Things to Do When Your Site is Hacked
I could imagine the panic when you realize the familiar designs of your site have disappeared in front of your eyes. Google Webmaster Tools Blog had a post about “things to do when your site is hacked”. Aside from contacting your hosting provider, here’s a summary of what you should do if your site fell victim to the hackers:
- Take your site off-line. Return a 503 header status code if you are unable to take it off-line, then proceed to the Webmaster Tools to remove all the hacked and/or unwarranted pages.
- Determine the purpose of the hackers and investigate the scope of the damage. It is important to see if your other sites are also affected.
- Reinstall the OS, re-install your site with the latest patches and updated third party add-ons. (Hopefully you have a back-up of your site), then change your passwords.
- Re-launch your site, and log into the Webmaster Tools to see if your site has been flagged for malware. Resubmit removed URLs using the re-include option, and watch out for the return of the hackers.
There are also a few more FAQs included in the post:
“Q: Is it better to take my site off-line or use robots.txt to prevent it from being crawled?
A: Taking it off-line is a better way to go; this prevents any malware or badware from being served to users, and prevents hackers from further abusing the system.
Q: Once I’ve fixed my site, what’s the fastest way to get re-crawled?
A: The best way, regardless of whether or not your site got hacked, is to follow the Webmaster Help Center guidelines.
Q: I’ve cleaned it up, but will Google penalize me if the hacker linked to any bad neighborhoods?
A: We’ll try not to. We’re pretty good at making sure good sites don’t get penalized by actions of hackers and spammers. To be safe, completely remove any links the hackers may have added.
Q: What if this happened on my home machine?
A: All of the above still applies. You’ll want to take extra care to clean it up; if you don’t, it’s likely the same thing will happen again. A complete re-install of the OS is ideal.”


