Act in this order. Speed matters, because a compromised account is usually being used for something within hours.
1. OPEN A TICKET IMMEDIATELY
Tell us what you have observed. We can check the account from the server side, review access logs, and see whether anything is being sent or served that should not be.
2. CHANGE EVERY PASSWORD
cPanel password Client Area password All email account passwords All FTP account passwords Database passwords, updating the application config afterwards All website admin logins (WordPress, and any other application)
Use new, unique passwords. Do not recycle a variation of the old one.
3. REVOKE ACCESS YOU DO NOT RECOGNISE
Delete unknown FTP accounts, email accounts, website administrator users, SSH keys and API tokens.
4. FIND THE ENTRY POINT
Usually an out-of-date plugin, a nulled theme, a reused password, or malware on your own computer. Until you know which, the problem is not fixed.
5. CLEAN AND HARDEN
Follow our guide on cleaning a hacked website, then work through the security checklist.
6. SCAN YOUR OWN COMPUTER
If credentials were stolen by a keylogger on your laptop, changing them again will simply hand over the new ones.