Hacked website recovery

Last updated: October 5, 2026 · 3 min read · By Ali Raza

Quick answer

If your website is hacked: contain it (change all passwords, take a backup of the infected site for evidence), clean it (replace core, theme and plugin files with fresh copies, remove malicious code, unknown users and spam pages), close the entry point (update or remove the vulnerable plugin), then recover in Google: request a review in Search Console if there is a security issue, submit an updated sitemap and let spam URLs return 404 or 410 so they drop out of results.

A hacked website is stressful, but most hacks follow familiar patterns and can be fully cleaned. The worst mistake is a quick surface fix that leaves the backdoor in place, so the hack comes back a week later.

This plan is written for WordPress sites, where most hacks we see happen, but the steps apply to most platforms.

Hack recovery in five stages

1ContainPasswords, access, evidence backup
2CleanFiles, database, users, spam pages
3CloseFix the vulnerability that let them in
4RecoverSearch Console review, sitemap, 404s
5ProtectMonitoring, firewall, backups

What is Japanese keyword spam?

One of the most common hacks. Attackers create thousands of auto-generated pages in Japanese, often selling counterfeit goods, under your domain. Visitors may not see them, but Google does, and your search results fill with Japanese titles. Attackers sometimes even verify themselves as owners in Search Console. Google publishes a dedicated guide to fixing this hack.

Step 1: Contain

  • Change passwords for hosting, FTP or SFTP, database, WordPress admins and email.
  • Enable two-factor authentication for all admin accounts.
  • Take a full backup of the hacked site to keep as evidence, stored separately.
  • Tell your host; they may have logs or a malware scanner.

Step 2: Clean

  • Replace WordPress core, themes and plugins with fresh copies from official sources.
  • Search uploads and other folders for PHP files that should not be there.
  • Check the database for injected scripts, spam posts and unknown admin users.
  • Check .htaccess, wp-config.php and cron jobs for redirects or hidden code.
  • In Search Console, remove any unknown verified owners.

Step 3: Close the entry point

Find how they got in, usually an outdated or abandoned plugin, a weak password or a compromised account. Update or remove it. Without this step, reinfection is likely. Our WordPress security guide explains why plugins are the most common route.

Step 4: Recover in Google

  1. Make sure the spam URLs now return 404 or 410, not your homepage.
  2. If Search Console shows a security issue, fix it and request a review.
  3. Submit an updated sitemap containing only your real pages.
  4. Use the Removals tool for urgent cases, knowing it only hides URLs temporarily.
  5. Monitor search results and Search Console coverage over the following weeks.

Step 5: Protect the site

Add a firewall, malware monitoring, file change alerts and off-site backups. Our backup guide explains the 3-2-1 rule. If you would rather not handle this alone, our website care plans include cleanup, hardening and monitoring.

Frequently asked questions

How do I know if my website has been hacked?

Common signs are strange pages in Google results, often in another language, unknown admin users, redirects to other sites, browser warnings and security alerts in Search Console.

What is the Japanese keyword hack?

A hack that creates many auto-generated Japanese pages, often selling counterfeit goods, on your domain so they appear in Google under your site.

How long does it take Google to remove hacked pages?

Once spam URLs return 404 or 410 and the site is clean, they drop out as Google recrawls, which can take weeks. The Removals tool hides urgent URLs temporarily.

Can a hacked website be fully cleaned?

Yes, if you remove all malicious code and accounts and close the vulnerability that let the attacker in. Otherwise the hack often returns.

Sources

AR

Ali RazaFounder, Upstack Web

Full-stack developer with 7+ years of experience and a master’s degree in Computer Science. Ali builds custom software, CRMs and AI automation for growing businesses in the US, Canada, the UK and Europe. About Upstack Web