If you think your website has been hacked, take these steps right away:
Step 1: Change Your Passwords
- Log into cPanel and change all passwords immediately:
- cPanel password
- Email account passwords
- FTP account passwords
- Database user passwords
- WordPress/Joomla/etc. admin passwords
- Check when your site was last modified using File Manager in cPanel. Look for recently changed files.
Step 2: Restore from Backup
The fastest way to clean a hacked site is to restore from a clean backup:
- Go to Backups in cPanel.
- Restore your home directory and database from a date before the hack.
Step 3: Scan and Secure
- Use cPanel's Site Quality Monitoring or a plugin like Wordfence (for WordPress) to scan for malware.
- Update all software to the latest versions.
- Remove any unknown admin users from your CMS.
Step 4: Open a Support Ticket
If you need help, open a support ticket. We can help find how the breach happened and suggest ways to secure your site.
Prevention: Keep your CMS, plugins, and themes updated. Use strong passwords. Avoid nulled themes and pirated plugins.