Guide · 2026-07-20

Website Hacked? First Aid and Prevention

Suddenly your website shows pharma spam, Google warns visitors about your domain, or your hosting provider has taken the site down: a hack usually catches small businesses completely off guard. The good news: with the right steps, the damage can almost always be contained. This guide covers what to do in the first hours, which notification duties apply in Germany — and how to prevent a second incident.

Illustration: browser window with a broken shield and warning symbol, next to a wrench and a life ring — symbolising first aid after a website hack

How do I know my website has been hacked?

Not every hack is obvious. Some attackers deface the homepage, but most deliberately stay under the radar: they hide spam links in the source code, redirect visitors to shady shops or send phishing emails through your server. Typical warning signs are unexplained redirects, unfamiliar content or new admin users nobody created.

Often the alert comes from outside: Google flags the page in search results with “This site may be hacked”, the browser shows a red warning screen, your host reports suspicious traffic, or customers mention strange emails. Take these signals seriously — the longer malicious code stays active, the greater the damage to rankings and reputation.

First aid: what to do in the first 24 hours

Step one: take the website offline temporarily or switch it to maintenance mode. This protects your visitors from malware and stops the spread. Inform your hosting provider or web agency immediately — good providers have processes for exactly this case and can secure log files before traces are lost.

Document the incident: screenshots, time of discovery, affected areas. You will need this later for a possible report to the data protection authority, for insurance or a criminal complaint. And check from a clean device whether your email accounts or other services sharing the same password could be affected.

  • Take the site offline or enable maintenance mode
  • Inform your host or website manager, have log files secured
  • Change all passwords: admin, FTP, database, hosting panel, email
  • Document the incident with screenshots and timestamps
  • Scan your own computer for malware — it is often the entry point

Cleanup: restore a backup or remove the malicious code

The safest way back is a clean backup from before the attack — which is why regular, externally stored backups matter so much. Before restoring, however, the vulnerability the attacker used must be closed, otherwise they will be back within days. Afterwards: change all credentials again and update every piece of software.

If no usable backup exists, the malicious code has to be removed manually. Free scanners such as Sucuri SiteCheck give a first assessment but do not replace a thorough audit — attackers like to leave several backdoors. For non-experts this is barely feasible; professional cleanup typically costs from a few hundred to over a thousand euros depending on scope. With a managed website subscription, cleanup and recovery are the provider’s job.

Notification duties: when GDPR and the police come into play

If personal data was compromised — customer data from a contact form, customer accounts or a newsletter list — Article 33 GDPR applies: you must report the breach to the competent data protection authority within 72 hours of becoming aware of it, provided there is a risk to the individuals affected. In high-risk cases, such as leaked credentials or payment data, Article 34 additionally requires notifying the affected persons directly. Violating the notification duty can cost more than the hack itself.

Independently of that, you can file a criminal complaint: every German federal state runs a central cybercrime contact point (ZAC) for businesses. A complaint also helps with insurance and documentation. The BSI, Germany’s federal IT security agency, publishes free checklists and first-aid documents for IT security incidents — a good way to judge whether you can handle the incident on your own.

Removing the Google warning and saving your reputation

If Google detected malware on your site, the domain ends up on the Safe Browsing list — browsers like Chrome and Firefox then display a full-screen red warning. For visitors this is a total outage, even if the site is technically running again. The warning does not disappear on its own: after a complete cleanup, request a review in Google Search Console under “Security issues”.

The review usually takes a few days. Important: clean up first, then request the review — if malicious code is still found, the block is extended. Ranking losses from a hack usually recover once the site is and stays clean. Communicate openly and factually with affected customers; a well-managed incident damages trust far less than silence.

Prevention: how to avoid getting there in the first place

The vast majority of hacks on small websites are not targeted attacks but automated mass scans for known weaknesses — outdated CMS versions, vulnerable plugins, weak passwords. That is exactly why prevention works so well: keep software current, use unique passwords with two-factor authentication and maintain regular external backups, and you are simply no longer a worthwhile target for bots.

The honest question is: who takes care of this — every week, year in, year out? With a self-managed WordPress installation, that is you. With a managed website subscription like ours (from €79 per month), updates, security, backups and monitoring are part of the package — and if something does happen, there is someone responsible for fixing it instead of someone to blame.

  • Update CMS, plugins and themes promptly — the most common entry point
  • Unique, long passwords plus two-factor authentication for all admin access
  • Automatic backups in an external location, tested for restorability
  • Consistently delete unused plugins, themes and user accounts
  • SSL, a current PHP version and a host with security monitoring

Frequently asked questions

Do I have to report a website hack to the data protection authority?

+

How much does cleaning up a hacked website cost?

+

How long until the Google warning disappears?

+

Why was my small website hacked of all things?

+

Is a security plugin enough protection?

+

Website subscription — from €79/month

Custom web design, German hosting, maintenance and personal support in one monthly package.

Book a free consultation

← All guide articles