Rescue · $2,950
My Website Has Been Hacked. What Do I Do Right Now?
This happened to me. I lost everything I'd built. Here's the first hour, what not to touch, and how you get it back.
If your website has been hacked, do four things in this order: take the site offline or into maintenance mode, change every password from a different device, take a full forensic backup before you clean anything, and stop touching it.
Key takeaways
- Deleting the spam pages is the most common first move and it's the wrong one. It hides the symptom and leaves the door open.
- The damage isn't the spam. It's your domain reputation — and that's what takes months to rebuild, not days.
- If you clean without finding the entry point, you'll be reinfected. Usually within weeks, often within days.
- Removing bad pages isn't enough. They must be properly de-indexed or Google keeps serving them.
- Your backups are probably infected too. The compromise almost certainly predates the day you noticed.
My Website Has Been Hacked. What Do I Do Right Now?
This happened to me. I lost everything I’d built. Here’s the first hour, what not to touch, and how you get it back.
Call (754) 302-4631 — flat rate $2,950, no hourly billing, no surprises.
The story
I didn’t find out from a security alert. I found out because the phone stopped ringing.
For weeks my site looked completely, boringly normal. I opened it every day. Homepage fine. Services fine. Contact form fine. Nothing to see — and that’s not an accident, that’s the craft. A good compromise is invisible to the owner by design. It shows you your site and shows Google something else entirely.
Underneath, somebody had made themselves primary admin and built tens of thousands of pages I never saw. Casinos. Pharmaceuticals. Mail-order brides. My domain — the one with my name on it, the one I’d spent years making trustworthy — had been quietly turned into a spam farm and was busily laundering someone else’s rankings.
By the time I understood, my domain’s reputation was gone. Not damaged. Gone. I took the entire site down. Everything I’d built.
I’m telling you this because in about four minutes you’re going to have to make some decisions, and I want you to know they’re being made by someone who’s stood exactly where you’re standing.

Here’s the direct answer
If your website has been hacked, do four things in this order: take the site offline or into maintenance mode, change every password from a different device, take a full forensic backup before you clean anything, and stop touching it. Don’t delete the spam pages. Don’t just reinstall the theme. Those instincts feel productive and they destroy the evidence needed to find how the attacker got in — which is the only thing standing between you and being hacked again next month. sosSTEVIE handles hacked site recovery end to end for a flat $2,950: containment, forensics, clean-up, de-indexing, and hardening.
Key Takeaways
- Deleting the spam pages is the most common first move and it’s the wrong one. It hides the symptom and leaves the door open.
- The damage isn’t the spam. It’s your domain reputation — and that’s what takes months to rebuild, not days.
- If you clean without finding the entry point, you’ll be reinfected. Usually within weeks, often within days.
- Removing bad pages isn’t enough. They must be properly de-indexed or Google keeps serving them.
- Your backups are probably infected too. The compromise almost certainly predates the day you noticed.
The first hour
If you’re reading this because it’s happening right now, stop and do this.
1. Take the site offline. Maintenance mode, holding page, or pull it entirely. Every minute it’s live it’s serving malware to your customers and digging your reputation deeper. Yes, this feels drastic. Do it anyway.
2. Change passwords from a different device. Hosting, WordPress admin, FTP/SFTP, database, domain registrar, and the email account that can reset all of them. Use a device that hasn’t touched the site. If the attacker has a keylogger on the machine you built the site from, you’re handing them the new passwords.
3. Check who else is an admin. In WordPress: Users → Administrators. Look for accounts you don’t recognize — and look carefully at ones you do, because a good attacker doesn’t add “hacker123”, they escalate an existing dormant account or create something that looks like a plugin’s service account.
4. Take a full forensic backup. Now. Before you clean anything. Files and database, infected exactly as they are. This is the single step everyone skips and the one that determines whether this happens again. It is your only record of what was done and how.
5. Then stop.
I mean it. Stop. Don’t delete pages, don’t reinstall the theme, don’t run a one-click “fix” plugin. Every one of those feels like progress and every one of them destroys the trail. I know precisely how badly you want to do something. Doing the wrong something is how a one-week recovery turns into three months of getting reinfected.
