You have found out that something is wrong. Perhaps the homepage is showing someone else's message, perhaps Google is warning visitors away, perhaps a customer forwarded you a screenshot of pharmacy adverts on your services page. Almost nobody reading this is a technical person, so this is written as an order of operations rather than a set of instructions.
The single most expensive mistake is doing the visible thing first. Cleaning the page that looks wrong, before you know how anyone got in, usually means doing it again a week later.
First hour: close the door
Compromises persist because the way in stays open. Before touching the website itself, change the credentials that control it.
Your hosting account
The control panel where the site actually lives. New password, and turn on two-factor authentication if it is offered.
Your domain registrar
The account that controls where your domain points. This one matters most — someone with it can redirect your website and your email anywhere they like.
The website admin login
The WordPress or CMS login. Remove any administrator accounts you do not recognise, and any you recognise but no longer use.
The email account behind them
Every one of the above resets through an inbox. If that inbox is compromised, nothing else you change will hold.
Then take the site offline if it is defaced or Google has flagged it. Ask your host for maintenance mode, or put up a single holding page with your phone number. A page saying "we are working on this, call us" costs you nothing. A page selling counterfeit goods under your company name costs you a customer who will not tell you why they stopped calling.
Do not delete anything yet. A compromised site is also the evidence of how it was compromised. Ask your host whether they keep backups and access logs, and how far back — that question is much harder to answer usefully after you have wiped the server.
Then: find out what was actually reached
"Hacked" covers everything from a defaced homepage to a genuine data breach, and the response differs completely. Three questions settle it.
| Question | Why it decides the response |
|---|---|
| Did the site hold personal data? | Most small company websites hold nothing but enquiry-form submissions. If yours stored customer records, Malaysian PDPA obligations apply and that becomes a legal question before a technical one. |
| Is your email on the same domain? | If mail runs on the domain and the registrar account was reached, assume email was exposed too. This is usually the more serious half and the half people forget. |
| Was anything taken, or just added? | Defacement and spam injection are vandalism — noisy and embarrassing. Quiet, persistent access is worse and harder to see. Your host's logs are the only honest way to tell. |
If you cannot answer these from your own accounts, your hosting provider can. It is a reasonable thing to ask them and they deal with it regularly.
How this usually happens
Not to make you feel worse, but because the cause determines whether the fix will hold. In small company websites it is almost always one of four things, and none of them requires anyone to have targeted you specifically.
An out-of-date plugin or theme
By far the most common. Automated scanners look for known weaknesses in widely used components and find them at scale. Nobody chose your company.
A reused or weak password
Credentials leaked from an unrelated service, tried everywhere. Two-factor authentication defeats this almost entirely.
An abandoned account
The developer who built the site, the intern who added a page, the agency you stopped using. Old administrator accounts are doors nobody remembers leaving open.
Nobody was watching
The site ran for years with no updates and no owner. This is the underlying cause behind the other three more often than it is a cause of its own.
Then decide: clean, rebuild, or retire
This is where owners lose the most money, because the instinct is to restore things to how they were. That is often the worst of the three options.
| Option | When it makes sense |
|---|---|
| Clean it | When the site is genuinely valuable, someone competent will own it afterwards, and you can pay for the work to be done properly. Cleaning means finding every modified file and every back door — being wrong once means it comes back. |
| Rebuild it | Usually the cheaper and safer answer for a small company website. Your content still exists; what was attacked was the machinery around it. A rebuilt site with far less machinery removes the problem instead of treating it. |
| Retire it | A legitimate answer nobody offers you. If the site never brought work and your customers come from tenders, main contractors or word of mouth, keep the domain alive and let the site go. Losing a website you were not using is not a loss. |
Keep the domain whatever you decide. The site can be rebuilt and content can be retyped. A domain that lapses can be registered by someone else — and if your email runs on it, that goes too. Check the expiry date today.
What we do and do not do
We do not clean or restore compromised installations. That is specialist recovery work, it needs someone who does it constantly, and we would do it badly. If your site needs cleaning, ask your host first — many offer it, and they already have the logs and backups.
What we do is the rebuild-and-keep-it-current answer: a company site on a platform with very little to attack, on a domain registered to you, with one named party responsible for it afterwards. That last part matters more than the technology. Sites are rarely compromised because the software was bad. They are compromised because nobody was looking after them.
Retrieved from https://amkatechnologies.com/insights/website-hacked-what-to-do
Published 29 July 2026. AMKA Technologies Sdn Bhd, SSM 202301041763 (1535682-T).