forumNew topic

Checking if a website is hacked: Is it just a buggy plugin or is someone inside?

EEsraMember
Job title
Python developer
Joined
Aug 2024
Message
134
#1

We run a small-scale e-commerce site based in Germany selling spare parts for commercial kitchen equipment. We turn over around 12,000 euros a month and get about 400 unique visitors a day. Two days ago, two different customers told us they were redirected to a weird betting-style page when accessing the site from mobile. I tested it multiple times on desktop from my own computers, and there is no redirect or any sign of weird behavior.

At the same time, I noticed CPU usage suddenly maxing out in the server control panel, and I got an automated warning from our hosting provider about 1,500 suspicious outgoing emails sent from the server. Last week, an update for our form plugin failed halfway through and threw a database error; we've been having minor glitches ever since.

Right now I can't quite tell: Is this just a technical glitch caused by the broken plugin getting stuck in a loop, or did someone actually breach the system and inject malicious code into the files? Before shelling out 800-1000 euros to a security firm for an audit, is there a concrete way we can verify this ourselves and manually tell a hack apart from a software conflict?

HHilal Ö***Member
Job title
Social media manager
Sector
Tourism
Organization type
boutique agency
Joined
Apr 2024
Message
215
Most Helpful#2

Short answer: Unfortunately, your site is most likely hacked; mobile redirects and mass outgoing emails from the server are not software bugs they are classic malware symptoms. A crashed plugin can spike CPU usage but it won't send out thousands of external emails or generate conditional redirect rules targeting only mobile devices.

To make sure first check the .htaccess file and index.php in your root directory via FTP or your file manager. Attackers usually add user-agent checks to these files to redirect only search engine crawlers and mobile browsers to external URLs; that's why you don't see it on desktop. Check the last modified timestamps on the files—if core files that haven't been touched in months show updates within the last forty-eight hours, the system has been compromised.

The second concrete step is checking the mail queue and cron jobs on the server. Suspicious PHP files are usually hidden in directories that shouldn't host executable files, like the uploads folder. Also check the users table in your database for any newly created admin accounts you didn't set up.

Before hiring outside professional help right away you can download a clean backup of the site to run a local malware scan and check the Security Issues tab in Google Search Console. If root-level write access was compromised, simply deleting the problematic plugin won't fix it; all core files need to be replaced with a clean installation.

CCeren B***Member
Job title
Sales Manager
Sector
Law
Organization type
early-stage startup
Joined
Jan 2025
Message
282
#3

Redirecting on mobile but not desktop is a classic user-agent sniffing trick. Attackers write rules to exclude IP addresses logged into the admin dashboard or standard desktop browsers. Open the mobile device emulator in your browser's developer tools and watch the initial redirects in the network tab—the filename doing the redirect will show up right there.

MMurat Z***Member
Job title
Field sales representative
Sector
Glass
Organization type
chain store
Joined
Jan 2025
Message
27
#4

when a plugin breaks your site whitescreens or throws fatal errors it doesn't just shoot out 1500 emails on its own. i mean they're blatantly using your server as a spam relay right now. change your ftp and db passwords immediately imo, don't wait.

FFeyza A***VeteranCommunity member
Joined
Jul 2023
Message
360
#5

When our spare parts store in Stuttgart had a similar breach, we noticed too late and our hosting account got completely suspended. A local security specialist charged 650 euros to clean it up, and because our domain ended up on spam blacklists, it took us 3 months to recover our Google rankings. I'd strongly suggest taking urgent action before your host shuts down the account.

EEmine A***MemberCommunity member
Joined
Mar 2025
Message
1
#6

Do you have SSH access in your hosting panel, or are you on a shared dashboard? Also, when that plugin update failed halfway through, did you manually change any file permissions? Those two details are critical for figuring out how the filesystem was accessed.

MMerveMember
Job title
Operations manager
Organization type
cooperative
Joined
Mar 2024
Message
118
#7

Follow these three steps immediately: 1) Regenerate the security keys in your config file via FTP to invalidate all active sessions. 2) Search for PHP files inside your uploads folder, don't delete what you find, just rename them to quarantine. 3) Flush the outgoing mail queue from your hosting panel and change your email account passwords right away.

SSerkan G***Expert
Job title
Penetration testing specialist
Organization type
a company within a holding
Joined
Nov 2023
Message
154
#8

Before jumping straight to worst-case scenarios, you should also look at the plugin logs. On some form plugins if the submission logic gets abused by spam bots, it can generate entries every second and blast out notifications back to back. That said, the mobile redirect makes it super suspicious; you might be dealing with two separate issues happening at once.

ÖÖzge A***ExpertCommunity member
Joined
Apr 2025
Message
42
#9

We went through something similar last year. Customers called saying sketchy ads were popping up on the site and at first we didn't believe them because everything looked completely normal on our office PCs. Turned out they only injected the redirect for people coming in from Google on mobile; typing the URL directly didn't trigger it at all. It had reached deep into the database tables, took us two full days to clean up.

YYağmur A***Member
Job title
Technical service technician
Sector
Healthcare services
Organization type
300-person organization
Joined
Feb 2024
Message
349
#10

In the German market, the biggest risk with these incidents is data protection compliance. If the customer database was accessed or customer emails were abused in outgoing blasts, you might trigger mandatory reporting requirements. Before panicking, make a backup copy of your server access logs so you don't destroy evidence before starting the cleanup.

İİsmail Ş***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
boutique agency
Joined
Apr 2024
Message
32
#11

I'm curious too. Hasty decisions become decisions you have to fix six months later.

Mistakes made on the website hack check side are usually reversible but expensive. If you post the result here, it will help others too.

TTülay B***Veteran
Job title
Human Resources Manager
Sector
Seafood
Organization type
300-person organization
Joined
Jan 2023
Message
35
#12

The opposite happened to me, that's why I'm writing. When you try to change everything at once, nothing settles.

AAli Y***MemberCommunity member
Joined
Mar 2025
Message
157
#13

you're right I've been down that road too then most time waste accumulates in tasks waiting for approval.

if I were you, Id go this route.

KKoray T***Member
Job title
Regional Manager
Sector
Construction
Organization type
sole proprietorship
Joined
Dec 2023
Message
103
#14

This approach has a cost, which isn't discussed. Mistakes made on the website hack check side are usually reversible but expensive.

This is my opinion, I'm not claiming it's absolute truth.

JJale Ö***New memberCommunity member
Joined
Jun 2026
Message
10
#15

I'll argue the opposite, don't get mad. If you scold false alarms, nobody will report again.

Hope this helps.

OOnur S***Member
Job title
System support specialist
Sector
Packaging
Organization type
300-person organization
Joined
Jul 2025
Message
14
#16

There's a part I don't understand. Trying to do this alone is the most expensive way.

If you get three different answers on a topic the question was asked wrong. If you post the result here, it will help others too.

HHasan A***MemberCommunity member
Joined
May 2023
Message
203
#17

yore right.

TTuğçe O***MemberCommunity member
Joined
Sep 2025
Message
3
#18

The discussion got scattered, let me summarize. If you scold false alarms, nobody will report again.

Taking measures without an inventory leaves doors you haven't seen open.

YYiğit A***VeteranCommunity member
Joined
Jan 2025
Message
2
#19

Same here. When making decisions, write down the worst-case scenario too, not just the best.

Good luck with that.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#20

A quick correction: "secure" here isn't absolute; it just means raising the cost. The goal isn't to make attacks impossible, but to make them not worth the effort.

Reply