Call (754) 302-4631 — if it’s live and bleeding, that’s a phone call, not a form.
What’s actually been taken
Here’s the part nobody tells you while you’re panicking about the spam pages.
The spam isn’t the damage. The spam is the exhaust. The damage is that Google spent weeks watching your trusted domain publish thirty thousand pharmacy pages, and it drew the obvious conclusion. Your rankings didn’t dip. Your trust went.
That’s why “just delete the pages” doesn’t work. You can remove every spam page in an afternoon and stay invisible for months, because the pages were never the problem — the reputational verdict was. And it’s why this hurts in a way an outage doesn’t. An outage ends when the site comes back. This doesn’t.
Then there’s the timeline, and this is the part that should genuinely alarm you. IBM’s 2025 Cost of a Data Breach report found the average breach took 181 days to identify and another 60 to contain — a 241-day lifecycle, and that’s the lowest figure in nine years of their research. That’s enterprise data, from organizations with security teams and monitoring budgets, so treat it as directional rather than a number about your specific website. But the direction is the whole point: the average intruder is inside for the better part of six months before anyone notices, and small businesses aren’t finding out faster than banks.
Mine ran for weeks. I thought that was bad. By that benchmark I got off lightly.
Then there’s what else was in there. Attackers who can create thirty thousand pages can also read your database. Customer records, inquiry history, whatever your contact form has been quietly storing since 2019. That’s not a website problem any more, it’s a disclosure obligation, and the clock on it started when the breach did — not when you noticed. I’m not a lawyer. If customer data was in there, talk to one this week.
And your backups. Everyone’s plan is “restore from backup.” Your backups are almost certainly infected, because the breach predates the day you noticed, and your backup rotation probably doesn’t reach back that far. Restoring blind just reinstalls the attacker.
What this actually costs you
Let me put a frame around this, because the $2,950 needs context.
The direct clean-up is the cheap part. The expensive parts are: the revenue you lose while you’re invisible, the months of rebuilding domain trust, the customers who hit a browser warning on your URL and quietly went elsewhere, and — if customer data was exposed — notification, legal advice, and whatever your jurisdiction requires.
IBM’s same 2025 report found that breaches identified in under 200 days cost dramatically less than those that ran longer — a difference measured in millions at enterprise scale. Scale that down to a small business and the shape holds: speed of detection is the single biggest variable you still control.
At the low end, a compromise caught in days is a bad week and a bill. At the high end, an unaddressed compromise takes the domain with it. Mine did. I had a working agency, and then I had a domain nobody could trust and a decision about whether to keep the name.
I don’t say that to frighten you into calling. I say it because the difference between those two outcomes is almost entirely about what you do in the next 48 hours, and that part is still yours.
The Rescue Protocol
Five phases, in order. The order is the whole method. All five are included in the $2,950.

Phase 1 — Contain. Site down, credentials rotated, attacker locked out, forensic snapshot taken. Goal: stop it getting worse. Nothing gets cleaned yet.
Phase 2 — Diagnose. Find the entry point. Vulnerable plugin, stolen credential, compromised host, an old backdoor from a breach you never knew about. Map every injected file, every rogue account, every scheduled task and every backdoor — attackers leave several, precisely because they expect you to find one and relax.
Phase 3 — Clean. Remove the infection and close the door. Not the other way round. Cleaning before you’ve found the entry point is just giving the attacker a fresh site to reinfect.
Phase 4 — De-index. The half almost every “malware removal” service skips. Removal requests for the spam URLs, correct status codes so Google stops asking, sitemap cleanup, disavow where warranted, security review request if you’ve got a manual action, and Search Console monitoring until the index is genuinely clear. This phase is measured in weeks. It’s also the phase that decides whether your traffic returns.
Phase 5 — Harden. You were vulnerable before. That hasn’t changed just because you’re clean. Hardening is where the rescue actually finishes.
Most people want to jump to Phase 3, because Phase 3 is the one that feels like fixing. Phases 1 and 2 are what make Phase 3 permanent.
Frequently Asked Questions
How much does it cost to fix a hacked website? My Hacked Website Rescue is a flat $2,950 covering all five phases: containment, forensic diagnosis, clean-up, de-indexing and hardening. Flat rate rather than hourly, deliberately — you’re already having the worst week of your business year and you shouldn’t also be watching a meter run. If the compromise turns out to be far larger than a standard business site, I’ll tell you before starting rather than after.
