If your website is hacked, do not simply restore a backup and assume the problem is solved. The priority is to contain the compromise, identify how the attacker got in, protect administrator credentials, preserve useful evidence, restore from a known-clean state, and close the weakness that caused the incident.
Signs Your Website May Be Compromised
- Unexpected redirects
- Unknown administrator accounts
- Spam pages or strange search results
- Modified files
- Malware warnings
- Unexplained traffic spikes
- Customers reporting suspicious checkout behavior
- Plugins or themes installed without authorization
- Hosting or security alerts
1. Contain the Incident
If the site is actively harming users, redirecting visitors, stealing credentials, or serving malware, consider temporarily restricting public access while the incident is investigated. Coordinate with your hosting provider if you do not control the infrastructure directly.
2. Protect Administrator Accounts
Change passwords for website administrators, hosting, domain registrar, database access, deployment tools, CDN, email accounts, and other connected services if compromise is possible. Use a known-clean device and enable MFA wherever available. Remove unknown users and revoke old sessions.
3. Preserve Evidence
Keep copies of suspicious files, security alerts, access logs, timestamps, screenshots, unknown usernames, IP addresses, changed DNS records, malicious pages, and notices from search engines or hosts. Evidence can help identify the cause and support reporting if the incident involves fraud, cybercrime, or personal data.
4. Find the Entry Point
Common entry points include outdated plugins or software, reused passwords, stolen administrator credentials, insecure hosting accounts, exposed API keys, vulnerable themes, and compromised employee devices. If the cause is not fixed, a restored site may be hacked again.
5. Restore From a Known-Clean Backup
Use a backup that predates the compromise and verify that it does not contain the same malicious files or vulnerable components. Update the platform, themes, plugins, dependencies, and credentials before fully reopening the site.
6. Check Whether Personal Data Was Exposed
If the site stores customer, employee, subscriber, payment-related, or other personal information, investigate whether that data was accessed or copied. A hacked website can become a personal-data breach even if the visible website appears normal.
See Data Breach Response Checklist Philippines and Data Breach Notification Philippines.
7. Prevent Reinfection
- Keep CMS software and plugins updated.
- Remove unused plugins, themes, accounts, and staging sites.
- Use MFA for admin and hosting accounts.
- Limit administrator privileges.
- Keep off-site backups.
- Use supported software.
- Monitor file changes and login activity.
- Protect developer and deployment credentials.
Last materially reviewed: September 3, 2026
Direct Answer
If a website is hacked, the priority is to contain the compromise, preserve evidence, reset exposed credentials, patch the vulnerability that allowed access, restore from a known-good backup when appropriate, and monitor for reinfection. If personal data may have been exposed, the incident may also trigger Philippine Data Privacy Act breach-assessment and notification duties.
Primary guidance: CISA website-security guidance. If personal data may have been exposed, also see NPC Breach Reporting.
Key Takeaways
Contain first. Stop the attacker from maintaining access. Preserve evidence. Save logs, timestamps and indicators before wiping systems. Fix the entry point. Restoring a backup without patching the cause can lead to reinfection. Assess data exposure. A website compromise involving personal data may create separate privacy obligations.
Frequently Asked Questions
Should I immediately delete a hacked website?
Usually no. Preserve logs and other evidence first, then contain the compromise. Immediate deletion can destroy information needed to understand how the attack happened.
When should a hacked website be reported as a data breach?
Assess whether personal data was accessed or acquired without authorization and whether the National Privacy Commission’s breach-notification criteria are met. Not every website compromise automatically requires breach notification.
Official Sources
CISA — Website Security Guidance
National Privacy Commission — Breach Reporting
Decision Snapshot
| If you see… | Do this first |
| Malware warning | Restrict exposure and investigate |
| Unknown admin account | Secure admin and hosting credentials |
| Spam pages in Google | Check files, database and search-console warnings |
| Customer data may be exposed | Start a privacy-breach assessment |
| Site keeps getting reinfected | Find the original entry point before restoring again |
