laptop with red background and black flag with a skull & crossbones

What to do if your website’s been hacked

The website looks fine when you check it. A customer says it looks broken, or shows something odd, or won’t load properly for them. Emails have stopped arriving, or bounce for no obvious reason. When you ask the person who built the site to look into it, the answer is vague, slow, or comes with an unexpected price tag attached.

Any one of those things has an innocent explanation on its own. Together, and especially right now, they’re also exactly what a compromised website looks like from the outside.

Why this is more likely right now than usual

On 9 July 2026, the Australian Signals Directorate issued a critical alert about a large-scale campaign targeting websites built on WordPress, Joomla and similar platforms. Attackers are scanning for a specific list of known, already-patched vulnerabilities and exploiting any site that hasn’t been updated. TechCrunch reported the same week that even a conservative estimate puts the number of vulnerable WordPress sites in the tens of millions.

None of this requires an attacker targeting your business specifically. It’s automated scanning, running constantly, looking for sites that haven’t applied an update that’s been available for weeks or months.

The alert itself sets out immediate mitigation advice and additional steps to protect your website, and we recommend reviewing this with whoever manages your site. If you’re not sure how to apply any of it, get in touch and we can walk through it with you.

Which sites are most exposed

Self-managed WordPress and Joomla sites carry the most risk, particularly if plugins or themes haven’t been updated recently, or if nobody can tell you the last time they were. Sites on managed hosting or SaaS platforms like Squarespace carry considerably less risk, because the platform handles security updates for you rather than leaving it to whoever built the site.

If you don’t know which category your website falls into, that’s a good thing to find out before anything looks wrong.

What to do if you think it’s happened

Don’t make changes to the live site before you understand what’s going on. Overwriting evidence of how someone got in makes it harder to close the actual gap, and easier for them to get back in the same way later.

From there:

  • Contact your hosting provider directly and ask them to check for unusual activity, unfamiliar admin accounts or unexpected file changes.
  • If your usual web developer is slow to respond, unclear about what’s wrong, or asks for money before explaining what happened, treat that as a signal rather than a normal part of the process.
  • Once the site is secure again, change every password associated with it, including hosting, the CMS admin login and any connected email accounts.
  • Turn on two-factor authentication wherever it’s available.

Have you run a backup lately? covers why a clean, tested backup makes the difference between a quick recovery and a rebuild from scratch, and password security has more on what makes a password worth using.

How to stop it happening again

Keeping your CMS, plugins and themes updated is the single biggest factor in whether a site gets caught up in campaigns like this one. Is your website vulnerable? and our older security guidance go into what ongoing maintenance involves. The advice hasn’t changed much over the years, because these attacks often succeed when basic maintenance gets skipped, rather than because someone’s found a new and more clever way in.

If ongoing maintenance isn’t something you or your current provider are doing, a security review is a practical way to find out where you stand before it becomes a live problem. And if you’re not sure you have proper access to your own hosting account or domain, check that too.

If your site is showing any suspicious signs, get in touch and we’ll help you work out what’s going on.