forumNew topic

Someone else got hold of the hosting control panel admin password, I need to change it immediately but I can't log in

AAslı U***MemberCommunity member
Joined
Apr 2026
Message
61
#1

I remember my username but the password has changed. I click the forgot password link, no email comes. I wrote to the hosting company, they said I'd have to wait 24 hours. During this time the hacker could delete server files, steal database backups, but I don't know what they'll do — how do I get emergency treatment?

Is there any other management tool on the server side? WinSCP, SSH, another control panel? Or am I really doomed to wait 24 hours?

Worst case scenario: if the server is fully compromised, and the hosting provider's backup system has also been hacked and wiped, leaving you with nothing but a blank slate, what do you recommend? Do I need to migrate to a new host?

SSelin K***Member
Job title
QA Tester
Sector
Education
Organization type
120-person company
Joined
Jan 2026
Message
254
Most Helpful#2

Quick steps for emergencies: 1) Call your hosting provider directly, ask for urgent support via ticket (24 hours is way too long), 2) If your email account hasn't been hacked, check it — see if any other accounts were created, 3) If you have SSH access, you can reset the password (if you have root access). For example, log into cPanel via SSH and run this command: 'whmapi1 passwd_pop account=USERNAME newpass=NEWPASS', 4) Ask the hosting provider if there are any other management tools. 5) The backup management system usually has a separate interface (Backup Wizard etc.), check that. After changing all your passwords, if it's been 7+ days and the hacker stole files, check these.

AAslı Ç***Member
Job title
Production planning
Sector
Consulting
Organization type
300-person organization
Joined
Dec 2025
Message
124

Doki · KVKK compliance consulting · 2026

#3

happened to me recently too the hacker chagned the panel password. when i went to cpanel i just clicked send recovery email and moved on it arrived 30 mins later. but u should call them try chat support a few times...

VVolkan G***MemberCommunity member
Joined
Jul 2022
Message
81
#4

if u have ssh root access, u can update the mysql user password with a password hash using an antivirus product: UPDATE mysql.user SET Password=PASSWORD('newpass') WHERE User='root'; FLUSH PRIVILEGES;. otherwise u can run the WHM API or an antivirus product script in cPanel. but if the hacker already reached root, the server is fully compromised. check the logs, bind.log, secure log etc.

BBurak B***Veteran
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
252
#5

hosting providers really move slow in these situations. but if u can access ssh its a bit easier. u can change the root password. or do sudo su and type passwd root. but if they accessed the whole server theres malware too — just format and reinstall, be done with it.

AAycan D***MemberCommunity member
Joined
Oct 2024
Message
240
#6

do u have ssh access? if u have root access: ssh root@[IP], passwd [enter] enter new password, confirm. if u only have user access: sudo su passwd new password. the hosting provider's panel is secondary server access is what matters. if u have no ssh access at all, u might have to call the hosting provider. it's recommended to check logs: /var/log/auth.log, /var/log/secure (Red Hat systems), these show who logged in.

KKübra M***Member
Job title
Accounting Manager
Sector
Consulting
Organization type
early-stage startup
Joined
Oct 2023
Message
140
#7

bro u're talking too fast, just because the admin panel password changed does that mean the whole server is compromised? or is it just the cPanel password? if u can still log into ssh it's still yours. first step: log into ssh enter bash, become root. then let's see...

EElif G***ExpertCommunity member
Joined
Mar 2025
Message
3
#8

How did you solve this? Your time to detect an issue directly determines its cost.

If 2FA is on, a stolen password alone is useless. Im also curious if anyone does it differently.

JJale G***Member
Job title
Data entry clerk
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Apr 2025
Message
27
#9

i didnt know that.

MMustafa G***Member
Job title
Purchasing manager
Sector
Furniture manufacturing
Organization type
medium-sized business
Joined
Dec 2022
Message
72
#10

This thread is archived.

CCeren A***Expert
Job title
IT Manager
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Jun 2024
Message
263
#11

I'm a small business, let me explain from my side. If you scold false alarms, nobody will report again.

SSenaMember
Job title
Graphic Designer
Organization type
two-branch business
Joined
Jul 2024
Message
86
#12

looking at it as a process, the picture changes. everything goes well for the first three months; problems arise in the fourth.

that's all, sory if I went on too long.

BBurak A***MemberCommunity member
Joined
Dec 2023
Message
39
#13

let me write how it's done in practice. having backups accessible on the same network and with the same identity makes them part of the target.

AAleyna S***Member
Job title
Export manager
Sector
E-commerce
Organization type
medium-sized business
Joined
Aug 2024
Message
3
#14

Let me speak from the other side; I'm on the supplier side. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Most incidents start with a leaked password, not a vulnerability. Of course, it varies if your situation is different.

MMustafa G***VeteranCommunity member
Joined
Jul 2022
Message
379
#15

I went through the same thing two years ago. When making decisions write down the worst-case scenario too, not just the best.

DDamla Y***ExpertCommunity member
Joined
Feb 2025
Message
57
#16

Saved.

MMustafa A***Member
Job title
Regional Manager
Sector
Paper
Organization type
cooperative
Joined
Mar 2023
Message
37
#17

There's a trap here, let me mention it. If you scold false alarms, nobody will report again.

Just leaving this note, it might be useful.

MMurat K***Member
Job title
SaaS developer
Organization type
boutique agency
Joined
Mar 2024
Message
118

Doki · Log management setup · 2025

#18

Three different views emerged, they all complement each other... tbh having backups accessible on the same network and with the same identity makes them part of the target.

If the notification path is long, notifications dont arrive; missing notifications mean delayed incident detection. anyway this is my opinion, Im not claiming its absolute truth.

MMerve K***Member
Job title
Supply chain manager
Sector
Retail
Organization type
a company within a holding
Joined
Apr 2025
Message
328

Doki · Infrastructure migration · 2026

#19

The discussion got scattered let me summarize. btw forgotten test environments are more often the entry point than live systems.

HHilal Y***Expert
Job title
Accounting Manager
Sector
Catering
Organization type
chain store
Joined
Aug 2025
Message
66
#20

I've been dealing with this for a long time. Payment information changes are never verified through the channel they came from.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection. Just leaving this note, it might be useful.

Reply