How to Tell If Your Website Has Been Hacked: 12 Warning Signs

how to tell if your website has been hacked

Worried your website has been hacked? The warning signs are not always obvious. This guide walks through how to tell if your website has been hacked and exactly what to do next.

Most website hacks are quiet. Attackers rarely deface your homepage with a skull and a ransom note — that draws attention, and attention gets the intrusion cleaned up. Far more often they slip in, add a few hidden files, and quietly monetise your site for weeks or months: injecting spam links, redirecting your visitors, mining cryptocurrency, or using your server to attack other sites. By the time most owners notice, the damage to their traffic and reputation is already done.

Here are the warning signs that your website has been compromised — and what to do the moment you spot one.

1. Your site suddenly redirects somewhere else

You type your address and land on a pill-selling storefront, a fake “you’ve won a prize” page, or a sketchy download. Malicious redirects are one of the most common signs of a hack. They’re often conditional — only triggering for visitors arriving from Google, or only on mobile, or only for people who aren’t logged in — which is why an owner checking their own site sees nothing wrong.

2. Google or your browser flags the site

A red “Deceptive site ahead” or “This site may harm your computer” warning is Google Safe Browsing telling the world your site is dangerous. It’s one of the clearest signals of a compromise, and it tanks your traffic instantly — most visitors turn back the moment they see it.

3. Google Search Console sends a security alert

If you’ve verified your site in Search Console, Google emails you the moment it detects malware, hacked content, or a social-engineering issue. Check the Security Issues report — it often points to the exact URLs where Google found problems.

4. Strange new pages or spam content appear

Search your site on Google with site:yourdomain.com. If you see pages you never created — often in another language, selling counterfeit goods or pharmaceuticals — your site is being used for spam SEO. This is one of the most damaging hacks, because it poisons your domain’s reputation with search engines.

5. Unfamiliar admin accounts

Open your list of users and look for accounts you don’t recognise, especially ones with administrator privileges. Attackers frequently create a hidden admin user so they can get back in even after you change your password.

6. Files changed or appeared that you never touched

Unexpected files — particularly ones with random names in your uploads folder, or modified core and theme files — are a red flag. Injected code often hides inside otherwise-normal files, using functions like eval() and base64_decode() to obscure what it is doing.

7. Your site is slow, unstable, or crashing

Malware consumes resources. If your site suddenly slows to a crawl, throws errors, or your host warns you about excessive CPU usage, a compromise using your server to send spam or mine cryptocurrency is a common cause.

8. Spam is being sent from your domain

Complaints that your address is sending spam, a spike in bounce-backs for emails you never sent, or your domain landing on an email blocklist all suggest attackers are abusing your server or mail configuration.

9. Your traffic drops off a cliff

A sudden, unexplained fall in organic traffic can mean Google has flagged or de-indexed your site over hacked content. If analytics fall sharply with no other explanation, a security issue is worth ruling out.

10. Security tools you didn’t change are disabled

Some malware deactivates security plugins, deletes logs, or turns off updates to avoid detection. If your security tools are mysteriously switched off or your settings have changed on their own, treat it as suspicious.

11. Pop-ups, ads, or content you never added

Unexpected ads, pop-ups, or banners — especially ones that appear only to visitors and not to you when logged in — point to injected advertising or affiliate code.

12. Your host or a scanner flags malware

Many hosts run their own scans and will warn or suspend you if they detect malicious files. An external security scan is often the first thing to catch a compromise that the owner simply can’t see from the front end.

What to do if you spot the signs

Don’t panic, and don’t start deleting files at random. Work through it methodically:

Scan first. Confirm the problem and find where it lives. A remote scan checks how your site looks to the outside world — redirects, blocklist status, injected scripts, exposed files — without you having to dig through code.

Back up the current state before you change anything, so you can investigate the compromise later if you need to.

Change every password — admin accounts, hosting, database, and FTP — and remove any users you don’t recognise.

Clean or restore. Remove the malicious files, or roll back to a known-good backup from before the hack. Then update everything: core, plugins, and themes.

Re-scan and request a review. Once you’re clean, scan again to confirm, and if Google flagged you, request a review in Search Console to clear the warning.

Catch it before your visitors do

The hardest part of a website hack is that the owner is usually the last to know — the malicious behaviour is often hidden from anyone who is logged in. The only reliable way to know where you stand is to look at your site the way an outsider, and Google, sees it.

EzyAudit AI scans your website for exactly these signs — malicious redirects, Google Safe Browsing blocklisting, injected and obfuscated scripts, hidden iframes, exposed files, and dozens of other checks — and hands you a clear, prioritised report in about 90 seconds. Run a free scan and find out whether your site is quietly working for someone else.

Clear signs your website has been hacked

If you think your website has been hacked, act quickly: change passwords, update everything and scan for the cause. Google Search Central publishes guidance on hacked sites worth reading. Run a scan with EzyAudit AI to pinpoint how your website has been hacked and how to fix it. You can also review our website security checklist to harden things afterwards.

Scroll to Top