Ten Signs Your Website Has Been Hacked And What To Do
A hacked website rarely announces itself in plain English. More often, the first clue is a small change: a strange page in Google, a customer reporting a warning, or an unexpected email sent from your business address. By the time the problem becomes obvious, an attacker may have added users, stolen information, or used your domain to distribute spam.
This matters to Australian businesses of every size. A Melbourne café, a Brisbane tradie, a Perth property service, and a national online shop all depend on trust, search visibility, and reliable communication. A compromised site can damage local reputation quickly, especially when customers are used to checking a business online before calling or visiting.
The good news is that prompt action can limit the damage. The signs below cover visible website changes, technical symptoms, search engine warnings, and suspicious account activity. They also explain what to do before attempting repairs that might erase useful evidence.
Sudden Changes You Did Not Authorise
Sign one: unfamiliar pages or posts appear on your site. You may find casino articles, pharmaceutical offers, cryptocurrency pages, or foreign-language content that nobody at the business published. Attackers often hide these pages from normal menus, so search results or a direct link may reveal them first.
Sign two: your homepage, logo, or layout has changed. A defaced page is the obvious version, but some attackers make subtler edits, such as replacing a phone number, adding a new administrator, or inserting a hidden link. Compare the current site with a recent backup and check your content management system’s revision history.
Do not simply delete the visible page and assume the problem has gone. Malicious code may remain in a plugin, theme, upload folder, database record, or hosting account. If the same vulnerability is still open, the altered content can return within hours.
Redirects And Unwanted Messages
Sign three: visitors are sent somewhere else. A customer might click your homepage and land on an unrelated shop, a fake competition, or a suspicious login screen. Some redirects appear only on mobile devices, only to visitors from Google, or only after several clicks, making them difficult to spot from your office computer. A redirect to an unrelated vacuum retailer would be a clear example of content that has no legitimate connection to your business.
Sign four: your site displays spam, fake support notices, or scam promotions. An attacker may target your audience with a message claiming that a parcel is waiting, an account needs verification, or a device has a virus. These pages can look convincing and may use your colours, logo, or domain name.
Ask several people to test the website from different devices and networks, but do not encourage anyone to enter personal information. Record the affected URLs, browser messages, dates, and screenshots. Those details can help a developer or hosting provider identify whether the infection is based in the site, DNS settings, advertising scripts, or a third-party service.
Warnings, Pop-Ups And Browser Trouble
Sign five: browsers or security tools warn visitors away. Messages such as “Deceptive site ahead,” “This website may be hacked,” or a blocked download indicate that Google Safe Browsing or another security service has detected suspicious activity. Your own browser may not show the warning if you have visited the site repeatedly or use a trusted device.
Sign six: unexpected pop-ups, downloads, or fake virus alerts appear. A legitimate business website should not force visitors to download an unknown file or claim that their iPhone, Windows computer, or Android device is infected. Malicious advertising scripts and injected JavaScript can create these symptoms even when the visible pages look normal.
Take the warning seriously and avoid testing the site by clicking every suspicious element. Contact your web host, review security notifications, and check Google Search Console for manual actions or security issues. If your business operates on a .com.au domain, remember that local search visibility can be affected even when the site still loads for some Australian visitors.
Strange Accounts And Content
Sign seven: a new administrator or user account appears. Check the user area of WordPress, Shopify, Joomla, your hosting control panel, and any connected email or marketing platform. An intruder may create an account with an ordinary-looking name, change an existing email address, or grant high-level permissions to a compromised user.
Sign eight: passwords, settings, or contact details have changed without approval. You might be locked out of the dashboard, notice a different recovery email, or find that forms now send enquiries to an unfamiliar address. An attacker who controls an administrator account can often create further access, modify backups, and hide traces of activity.
Change passwords from a clean device, beginning with the hosting account and administrator accounts. Use unique passphrases and multi-factor authentication wherever available. Do not reuse the password for your website on email, banking, social media, or domain registration accounts; one stolen password can otherwise open several doors.
Slower Systems And Missing Mail
Sign nine: the website becomes unusually slow or unreliable. A compromised site may be used to send spam, mine cryptocurrency, scan other systems, or serve malicious files. Hosting resources can become exhausted, causing timeouts, high CPU usage, database errors, or a site that works in the morning but fails during the busy arvo.
Sign ten: business email behaves strangely. Customers may receive bounced messages, fake invoices, password reset notices, or replies that nobody at your team sent. Your domain could also appear on a spam blacklist. Check sent folders, forwarding rules, mailbox logins, DNS records, and SPF, DKIM, and DMARC settings.
A slowdown does not always prove that the website was hacked; a traffic surge, faulty extension, or hosting issue can produce similar symptoms. Still, unusual server activity paired with suspicious email should be treated as a security incident. Ask the provider for access logs, login records, malware scans, and information about resource usage.
Check Before You Clean Up
Start by limiting harm. Put the site into maintenance mode or use a trusted temporary page if customers are being redirected or exposed to scams. Do not delete files at random, reinstall everything immediately, or restore an old backup without checking it. A backup made after the intrusion may contain the same malicious code.
Create a short incident record with the time the problem was found, affected pages, unusual accounts, warning messages, and recent changes. Review your site's website sitemap alongside Google results to spot pages that should not exist. Search for your domain using terms such as “site:yourdomain.com.au,” and compare the results with your genuine pages.
Ask your hosting company or web developer to preserve logs before they rotate. They can compare clean and infected files, inspect database entries, identify the entry point, and determine whether other sites on the same hosting account were affected. If customer, employee, or payment information may have been exposed, obtain professional advice about Australian Privacy Act obligations and any required notifications.
Recover, Harden And Monitor
A proper cleanup involves removing malicious files and accounts, updating the content management system, replacing vulnerable plugins, checking permissions, and rotating every relevant password. The affected site should be scanned after restoration, then tested in several browsers and on mobile networks. Payment systems and booking forms deserve separate checks because they handle sensitive information.
Prevention is practical rather than mysterious. Keep the core platform, themes, extensions, server software, and device operating systems current. Use reputable plugins, limit administrator access, maintain offline or protected backups, and enable multi-factor authentication. Ask your hosting provider whether firewalls, malware monitoring, daily backups, SSL management, and server-side scanning are included in your plan.
Monitor the site after recovery instead of treating the first clean scan as the end of the matter. Watch search results, uptime, login activity, email delivery, and customer reports for several weeks. A small Australian business does not need a huge security department, but it does need clear ownership of updates, backups, domain access, and emergency contacts.
If any of these signs appear, act today: restrict access, preserve evidence, change credentials from a clean device, contact your host or web specialist, and warn affected customers when appropriate. Prompt professional help can restore a trustworthy online presence before a minor compromise becomes a costly business interruption.