forumNew topic

Website got hacked and is redirecting visitors — what should we do in the first hour?

MMehmet C***Member
Job title
Store associate
Sector
Electrical-electronics
Organization type
120-person company
Joined
May 2025
Message
263
#1

We woke up to a nightmare this morning on our Cologne-based e-commerce store where we sell industrial kitchen equipment spare parts. While the site looks totally normal when accessed from desktop, anyone clicking from Google search results or visiting on mobile gets redirected to gambling and fake crypto sites.

Our site averages 1,800 Euro in daily revenue, and right now our phone lines are completely jammed, we can't take orders. We're also terrified of getting blacklisted by search engines and slapped with a red security warning. We have access to the hosting control panel, the database is intact, but we don't want to panic and delete the wrong file, breaking the whole system.

In the first hour of an incident like this, who should take action, and in what exact order? How should we contact the hosting company, and where do we even begin cleaning this up?

DDoruk U***Member
Job title
Technical service technician
Sector
Cosmetics
Organization type
two-branch business
Joined
Aug 2025
Message
137
Most Helpful#2

Short answer: What you need to do in the first hour is not panic and delete files at random, but immediately route visitor traffic to a secure maintenance page and pull a full backup of the current state. Next, change all server, database, and admin passwords, and ask your hosting provider to freeze the server access logs.

Attackers usually inject conditional redirect scripts that differentiate search engine bots and desktop admins from regular visitors, targeting only mobile devices and visits where the referer is a search engine. These scripts are typically hidden inside root configuration files, the main index file, or your theme's header templates. Download a snapshot of the server in its current state before cleaning anything up, because you will need this evidence for forensic analysis or finding the attack vector.

Here is the emergency response sequence you should follow in the first hour: 1) Put your site into temporary maintenance mode immediately from the hosting panel or replace the main index file with a static maintenance page, 2) Change all server, FTP, database, and CMS admin passwords, 3) Check file modification dates to identify script files changed in the last 24-48 hours, 4) Locate the most recent clean automated server backup, but do not restore it until the vulnerability is patched.

When reporting this to hosting support, state clearly that your site is executing external redirects and request that server access and error logs be preserved. If you just restore an old backup without cleaning the site and fixing the root cause, you'll be hacked again within minutes because the exploit is still open.

YYavuz T***Expert
Job title
Sales Manager
Sector
Sports and fitness
Organization type
two-branch business
Joined
Jul 2025
Message
96

Doki · E-commerce infrastructure · 2023

#3

First things first: download your server config file via FTP and inspect it. They usually bury external redirects disguised as strings of gibberish right between rewrite rules. If you know what the original file looked like, delete those suspicious lines and save; at least the redirecting will stop temporarily.

KKoray E***Expert
Job title
Software developer
Sector
Packaging
Organization type
chain store
Joined
Sep 2023
Message
25
#4

The redirect only triggering on mobile and from search engines is a classic referer check. The malicious code might not just be in core files—it could also be written straight into database settings tables. If you have SSH access to the server, you can instantly find suspicious files by searching for anything modified in the last 48 hours.

LLale Ç***New member
Job title
System support specialist
Sector
Tourism
Organization type
chain store
Joined
Jun 2026
Message
161
#5

When submitting a ticket to your host, make sure to include these three details: 1) Which devices and referrers trigger the redirect, 2) The exact time and date the issue was first spotted, 3) Whether any unauthorized, unknown files were created in the directories. That way they escalate it straight to security instead of giving you a canned response.

HHavva G***MemberCommunity member
Joined
Feb 2023
Message
384
#6

The exact same thing happened to our wholesale site in Frankfurt last year. In a panic, we restored yesterday's backup and two hours later it got hacked again because there was a vulnerability in an outdated form plugin. We lost 2,000 Euro a day. Just restoring a backup without patching the exploit is definitely not a permanent fix.

note: I wrote this based on my own experience, it might not apply to everyone.

OOya G***Member
Job title
Production Manager
Sector
Catering
Organization type
300-person organization
Joined
Oct 2023
Message
66
#7

Did you have any third-party themes or plugins installed that haven't been updated in a long time? Also, are you on a shared hosting plan or a dedicated VPS? If it's shared, there's a very high chance it spread from another site on the same server.

OOsman K***VeteranCommunity member
Joined
Feb 2026
Message
279
#8

if the hosting company has an auto-backup whatever you do dont overwrite it right away. btw first take a backup of the current infected state and put it asidde and sometimes yesterdays backup that you think is clean is actually infected too you might need to go back at least a week.

EElaMember
Job title
Psychologist
Joined
Aug 2024
Message
74
#9

Since you operate in the German market, investigating whether user data has been leaked is critical regarding your legal obligations. If there is any possibility of access to customer details or checkout pages, you may be legally required to report the incident to the relevant state data protection authority.

İİlker A***MemberCommunity member
Joined
Mar 2023
Message
175
#10

Check Search Console immediately; if a warning has been flagged under the security issues tab, you will need to request a review right away as soon as the cleanup is done.

VVeli N***Expert
Job title
System administrator
Sector
Packaging
Organization type
a company within a holding
Joined
May 2022
Message
359
#11

Great work. Trying to do this alone is the most expensive way.

If you post the result here it will help others too.

ZZeynep K***Expert
Job title
Marketing manager
Sector
Textile
Organization type
two-branch business
Joined
Nov 2023
Message
330
#12

Three different views emerged, they all complement each other. An automated scan report is not the same as a penetration test.

KKadir K***Veteran
Job title
Product Manager
Sector
Livestock
Organization type
boutique agency
Joined
Aug 2025
Message
131

Doki · Penetration test · 2024

#13

Let's separate the concepts, they're getting mixed up. Taking measures without an inventory leaves doors you haven't seen open.

If you don't write this down from the start, it leads to arguments later. If you have questions, write them; I'll answer as best I can.

IIrmak Ö***ExpertCommunity member
Joined
Aug 2023
Message
153
#14

Here's how it went for us. People defend habits, not processes. Resistance comes from there.

Hope this helps.

ÜÜmit K***Member
Job title
Operations manager
Sector
Jewelry
Organization type
a company within a holding
Joined
May 2022
Message
406
#15

Following.

UUğur V***MemberCommunity member
Joined
Aug 2023
Message
282
#16

here's how it went for us... having backups accessible on the same network and with the same identity makes them part of the target.

im also curious if anyone does it differently.

AAleyna Ç***Member
Job title
Field sales representative
Sector
Packaging
Organization type
a company within a holding
Joined
Apr 2024
Message
225
#17

Quick summary for newcomers: Having backups accessible on the same network and with the same identity makes them part of the target.

Of course, it varies if your situation is different.

EEfe K***ExpertCommunity member
Joined
Feb 2023
Message
2
#18

I've been down this road, let me tell you. Hasty decisions become decisions you have to fix six months later.

If permission and scope aren't in writing, don't start that test. If you post the result here, it will help others too.

ÜÜlkü K***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
40-person manufacturing company
Joined
Dec 2024
Message
330
#19

I have a question. Most incidents start with a leaked password, not a vulnerability.

Correct me if I'm wrong.

OOya Y***ExpertCommunity member
Joined
Jan 2023
Message
60
#20

If you're going this route, sort this out first. Start with a small trial; don't commit to everything at once.

When making decisions, write down the worst-case scenario too, not just the best. If you have questions, write them; I'll answer as best I can.

Reply