Sound familiar?
- Google results show Japanese, pharma or casino spam under your domain
- Visitors on mobile are redirected to scam or adult sites
- Chrome shows a red "Deceptive site ahead" or "Dangerous site" warning
- Admin accounts you did not create, or you are locked out
- Your host has suspended the account for malware or spam sending
- Customers report card fraud after buying from your online shop
Key facts
- Entry point found and closed, not just symptoms cleaned
- Files and database cleaned; core files replaced with clean copies
- All passwords, keys and salts reset; unknown admin users removed
- Google Search Console security issues reviewed and reconsideration requested
- Works on WordPress, WooCommerce, Joomla, Drupal, Magento, PrestaShop and OpenCart
- £45 an hour + VAT or quoted; plans from £25 a month + VAT include security monitoring
Signs your website has been hacked
Many hacks are designed to be invisible to the site owner. Attackers often show spam or redirects only to search engines or mobile visitors, and hide from logged-in administrators. Common signs:
- Search Google for site:yourdomain.co.uk and see pages you never created.
- Google Search Console reports a security issue or manual action.
- Your host sends a malware or outbound spam warning.
- New admin users, changed admin email addresses, or new files with random names in the uploads folder.
- The site suddenly slows down or uses far more server resources than normal.
Hacks are common. The UK Government's Cyber Security Breaches Survey 2025 found 43% of UK businesses reported a breach or attack in the previous 12 months.
How we repair a hacked site
- Contain: put the site into maintenance mode or block public access if it is harming visitors, and take a forensic copy of the hacked state.
- Find the entry point: server access logs, recently modified files, outdated plugins or extensions with known vulnerabilities, weak or reused passwords, or a compromised hosting account.
- Clean files: replace CMS core with clean copies from the official source, reinstall plugins and themes from trusted sources, and hunt backdoors such as obfuscated PHP using eval, base64_decode or gzinflate, and PHP files hidden in upload folders.
- Clean the database: injected scripts in posts, options and widgets, spam pages, rogue admin users, and malicious cron entries.
- Close the hole: update or remove the vulnerable component.
- Reset credentials: CMS admin, database, SFTP, hosting control panel and API keys, plus WordPress salts or equivalent secrets.
- Request reviews: submit a review in Google Search Console and check other blocklists.
Full detail on the cleaning process is on our malware removal page.
Restore from backup or clean in place?
If you have a clean backup from before the hack and the content has not changed much since, restoring it is often quickest. But a backup only helps if you also close the hole; otherwise the site is reinfected within days. And many hacks sit unnoticed for weeks, so recent backups may already contain the malware.
We compare backups against the hacked site to choose the cleanest starting point, then patch before going live. Every dijitul plan includes daily backups stored off the server. See website backups.
Shops, customer data and your legal duties
If your site handles customer data or payments, a hack may be a personal data breach under UK GDPR. The ICO expects reportable breaches to be reported within 72 hours of you becoming aware. We help you work out what data the site held and what the attacker could reach, so you can make that decision with the facts. See GDPR IT compliance.
On WooCommerce, Magento, PrestaShop and OpenCart, we check checkout pages and settings for card skimming scripts, which often hide in the database rather than files. Also tell your payment provider if you suspect card data was exposed.
Hardening after the clean-up
Cleaning a site without hardening it is like changing the locks but leaving a window open. After every repair we:
- Remove unused plugins, extensions, themes and old copies of the site left in subfolders.
- Turn on two-factor authentication for every admin account and remove shared logins.
- Set correct file permissions and disable PHP execution in upload folders.
- Disable in-dashboard file editing where the platform allows it.
- Make sure the site runs a supported PHP version.
- Set up off-server daily backups and monitoring so a repeat is spotted quickly.
Prices and keeping it clean
Hacked site repair is charged at £45 an hour + VAT (30-minute minimum, then 15-minute blocks). Heavily infected or very large sites are quoted after an initial assessment. Afterwards, a plan from £25 a month + VAT keeps software updated and checked, takes daily backups and monitors uptime and security, which is the best defence against a repeat. See website security and cyber security support. If it is happening now, see emergency website support.
What it costs
Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Pick a plan if you want it looked after every month, or pay by the hour for a one-off job.
Essential
Keep it updated, backed up and watched.
- Website software updates (core, plugins, themes) applied and checked
- Daily backups
- Uptime monitoring
- Security monitoring
Business
Updates plus an hour of fixes every month.
- Everything in Essential
- 1 hour of fixes or changes every month
- Priority support
Complete
Website and your team's IT, covered.
- Everything in Business
- 3 hours of fixes or changes every month
- IT and Microsoft 365 helpdesk for your team
No plan? The first 30 minutes are the minimum charge, then we bill in 15-minute blocks.
Frequently asked questions
How do I know if my website has been hacked?
Warning signs include spam pages in Google results for your domain, redirects to other sites on mobile, browser security warnings, unknown admin users and host suspension notices. dijitul can check the site and confirm whether it is compromised.
How much does it cost to fix a hacked website?
dijitul charges £45 an hour + VAT for hacked website repair, with a 30-minute minimum then 15-minute blocks. Large or heavily infected sites are quoted after an initial look, so you know the cost before the full clean-up.
Can I just restore a backup?
Only if the backup is clean and you close the vulnerability that let the attacker in. Otherwise the site is usually reinfected quickly. dijitul checks backups for malware and patches the entry point before restoring.
How do I remove the Google "This site may be hacked" warning?
Clean the site completely, then request a review in Google Search Console under Security issues. Google reviews the site before removing the warning. dijitul handles the clean-up and the review request.
Do I need to report a hacked website to the ICO?
If personal data may have been accessed and the breach poses a risk to people, UK GDPR expects you to report it to the ICO within 72 hours of becoming aware. dijitul helps establish what data was exposed so you can decide.
How do I stop my site being hacked again?
Keep software updated, remove unused plugins and extensions, use strong unique passwords with two-factor authentication, and keep off-server backups. dijitul's plans from £25 a month + VAT include updates, daily backups and security monitoring.
Related
Get it fixed
One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.