Blog

Is your website hacked? 8 signs to check right now

Someone messaged you that your site redirected them to a strange page. Or your store’s sales suddenly dropped to zero. Or you found a search result you don’t recognise. The first reaction is panic, but it isn’t necessary: most hacks are automated and slow, not a personal attack on you, and most can be confirmed or ruled out in five minutes.

Run through these 8 checks in order. If one or two come back yes, it’s worth digging further. If four or more do, act now.

1. Unexpected redirects

Open the site in a private window and on your phone. Does your homepage sometimes redirect to a strange ad, a casino, or some other site you don’t recognise? Hacked sites often redirect only certain visitors (say, mobile users or people coming from search) so the owner never sees it happen.

2. New admin users

Open the user list in your content management system. Are there accounts you didn’t create, or accounts with administrator rights you don’t remember setting up? This is one of the clearest signs someone has gained access to the site.

3. A Google Search Console warning

If you have Search Console set up, check it. Google flags sites carrying malware and notifies the owner when it detects something suspicious. If you haven’t set up Search Console yet, it’s worth doing now, because it’s the first place you’ll hear about a problem, before you lose a client over it.

4. Unfamiliar files on the server

Check your file manager or FTP. Are there files with names that look random (like wp-tmp2.php or a string of characters), or files sitting in folders where none of your own files belong? This is a common way attackers leave themselves a backdoor.

5. Server load that doesn’t match your traffic

If your hosting dashboard suddenly shows much higher CPU usage or bandwidth, but your own traffic numbers haven’t grown, something may be running on the server without your knowledge: cryptocurrency mining, spam sending, or a script scanning other sites.

6. Spam in search results

Search Google for site:yourdomain.com together with words like “viagra”, “casino” or “replica”. If pages show up in search results that you never created but carry your domain, that’s classic SEO spam: an attacker has added hidden pages to your site to lure in search engines.

7. A browser “not secure” warning

If Chrome or another browser shows a red warning about malware or phishing before the site loads, that’s the most direct sign of all. It means Google or the browser maker has already blacklisted the site, so some visitors never reach it at all.

8. Unexpected outbound emails or traffic

If your hosting panel shows a large volume of emails being sent from the server that you didn’t send, or a security plugin logs strange outbound connections, the server is likely sending spam or talking to an attacker’s control server.

What to do if a sign checks out

Don’t go hunting for the root cause yourself if you’re not sure what you’re doing: a botched “cleanup” leaves the backdoor in place and the problem comes back a couple of weeks later. The right order is:

  1. Back up the current state, even though it’s infected. You may need it later for investigation.
  2. Have the site cleaned by someone who knows where to look for backdoors, not just how to delete the obvious message.
  3. Change every password (hosting, CMS, FTP, database) right after the cleanup. A password changed before it can leak straight back to the attacker.
  4. If Google flagged the site, request a review in Search Console so the warning gets lifted.

If one of these eight signs applied to you, start with a hacked website cleanup. If your site is currently clean and you want to keep it that way, see the cybersecurity services or write to me and describe what you noticed. I’ll tell you honestly whether there’s cause for concern.