Guide
12 signs your website has been hacked
Website malware is written to stay hidden from the person who owns the site. These are the indirect signals worth acting on — and the mistakes that make a compromise far more expensive.
Website malware is written to stay hidden from the person who owns the site. It often behaves differently for you than for everyone else — serving clean pages to logged-in administrators and the payload to everyone arriving from search. So the useful signals are usually indirect. Here are the ones worth acting on.
1. A browser or search warning on your own site
A red interstitial, or “This site may be hacked” under your listing in Google, means an automated system has already found something. It is not a false alarm to dismiss — see removing a Google blacklist warning for what to do about it.
2. Pages in Google you never created
Search site:yourdomain.com and read the results. Injected pages
promoting pharmaceuticals, replica goods, essay writing or casinos are one of the
most common infections. They are frequently cloaked, so the page renders normally
when you visit but serves spam to the search crawler.
3. Visitors report redirects you cannot reproduce
Redirect malware is usually conditional — mobile devices only, or first visit only, or only for traffic arriving from a search engine. If a customer says they were sent somewhere strange and you cannot make it happen, believe the customer. Try a phone on mobile data, in a private window, arriving via a search result rather than typing the address.
4. Admin accounts nobody created
Check your user list for accounts you do not recognise, and for existing accounts whose role has quietly changed to administrator. Attackers add these so they can return after the original hole is closed.
5. Files with modification dates that make no sense
Core files changed on a date when nobody deployed anything are a strong signal. Note that timestamps can be forged, so an unchanged date does not prove a file is clean — but a changed one is worth explaining.
6. Unexpected files in upload directories
Your uploads folder should contain media. Anything executable in there — a
.php file among the images, or an image with a double extension — is a
classic webshell drop.
7. The server is suddenly slow, hot or expensive
A jump in CPU with no matching jump in traffic often means a cryptominer. On metered hosting the first symptom is sometimes the bill, or a resource-limit warning from your host.
8. Your host emails about abuse or spam
Hosting providers detect outbound spam and abuse complaints before owners notice anything. Treat these messages as urgent rather than administrative noise.
9. Email from your domain stops arriving
If a compromised site has been used to send spam, your domain or server IP may end up on a blocklist. Legitimate mail then silently fails.
10. Unexplained outbound connections or scheduled jobs
Cron entries and systemd timers nobody set up are a common persistence mechanism — they quietly re-download the payload after you delete it. This is a frequent reason a site appears clean for a day and then is not.
11. Search results show the wrong title or description
If your listing shows a different language, or product names you do not sell, the crawler is being served content you cannot see.
12. Your security plugin has gone quiet or vanished
Malware frequently disables or deletes scanners as one of its first actions. A plugin that has stopped reporting is not necessarily reporting good news.
One clean scan does not mean clean
Scanners match known patterns in files they can read. They do not usually see rogue database entries, modified server configuration, extra SSH keys, or persistence living outside your web root. Most of the reinfections we are called about had a passing scan somewhere in their history.
What to do if several of these match
- Do not start deleting. Removing files destroys the evidence that tells you how they got in and what else they left.
- Take a full backup of the current, infected state. It is the only record of what happened.
- Change credentials from a device you trust — hosting panel, SSH, database, CMS administrators.
- Check every site on the same server, not just the one showing symptoms.
- Get the compromise investigated properly before restoring a backup — restoring over an unfixed entry point simply resets the clock.
Our step-by-step version of this is in emergency malware removal.
Seeing any of these right now? We'll take a look today.
Related guides
Unlimited malware removal, for one monthly price.
We clean websites and VPS servers as often as it happens, monitor them 24/7, and harden them so it doesn't happen again.