# Signs Your Website Has Been Hacked (and What To Do)

Source: https://dijitulsupport.co.uk/guides/signs-your-website-has-been-hacked/
Updated: 2026-10-10

> Common signs your website has been hacked are visitors being redirected to spam sites, unfamiliar admin users, strange pages or Japanese keywords in Google results, browser 'deceptive site' warnings, and your host suspending the account. dijitul cleans hacked websites for UK businesses, removes malware, closes the hole and restores trust, at £45 an hour + VAT.

## Key facts

- Redirects that only happen on mobile or only from Google are a classic hidden-hack pattern
- A site: search on Google can reveal spam pages, often in Japanese or selling pharmaceuticals, that you never created
- Google Search Console's Security Issues report lists hacked content Google has detected
- Unknown administrator accounts in WordPress Users are a strong sign of compromise
- Recently modified PHP files in wp-content/uploads should not exist and usually mean a backdoor
- Changing passwords without removing backdoors leads to reinfection
- dijitul cleans hacked sites remotely at £45 an hour + VAT

## The signs to look for

Hacks on small business sites are usually built to stay hidden, so the owner is often the last to notice. Watch for these:

- **Redirects to spam, betting or fake prize sites**, sometimes only on phones, only for first-time visitors or only when arriving from Google.
- **Strange search results.** Search Google for *site:yourdomain.co.uk*. Pages in Japanese, or titles about pharmaceuticals, replica goods or casinos, mean injected spam.
- **Browser warnings** such as 'Deceptive site ahead' or 'The site ahead contains malware'.
- **Host emails or suspension** for malware, phishing pages or sending spam.
- **New admin users** you did not create, or your own login no longer working.
- **Unexpected outgoing email**, with your domain landing on blocklists.
- **Slow pages and high server load** from crypto mining or spam scripts.
- **Unknown files**, such as PHP files in the uploads folder or odd names like *wp-vcd.php*.

## How to confirm it

- Open **Google Search Console** and check Security and Manual Actions, then Security Issues. Google lists hacked URLs it has found.
- Run your domain through a free external scanner such as Sucuri SiteCheck, which checks for known malware and blocklisting.
- In WordPress, open Users and sort by role. Remove nothing yet, but note any administrator you do not recognise.
- In your hosting file manager, sort files by date modified. Recently changed core files, or any **.php** file inside *wp-content/uploads*, are red flags.
- Look at **.htaccess** for rewrite rules sending visitors elsewhere, and at the *siteurl* and *home* values in the database options table.

Take a full backup of the infected site before changing anything. It is evidence, and it lets you recover content if a clean-up goes wrong.

Also check for scheduled tasks you did not set up (cron jobs in your hosting panel, or unfamiliar WordPress cron events), and for other websites on the same hosting account. On shared plans, one infected site often spreads to every other site in the same account, so cleaning one and ignoring the rest leads straight back to reinfection.

## What to do straight away

- Change your hosting, FTP or SFTP, database and WordPress admin passwords, from a computer you trust.
- Turn on two-factor authentication for every admin account.
- Tell your host. They may have logs showing how attackers got in.
- If customer data could have been exposed, consider whether you need to report a personal data breach to the ICO, which must be done within 72 hours of becoming aware where it is required. Our GDPR IT compliance page has more.

Do not just restore last week's backup and walk away. If the hole that let attackers in is still open, or the backup already contains a backdoor, the hack comes back, often within days.

## How a proper clean-up works

A thorough clean-up replaces WordPress core files with fresh copies, reinstalls every plugin and theme from the official source, removes unknown admin users, searches the database for injected scripts and spam pages, deletes backdoors, and resets all passwords and the security salts in wp-config.php. Then the cause is closed: usually an outdated or nulled (pirated) plugin, a weak password, or an old PHP version.

Afterwards, request a review in Google Search Console so warnings are lifted, and check your domain against email blocklists if spam was sent.

## When to call dijitul

Most owners call us as soon as they see a redirect or a host warning, and that is the right time. We clean the site, find how they got in, close it and harden the site, working remotely at £45 an hour + VAT. Larger or repeated infections are quoted before we start. See hacked website repair and malware removal, or contact us now.

To stay clean, our plans from £25 a month + VAT include updates applied and checked, daily backups and security monitoring. If your site also shows certificate warnings, see website not secure warnings.

## FAQs

### How do I know if my website has been hacked?

Look for redirects to spam sites, strange pages in Google when you search site:yourdomain, browser malware warnings, admin users you did not create, emails from your host about malware, and PHP files in your uploads folder. Google Search Console's Security Issues report confirms what Google has found.

### Why does my website redirect to a spam site only on my phone?

Many hacks deliberately target mobile visitors or people arriving from Google, so the owner browsing directly on a desktop never sees it. The redirect code is often hidden in .htaccess, a plugin file or the database. Test on mobile data in a private window to see what visitors see.

### Can I just restore a backup to fix a hacked website?

Only if you know the backup is clean and you close the hole that let attackers in. Otherwise the same vulnerability gets exploited again, or a backdoor in the backup reactivates. dijitul checks the restored site, removes backdoors and updates the weak point.

### How much does it cost to fix a hacked website?

dijitul charges £45 an hour + VAT for hacked website clean-ups, with a 30-minute minimum. A single infection on a small WordPress site is often a few hours of work. Heavily reinfected sites or large shops are quoted upfront before work begins.

### How do websites get hacked?

On small business sites the usual causes are outdated plugins or themes with known vulnerabilities, nulled (pirated) premium plugins containing backdoors, weak or reused admin passwords, old PHP versions and insecure hosting. Keeping software updated and using two-factor authentication blocks most attacks.

### Will Google remove the hacked warning on my site?

Yes, once the site is clean. Fix the hack, then request a review in Google Search Console under Security Issues. Google rechecks the site and removes the warning if it finds no malware or spam. Warnings stay until a review succeeds.

## Pricing and contact

Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Plans: Essential £25/month + VAT (Website software updates (core, plugins, themes) applied and checked, Daily backups, Uptime monitoring, Security monitoring); Business £50/month + VAT (Everything in Essential, 1 hour of fixes or changes every month, Priority support); Complete £99/month + VAT (Everything in Business, 3 hours of fixes or changes every month, IT and Microsoft 365 helpdesk for your team). Ad-hoc support is £45 an hour + VAT. The first 30 minutes are the minimum charge, then we bill in 15-minute blocks. Contact: 01623 650333, support@dijitul.uk, https://dijitulsupport.co.uk/contact/
