The average business owner discovers their website has been hacked 197 days after it happened. Read that again. Nearly seven months. For seven months, hackers had full access to their website — stealing customer data, sending spam through their domain, running scams under their brand name — and they had absolutely no idea. By the time they found out, the damage was done.
The uncomfortable truth about website hacking is that it's rarely dramatic. There's no skull and crossbones on your homepage. No villain sending you a ransom note (well, sometimes there is, but that's the obvious end). Most hacks are subtle, designed to go undetected for as long as possible because hackers make more money the longer they have undetected access to your website.
So how do you know if your website has been hacked? Here are the warning signs — some obvious, some that most business owners miss entirely.
1. Your Website Is Suddenly Slow for No Obvious Reason
If your website loads noticeably slower than usual and nothing on your end has changed — no new content, no new plugins, no server upgrades — this could be a sign that your server is being used for something you didn't authorise. Hackers commonly use compromised servers to send spam emails, run cryptocurrency mining scripts, or host files for other malicious purposes. All of that activity consumes your server resources and slows your website down.
Don't just assume it's a hosting issue. A sudden, unexplained drop in performance is always worth investigating further.
2. Google Shows a "This Site May Be Hacked" Warning
Google actively scans websites for malware and suspicious content. If they detect something wrong, they'll flag your website in search results with a warning like "This site may be hacked" or "This site may harm your computer." This warning appears directly in your search listing, visible to anyone who finds your website through Google.
If you have Google Search Console set up (and you should), Google will also send you an email notification when they detect a security issue. If you haven't set up Search Console yet, go do it right now — it's free, and this is just one of dozens of reasons why it's essential for any business website.
3. New Admin Accounts You Didn't Create
One of the first things a hacker does after gaining access to your website is create a new admin account for themselves. This gives them persistent access even if you change your own password. Log into your website admin panel and check the list of user accounts. If you see any accounts you don't recognise — especially admin-level accounts — your website has been compromised.
Check this regularly. Make it a monthly habit. It takes two minutes and could save you months of headache.
4. Your Website Is Redirecting Visitors Elsewhere
This is one of the more alarming hacks, and it's more common than you'd think. Someone visits your website URL, and instead of landing on your homepage, they're automatically redirected to a completely different website — often a scam site, a pharmaceutical site, or a phishing page designed to steal credentials.
The particularly cruel thing about this type of hack is that it often only triggers for visitors coming from search engines. When you visit your own website directly (by typing the URL), everything looks normal. But when someone clicks your Google listing, they get redirected. So you check your site, see nothing wrong, and have no idea your Google traffic is being stolen and redirected to someone else's scam operation.
Always test your website by clicking your actual search results links, not just typing the URL directly. Better yet, use Google Search Console's URL Inspection tool to see exactly what Google sees when it crawls your website.
5. Spam Emails Being Sent From Your Domain
Your website and email domain are connected. If your website server is compromised, hackers can use it to send thousands of spam emails using your domain name. You might not notice for a while — until email providers start blacklisting your domain, your legitimate emails start bouncing, and your clients stop receiving your invoices.
Signs to watch for: clients telling you they're not receiving your emails, your emails landing in spam folders, or sudden notifications from your hosting provider about unusual email sending activity. You can also check whether your domain has been blacklisted using free tools like MXToolbox.
6. Unfamiliar Files or Code in Your Website Directory
If you have access to your website's file manager through your hosting control panel (cPanel, Plesk, etc.), periodically browse your files for anything unfamiliar. Hackers often upload malicious PHP files to your server — files with random names like "x7k2m.php" or "shell.php" — that give them backdoor access to your website. These files are designed to look like they could be legitimate system files, but if you didn't put them there and don't recognise them, they're a red flag.
Malware scanning tools can automate this process for you, scanning every file on your server and flagging anything suspicious without you needing to manually browse through thousands of files.
7. Your Website Content Has Changed
Sometimes hacks are more obvious — content on your website has been changed, new pages have appeared that you didn't create, or strange links have been inserted into your existing pages. Hackers sometimes inject hidden links to other websites into your content as a way of boosting the search rankings of those sites (a practice called SEO spam). These links are often invisible to you when you look at the page, but they're there in the code, slowly damaging your own search rankings while boosting someone else's.
Run a regular content audit. Use a tool like Screaming Frog to crawl your website and check all your links. Anything linking to an external site that you didn't deliberately link to is suspicious.
8. A Sudden Drop in Search Traffic
If your Google Analytics shows a significant unexplained drop in organic search traffic, this could indicate that Google has penalised or de-indexed your website due to a detected security issue. Google takes website security seriously and will remove websites from search results if they detect malware, phishing pages, or other malicious content.
Always investigate a sudden traffic drop. Don't just assume it's an algorithm update — it could be a security issue.
9. Your Hosting Provider Suspends Your Account
Reputable hosting providers monitor their servers for malicious activity. If they detect malware on your website, they may suspend your hosting account to prevent their servers from being used to harm others. If you suddenly can't access your website or hosting control panel without explanation, contact your hosting provider immediately and ask whether your account has been flagged for security issues.
10. Customers Reporting Strange Things
Unfortunately, as mentioned at the start, many business owners only discover a hack when a customer reports something strange. "I visited your website and my antivirus flagged it." "Your website redirected me to a weird page." "I got a strange email that seems to be from your company."
Take every report like this seriously. Don't dismiss it as the customer's own device having a problem. Investigate immediately.
What to Do If You Suspect You've Been Hacked
If any of these signs apply to your website right now, here's what to do. First, don't panic — but act quickly. Change all your admin passwords immediately, including your hosting account, domain registrar, and website admin panel. Contact your hosting provider and inform them of the suspected breach. Run a full malware scan using a tool like Sucuri or Wordfence. If your website is seriously compromised, restore from a clean backup if you have one. And then — critically — identify and fix the vulnerability that allowed the hack in the first place, or it will happen again.
AUTHOR
RELATED POSTS
Get A Free Website Security Assessment
Book a free 30-minute consultation and find out exactly how secure your website is — and what to prioritize fixing first.