forumNew topic

WordPress site hacked, entire database encrypted, no password — what if I ignore it and reinstall?

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#1

Got a warning email last night, admins entered the password wrong several times (started with fail2ban). Then when I tried to enter my site in the morning, admin panel doesn't open, database isn't working.

Hosting company said 'database encrypted', what does encrypted even mean? Nobody gave me any instructions. I asked if they had backups, they said only 7-day backups. If I restore from this 7-day backup, will the hacker still be inside? Or should I install a fresh WordPress and create a dedicated database, getting rid of all the bad stuff?

I don't care if the posts, customer info etc. are gone, I just want it back online. Is there a quick fix?

MMelis Ö***Expert
Job title
Social media manager
Sector
E-commerce
Organization type
120-person company
Joined
Feb 2022
Message
14

Doki · Log management setup · 2025

Most Helpful#2

Database password isn't normal encryption — the database is protected on the server. It means you can't access the database file yourself. If you do a fresh install: 1) Delete the old database from the hosting control panel, 2) Create a new database and user, 3) Install WordPress from scratch. However, if the hacker got in way before the 7-day backup, you can restore; if they got in within the last 7 days, restoring from backup brings the same problem. Before checking the 7-day backups, check the access logs (access.log) — you'll see when they logged in. Restore a backup from before that date.

DDamla M***Member
Job title
Field sales representative
Sector
Real estate
Organization type
medium-sized business
Joined
Jul 2025
Message
63

Doki · Mobile app · 2023

#3

do a fresh install bro this is too hard start from scratch. anyway if the db password is cracked check with security team but hosting restore is for the rescue...

KKübra G***Member
Job title
Field sales representative
Sector
Law
Organization type
medium-sized business
Joined
Mar 2024
Message
7
#4

Database is protected; good news, if access is lost you can recover from backup. Check the MySQL dump, if there's shell code in base64 that backup is dirty too. If you have SSH access, cross-check file timestamps with access.log — find the compromise date, grab the newest backup from before that.

HHüsniye Ç***MemberCommunity member
Joined
Oct 2024
Message
17
#5

bro there's a lot to do but it's not that complicated and once aain — restore from the 7-day backup, then review plugins. delete any weird plugins. and what you need to do now: change all passwords FTP MySQL, cPanel all of them. and install fail2ban, let's see...

SSena Ç***Member
Job title
General Manager
Sector
Education
Organization type
family business
Joined
Jun 2025
Message
257
#6

WordPress sites are usually compromised due to plugin vulnerabilities or weak passwords. Do these steps: 1) Identify the oldest clean backup, 2) Download it, 3) Check on local machine (virus scan, file hashes), 4) Restore, 5) Update all plugins, 6) Change all passwords (DB user, FTP, cPanel, WordPress admin), 7) Install a WP Security plugin, 8) Monitor for two weeks, if it gets hacked again backup the database — this time switch to a new hosting.

ÖÖzge A***Member
Job title
Front office accounting
Sector
Chemistry
Organization type
300-person organization
Joined
Feb 2026
Message
357

Doki · Incident response support · 2023

#7

even the biggest companies get their wordpress sites hacked but you got hacked too? welcome to the club 😂 learn your lesson change your password install an ssl cert and youll be good.

ŞŞerife K***Veteran
Job title
Clinic manager
Sector
Electrical-electronics
Organization type
early-stage startup
Joined
Dec 2023
Message
128
#8

We experienced almost the exact same thing last year. Hasty decisions become decisions you have to fix six months later.

If permission and scope aren't in writing, don't start that test. I'm also curious if anyone does it differently.

MMurat B***New member
Job title
Customer service representative
Sector
Seafood
Organization type
cooperative
Joined
Jun 2026
Message
123
#9

You're right, I've been down that road too. If you don't write this down from the start, it leads to arguments later.

If you post the result here, it will help others too.

RRıdvan K***MemberCommunity member
Joined
Oct 2024
Message
77
#10

I was thinking the same thing. Don't hesitate to ask; those who don't ask always pay more.

That's all sorry if I went on too long.

UUfuk B***MemberCommunity member
Joined
Sep 2024
Message
114
#11

Ive been down this road let me tell you. The biggest time-waster for us was not knowing who had the final say.

This is my opinion, I'm not claiming it's absolute truth.

MMeryem Ö***Member
Job title
Export manager
Sector
Cleaning services
Organization type
40-person manufacturing company
Joined
Feb 2024
Message
13
#12

Saved.

HHasan K***MemberCommunity member
Joined
Apr 2023
Message
221
#13

I disagree with you on this point. Mistakes made on the wordpress hacked what to do side are usually reversible but expensive.

If you get three different answers on a topic, the question was asked wrong. If you have questions, write them; Ill answer as best I can.

HHilal D***MemberCommunity member
Joined
Dec 2024
Message
166
#14

This approach has a cost, which isn't discussed. Don't rely on a single measure; go layer by layer.

Hope this helps.

KKader Y***Member
Job title
Front office accounting
Sector
Software
Organization type
300-person organization
Joined
Aug 2025
Message
34
#15

Exactly like that. Don't hesitate to ask; those who don't ask always pay more.

Forgotten test environments are more often the entry point than live systems. This is my opinion, I'm not claiming it's absolute truth.

DDamla K***MemberCommunity member
Joined
Aug 2025
Message
1
#16

Let me summarize what's been said so far. Most time waste accumulates in tasks waiting for approval.

If permission and scope aren't in writing, don't start that test.

YYavuz B***Member
Job title
Human Resources Specialist
Sector
Leather
Organization type
120-person company
Joined
Mar 2024
Message
5
#17

My questions are cleared up, thanks. Solutions that work at a small scale collapse when you grow; I learned this late.

An automated scan report is not the same as a penetration test. Proven by experience.

TTolga G***Veteran
Job title
Secretary
Sector
Plastic
Organization type
regional distributor
Joined
Jan 2024
Message
138
#18

the answer above hits the nail on the head then if you dont write this down from the start it leads to arguments later.

ZZübeyde D***Member
Job title
Marketing director
Sector
Freight
Organization type
300-person organization
Joined
Mar 2024
Message
174
#19

There's one point I'm curious about. Payment information changes are never verified through the channel they came from.

I'm also curious if anyone does it differently.

CCaner K***VeteranCommunity member
Joined
May 2023
Message
21
#20

You're right, I've been down that road too. The harder it is to reverse a decision, the slower you should make it.

Proven by experience.

Reply