Recovering from a compromise affecting data.
WHAT IT LOOKS LIKE
Spam links injected into post content Administrator accounts you did not create Redirects configured in options Content altered or deleted Unfamiliar rows in configuration tables
FIRST ACTIONS
Open a ticket so we can check the account Take a copy of the current state before changing anything
Change every password: hosting, database, application administrators, FTP
FINDING WHAT CHANGED
Compare against a backup from before the compromise.
Check the users table for accounts you do not recognise.
Check the options table for altered site URLs and injected scripts.
Search post content for injected links.
CLEANING
Restoring a clean backup is the reliable route, provided the backup predates the infection.
Infections are frequently present for weeks. Check several restore points for the injected content to find one that is clean.
IF YOU HAVE NO CLEAN BACKUP
Remove the injected content specifically, which is laborious and workable.
THE CRITICAL STEP
Close the entry point. A cleaned database on a still-vulnerable site is reinfected within days.