder is like repainting a wall to deal with a leak behind it. The page will look clean in the editor and still serve spam to Google an hour later.

The same logic applies to restoring a backup. If the backup is newer than the break-in, you are restoring the compromise along with everything else. And if the door is still open, a restored site gets reinfected within days.

How they got in

Almost never by guessing your password. In our experience the common routes are, in order:

  • Plugins and themes obtained outside the official channels. A paid plugin downloaded free from a “nulled” site is the single most reliable way to get compromised. The modification that removes the licence check is the payload.
  • A plugin that has not been updated in years. Once a vulnerability is published, scanning the whole internet for sites still running the old version takes hours, not months.
  • An abandoned subdomain or a forgotten staging copy that nobody patches because nobody remembers it exists.

What a proper cleanup involves

Finding and deleting the visible spam is the easy part and the least important. A cleanup that holds needs to: identify how the attacker got in and close it; find every modified core, theme and plugin file and compare it against a known-good copy; remove back doors, including scheduled tasks and database-level ones; rotate the credentials the attacker may have taken; update everything; and then ask Google to re-check the site so the warning comes off.

It also needs someone to look again a week later, because reinfection is the normal failure mode.

What we charge for this

Hacked website cleanup is $350 flat. Your site is clean within 48 hours, and if it is reinfected within 30 days we clean it again at no charge — which is really a way of saying that if we only removed the symptom, that is our problem to fix, not yours.

If you would rather this never came up again, our care plans start at $99 a month and cover the updates, backups and monitoring that prevent most of it.

Want a second opinion on your own site?

Send us the address and a person will look at it properly, then email you what they find. Free, and there is nothing to buy at the end of it.

Let's build something your customers will use

A free 30-minute call, then a fixed written quote. No pressure and no jargon.

Enquiries answered 24/7 by our assistant · a person replies within one business day · No obligation, and no sales script.