Hacked PHP website: containment, cleanup and recovery
Stay calm. Most compromised sites can be recovered, but the cause must be found and fixed.
If your site or application has been hacked, you want it cleaned, back online and not hacked again next week. Cleaning the symptoms alone rarely achieves that. The attacker got in through something, and it needs to be found and closed.
Urgent? Call 03333 20 97 97, or book a conversation and say it's urgent. Urgent recovery work starts from £1,300 per day, subject to availability.
Signs of a compromise
- Your site redirects visitors to spam or unfamiliar pages
- Google or your browser warns that the site is dangerous
- Spam pages or odd links appearing on your site or in search results
- Your host has suspended the account or sent an abuse notice
- Unknown administrator users, or files you don't recognise
- Your site is defaced, or showing a ransom or attacker message
- Customers report card fraud after buying from you (a possible payment skimmer)
- Your server is suddenly slow, sending spam, or using lots of resources
- Data has appeared somewhere it shouldn't
What to do right now
- Don't panic, and don't delete things yet. Files and logs are evidence of how they got in.
- Limit the damage. If customers are being harmed (card skimming, redirects to malware), put the site into maintenance mode or take it offline.
- Preserve evidence. Take a copy of the files, database and server logs before changing anything.
- Change passwords from a clean device: hosting, database, admin users, email and anything connected. Change them after you've stopped the attacker's access, or they'll just see the new ones.
- Tell your host. They may have logs and may be able to help.
- Don't just restore the last backup. It may contain the same weakness, or the attacker's backdoor, and you'll be hacked again.
- Think about your legal duties. If personal data may have been affected, you may have to report to the ICO within 72 hours of becoming aware, and possibly tell affected people. If card data is involved, tell your payment provider. Take advice quickly.
How I handle it
1. Contain
Stop the damage first: take the site offline or restrict access, lock out the attacker, and secure accounts and credentials.
2. Preserve
Make forensic copies of files, database and logs, so there's a record and so we can analyse what happened.
3. Investigate
Find out what was changed, when, and how they got in. Common entry points in legacy PHP applications include outdated software, vulnerable plugins or libraries, weak or reused passwords, insecure file uploads, SQL injection and exposed admin tools. AI-assisted analysis speeds up the search through large codebases, with every finding verified by a person. How I use AI
4. Clean
Remove malicious code, backdoors, rogue accounts and unauthorised changes, and compare the code against known-good versions where available.
5. Close the hole
Fix the vulnerability the attacker used, and the obvious weaknesses next to it. This is what stops it happening again.
6. Restore and verify
Bring the site back safely, test it, and monitor for re-infection. Where search engines or browsers have flagged the site, I help you request a review.
7. Harden and report
Practical hardening (updates, access controls, backups, logging and monitoring) and a written account of what happened and what was done, which you can give to insurers, customers and regulators.
Why cleanup alone isn't enough
Sites are very often hacked again because:
- The original vulnerability wasn't found or fixed
- A backdoor was left behind to regain access
- Old, unsupported software stays in place
- Credentials weren't changed, or were changed too early
That's why I focus on root cause and hardening, not just deleting the visible malware. PHP security audit · PHP upgrades
When you may need more than me
I'm a PHP and infrastructure specialist, not a legal practice or a full-scale forensic incident-response firm. Be aware:
- Serious breaches involving large amounts of personal data may need legal advice and specialist incident response alongside the technical recovery. I can work with your advisers.
- If payment card data is involved, your card acquirer may require a formal investigation by an approved forensic investigator.
- Your cyber insurer may have its own response panel and must usually be notified quickly. Check your policy now.
What it costs
- Urgent recovery: from £1,300 per day, subject to availability and the nature of the incident
- After containment: the underlying weaknesses are fixed as a quoted piece of work, so the cleanup is not open-ended
- Hardening and upgrades: fixed price where scope is clear, or £950 per day
Data protection
Incident work involves very sensitive data. I work least-privilege, with confidentiality and a data processing agreement available on request, and I'll tell you promptly of anything that affects your own legal obligations. Data protection and security
For agencies
A client's site has been hacked and your team is out of its depth? I can step in quickly, white-label or direct. Agency terms
Frequently asked questions
Can you guarantee it won't happen again?
No one honestly can. What I can do is find and fix how they got in, remove backdoors, and harden the system so it's much harder to attack and quicker to detect.
How long does cleanup take?
It depends on the size of the system and how deep the compromise goes. I'll give you an honest estimate once I've looked, and tell you what's urgent first.
Should we restore from backup?
Not blindly. A backup may carry the same weakness or a backdoor. We need to identify when the compromise began and what's safe to restore.
Will Google remove the warnings?
Once the site is clean, I help you request a review. Timescales are up to the search engine, and not something I control.
Do we have to tell anyone?
Possibly. If personal data may be affected, you may have legal reporting duties, with tight deadlines. Take advice promptly.
Can you work with our host, insurer or lawyers?
Yes. I'll give them what they need, and keep a clear record of what was found and done.
Hacked, or think you might be?
Don't wait. Every day increases the damage.
Call 03333 20 97 97 or get in touch and tell me what you're seeing.