How do I know if my website has been hacked if it looks completely normal? Search site:yourdomain.com in Google and look at the page count — if it’s wildly higher than the pages you actually have, that’s your answer. Also check Google Search Console for security notices and manual actions, and review your admin user list for accounts you don’t recognize. Sophisticated compromises deliberately serve a clean site to the owner’s browser and a spam site to search engines, so “it looks fine to me” tells you nothing.
Can I just delete the spam pages and move on? No, and it’s the most expensive mistake at this stage. Deleting pages removes the symptom while leaving the entry point open, so you’ll be reinfected — usually within weeks. It also destroys the forensic trail needed to find how they got in. Worse, the pages need proper de-indexing rather than deletion, or Google keeps serving URLs that now return errors.
How long does it take to recover a hacked website? Containment and clean-up typically take a few days to a week depending on how deep the infection goes. Getting your search visibility back is the slow part and runs from several weeks to several months, because de-indexing and rebuilding domain trust happen on Google’s timetable, not mine. Anyone promising a same-day full recovery is selling you the clean-up and quietly skipping the reputation half.
Should I just restore from a backup? Almost never on its own, because your backups are probably infected. The compromise nearly always predates the day you noticed it — IBM’s 2025 research puts average time-to-identify at 181 days — and most backup rotations don’t reach back far enough to hold a genuinely clean copy. Restoring blind reinstalls the attacker along with your content.
You’re not the first person this happened to
You’re going to feel stupid. Don’t. I ran a web agency, I built sites for a living, I knew what I was doing, and I still didn’t spot it until the phone went quiet.
These attacks are engineered specifically to be invisible to you. That’s not a failure of attention. That’s the product working as designed.
The difference between a bad month and a lost business is what happens in the next 48 hours.
Call (754) 302-4631 now. Not urgent, but worried? Start with the $997 Diagnostic →
About Stevie
I lost my agency’s website to exactly this. Tens of thousands of spam pages built underneath a site that looked perfect in my browser. I found out when the calls stopped, and I had to take the whole thing down.
I rebuilt. Then I made this the thing I do, because when I needed someone who’d actually lived it, I couldn’t find one. The name came later, from a client who couldn’t pronounce mine and texted “SOS STEVIE” at midnight when his site went down. That story’s here.
sosSTEVIE — for when your digital presence is broken, invisible, or about to be. (754) 302-4631
Frequently asked questions
My website has been hacked — what do I do first?
Take the site offline, change every password from a clean device, take a full forensic backup of the infected state, and stop touching it. Don't delete spam pages or reinstall themes until forensics are complete.
How do I know if my website has been hacked if it looks completely normal?
Search site:yourdomain.com in Google and look at the page count — if it's wildly higher than the pages you actually have, that's your answer. Also check Google Search Console for security notices and manual actions, and review your admin user list for accounts you don't recognize.
Can I just delete the spam pages and move on?
No, and it's the most expensive mistake at this stage. Deleting pages removes the symptom while leaving the entry point open, so you'll be reinfected — usually within weeks. It also destroys the forensic trail needed to find how they got in.
How long does it take to recover a hacked website?
Containment and clean-up typically take a few days to a week depending on how deep the infection goes. Getting your search visibility back is the slow part and runs from several weeks to several months, because de-indexing and rebuilding domain trust happen on Google's timetable.
Should I just restore from a backup?
Almost never on its own, because your backups are probably infected. The compromise nearly always predates the day you noticed it — research puts average time-to-identify at 181 days — and most backup rotations don't reach back far enough to hold a genuinely clean copy.
Also in Rescue
Stop guessing.
Five days. One diagnosis. A ranked list of what's broken, what it's costing you, and what to do in what order — yours to keep whether you hire me or not.
About Stevie
Three years ago my own website was taken over. It looked completely normal in my browser while tens of thousands of spam pages ran underneath it. I found out when the calls stopped, and I had to take the whole thing down.
I diagnose before I quote, because I know exactly what it costs to be certain about the wrong thing. The whole story is here.