---
title: How to tell if your business website has been hacked
description: The warning signs that a business website has been hacked, how to check for them, and exactly what to do first if you find something wrong.
image: https://www.filtedev.com/hubfs/filtedev-social-share.png
---

<https://www.filtedev.com/>[Get a quote](https://www.filtedev.com/contact)

- [Services](https://www.filtedev.com/services)
- [Work](https://www.filtedev.com/work)
- [About](https://www.filtedev.com/about)
- [Blog](https://www.filtedev.com/blog)

[Request a quote](https://www.filtedev.com/contact)

[← All articles](https://www.filtedev.com/blog)

# How to tell if your business website has been hacked

Edmond DemaOctober 5, 20265 min read

Most website owners find out their site was hacked from someone else: a customer who got redirected to a scam page, a browser warning, or a hosting company suspending the account. By then the problem has usually been running for a while.

Hacked sites rarely look broken. Attackers want your site to keep working, because a working site with a good reputation is exactly what they are using. This guide covers the signs worth checking, how to check them, and what to do if you find something.

## Signs that something is wrong

### Search results show pages you never made

One of the most common attacks adds hundreds or thousands of spam pages to a site, often selling pharmaceuticals, counterfeit goods or gambling, sometimes in another language entirely. You will not see them in your menu. Google will.

**How to check:** search Google for `site:yourdomain.com` and scroll through the results. Look for page titles, languages or topics that have nothing to do with your business.

### Visitors are redirected, but you are not

Many redirects are written to hide from the site owner. They may only trigger for visitors arriving from Google, only on mobile phones, or only on the first visit. You open your homepage every day and everything looks fine, while customers from search land somewhere else.

**How to check:** open a private browsing window on your phone, search for your business on Google and click through to your site. Try a few different pages, not just the homepage.

### Google or your browser shows a warning

Google may label a result with "This site may be hacked", or browsers may show a full red warning page before loading your site. These are serious because they stop most visitors immediately.

**How to check:** set up [Google Search Console](https://search.google.com/search-console) for your domain if you have not already. Its Security Issues report tells you when Google has detected hacked content or malware on your site, and it is free.

### There are admin accounts you do not recognise

Attackers often create a new administrator account so they can get back in after you change your password.

**How to check:** review the user list in your website platform. Every account should belong to a named person who still needs access. Anything else should be investigated, not just deleted.

### Your emails start landing in spam

If your server is being used to send spam, email providers begin treating your domain as a spam source. Suddenly your quotes and invoices stop reaching clients.

### Your host contacts you, or the site slows down

Hosting companies monitor for malware and unusual resource use. An unexpected warning, suspension or large jump in server load can all indicate that something is running on your site that should not be.

### Files or code you did not add

For those comfortable looking under the hood: unfamiliar files in the site's folders, recently modified core files, or scripts from unknown domains in your page source are all red flags.

## What to do if you find something

The instinct is to start deleting things. Resist it. A careless cleanup often removes the visible symptom and leaves the way back in open.

1. **Take a copy of the site as it is now.** It feels backwards, but a snapshot of the infected site helps work out how the attacker got in.
2. **Change every password.** That includes the website admin, hosting account, database, FTP or SFTP access and the email account that can reset them. Turn on two-factor authentication while you are at it.
3. **Contact your hosting company.** Many can help identify infected files, and they need to know if their server is sending spam.
4. **Find the entry point.** The usual causes are an outdated plugin or theme, a weak or reused password, or a leftover account. If you do not find and fix the cause, the site will be reinfected, often within days.
5. **Clean or restore.** Restoring a backup from before the infection is often fastest, but only if you are sure the backup is clean and you patch the weakness immediately after restoring.
6. **Update everything.** Platform, plugins, themes and any code libraries, before the site goes back to normal.
7. **Ask Google to review the site.** If Search Console flagged a security issue, request a review once the site is clean so warnings are removed from search results.
8. **Keep watching.** Check the `site:` search and Search Console for the next few weeks. Reinfection is common when the original cause was missed.

## When to call in help

If the infection keeps coming back, if customer data may have been exposed, or if you are not confident about finding the entry point, bring in someone who does this regularly. If personal or payment information may have been accessed, you may also have legal obligations to notify people, so get proper advice on that quickly.

## Prevention is much cheaper than cleanup

Nearly every hacked business site we see had the same basic gaps: out-of-date software, shared or weak passwords, no working backups, and nobody responsible for maintenance. Closing those gaps costs a fraction of a cleanup, and far less than the lost trust of customers who saw a warning page instead of your business.

If you think your site may have a problem, or you want a second opinion on how well it is protected, [send us a short brief](https://www.filtedev.com/contact).

[← Back to all articles](https://www.filtedev.com/blog)

## Want this done properly?

Send a short brief about your website or project and we will reply with next steps and a written quote.

[Request a quote](https://www.filtedev.com/contact)[contact@filtedev.com](mailto:contact@filtedev.com)

**FilteDev**

Web development studio led by Edmond Dema. Based in Kosovo, working with clients in the United States and Europe.

[Services](https://www.filtedev.com/services)[Work](https://www.filtedev.com/work)[About](https://www.filtedev.com/about)[Blog](https://www.filtedev.com/blog)[Contact](https://www.filtedev.com/contact)

[contact@filtedev.com](mailto:contact@filtedev.com)[+1 724 345 2739](tel:+17243452739)[Privacy policy](https://www.filtedev.com/privacy)

© 2026 FilteDev. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@id" : "https://www.filtedev.com/about#edmond-dema",
    "@type" : "Person",
    "name" : "Edmond Dema",
    "url" : "https://www.filtedev.com/about"
  },
  "dateModified" : "2026-10-05",
  "datePublished" : "2026-10-05",
  "description" : "The warning signs that a business website has been hacked, how to check for them, and exactly what to do first if you find something wrong.",
  "headline" : "<span id=\"hs_cos_wrapper_name\" class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text\" style=\"\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"text\" >How to tell if your business website has been hacked</span>",
  "image" : "https://www.filtedev.com/hubfs/filtedev-social-share.png",
  "inLanguage" : "en",
  "mainEntityOfPage" : "https://www.filtedev.com/blog/how-to-tell-if-your-business-website-has-been-hacked",
  "publisher" : {
    "@id" : "https://www.filtedev.com/#organization",
    "@type" : "Organization",
    "name" : "FilteDev",
    "url" : "https://www.filtedev.com/"
  },
  "url" : "https://www.filtedev.com/blog/how-to-tell-if-your-business-website-has-been-hacked"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Edmond Dema",
    "url" : "https://www.filtedev.com/blog/author/edmond-dema"
  },
  "dateModified" : "2026-10-05T19:38:48.896Z",
  "datePublished" : "2026-10-05T19:38:48.000Z",
  "headline" : "How to tell if your business website has been hacked",
  "mainEntityOfPage" : {
    "@id" : "https://www.filtedev.com/blog/how-to-tell-if-your-business-website-has-been-hacked",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    }
  }
}
```