My Site Was Hacked Print

  • backupsdisasterrecovery, backups, hacked, backup, restore, woocommerce, troubleshooting, email, database, php
  • 0

Recovering from a compromise.

THE ORDER

  1. Open a ticket so we can check the account server-side.
  2. Take a copy of the compromised state before changing anything. You may need it to identify the entry point.
  3. Change every password: hosting, database, application administrators, FTP, email.
  4. Restore from a backup predating the infection.

THE BACKUP DATE PROBLEM

Infections are frequently present for weeks before being noticed. A backup from three days ago may already be infected.

Check several restore points. Look for the injected content in each to find one that is clean.

This is why retention matters. Three days of backups is not enough for this scenario.

AFTER RESTORING

Update everything immediately: core, themes, plugins, PHP version

Remove anything you do not use Fix permissions Enable two-factor authentication Scan again

IF YOU HAVE NO CLEAN BACKUP

Replace core files with fresh official copies, replace every extension with fresh downloads, and remove anything you cannot account for.

THE CRITICAL STEP

Close the entry point. A restored site that is still vulnerable is compromised again within days.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot