5 Signs Your Website Might Be Hacked (And What to Do Next)
From redirected traffic to sudden SEO spam, here are the warning signs every site owner should recognize — plus a clear incident response checklist.
Most hacked websites don't show obvious "you've been hacked" banners. Modern attackers prefer to stay invisible — quietly injecting credit-card skimmers, running SEO spam, redirecting your traffic to scam sites, or using your server to send spam email.
The longer a breach goes unnoticed, the more expensive it gets. Here are five signs to watch for — and what to do when you spot them.
1. Sudden drop in traffic or sales
If traffic from Google falls off a cliff and you haven't changed anything, your site may be flagged on Google Safe Browsing. Attackers inject spam pages or malicious redirects, Google's crawler notices, and your site gets labeled "deceptive" — a death sentence for organic traffic.
Check: Search Console → Security Issues. If it's flagged, the issue won't clear until you remove the malicious content and request a review.
2. Browser warnings you don't recognize
"Your connection is not private," "Deceptive site ahead," or "This site contains harmful programs" — these are your browser protecting your visitors from something it sees on your site. They are not false alarms to dismiss; they are realtime notifications that something active is wrong.
Do not click "proceed anyway." Find the underlying issue first.
3. Your homepage looks... different
Subtle changes — an extra tracking pixel, a new outbound link in the footer, a slightly modified copyright year, an unfamiliar script tag in the page source — these are the signatures of defacement or content injection. Attackers test whether you're paying attention by making small, deniable changes first.
Check: View page source and search for unfamiliar <script> tags or external domains you don't recognize.
4. Customers report weird emails from you
If you didn't send them, send they were not. This typically means your server's been compromised and is being used to relay phishing or spam. The damage compounds quickly: your domain lands on email blacklists and even legitimate messages start bouncing.
Check: Your email deliverability dashboard, and whether your domain is on common email blacklists.
5. Unexplained redirects or pop-ups
If a customer mentions being redirected to a sketchy site or seeing unfamiliar pop-ups on your pages, someone has injected a redirect or adware script. These often only fire for visitors from search engines (so you, the site owner typing the URL directly, never see them) — a deliberate evasion tactic.
Check: Open your homepage from an incognito window after Googling your brand name.
Your incident response playbook
- Don't panic, but act fast. Every hour matters.
- Take the site offline or set up a holding page to protect visitors and stop further damage.
- Restore from your most recent clean backup. This is the fastest reliable path back.
- Change all credentials: admin accounts, database, FTP, hosting control panel, API keys.
- Update everything: CMS core, plugins, themes, server patches. The hole the attacker used is still there until you close it.
- Set up monitoring so the next breach gets caught in minutes, not months.
The pattern across all five signs is the same: something changed, and you didn't notice. Monitoring exists to make sure that's never the case again.
Protect your website today
SecureWeb monitors your site 24/7 for malware, SSL issues, blacklisting, and data breaches — and explains every alert in plain English. Setup takes 2 minutes, no credit card.
Start Free