How do I know my website was actually hacked?
Common signs: your browser or search engine warns visitors about the site,
pages you never wrote appear in search results, the site redirects
somewhere else on mobile only, admin users exist that nobody created, or
your host emails you about abuse. Any one of these deserves a proper look.
Should I just restore a backup?
Only after you know how they got in. Restoring puts back the same
vulnerable version, and if the backup was taken after the compromise it
may contain the attacker's files too. Find the entry point first, then
restore or rebuild.
Will this hurt my Google ranking?
It can, especially if the site was flagged as unsafe or used to host spam
pages. Cleaning it up quickly, removing the injected content, and
requesting a review through Google Search Console is the recovery path.
The longer it stays compromised, the longer that takes.
Do I have to tell my customers?
If personal data may have been exposed, many jurisdictions require
notification within a set time, sometimes to a regulator as well as to the
people affected. That is a legal question — take advice early rather than
deciding on your own under pressure.
Can a security plugin clean it for me?
Scanners are useful for detection and for finding obvious injected code.
They cannot prove a server is clean, and they don't tell you how the
attacker got in. Treat a clean scan as encouraging, not as an all-clear.
Can you fix it for me?
We can help you contain it, work out how it happened, and rebuild the site
so it doesn't recur. Get in touch with what you've seen so far and when you
first noticed it — and follow the checklist above in the meantime, because
those steps matter more than who does them.