How to Find Out How Your Website Was Hacked

Invasion Investigation

Your site was hacked. You still don’t know what happened.

Are they gone? The passwords are changed. The warning is gone from search results and the site loads again.

And you can’t answer a single one of these:

How did they get in? Which means you can’t be sure they can’t do it again. How long were they inside? Which decides what they had time to reach. What was my site doing for them? Which is what your visitors and Google saw. Did any of it touch anyone else? Your customers, or somebody else’s website.

Cleaning removes the infection. It answers none of that — and skipping the answers is why so many sites get cleaned twice.

Nothing looks wrong. That’s the problem.

Here’s what people expect a hacked site to look like: broken pages, a defaced homepage, something obviously destroyed.

Almost never. Breaking your site works against them. A defaced site gets noticed in an hour and rebuilt in a day. A site that keeps working, keeps ranking, and keeps its owner comfortable earns money for months.

So the scene you walk into looks untouched — and to anyone reading the evidence, it’s a disaster. Multiple victims. Deliberate destruction of records. Traces from other people’s break-ins left lying around. And near-fatal damage to the one asset that takes twenty years to build and can’t be bought back.

“Nothing looks wrong” is why people don’t investigate. “It was worse than it looked” is why they should.

What an investigation actually produces

Four findings, each depending on the one before it.

The entry point. Until this is known, every security measure is a guess and reinfection stays likely. A site that’s been cleaned twice has usually been investigated zero times.

The dwell time. How long they held access before you noticed. This scopes everything else — three days and three years are different amounts of your business.

The use. What your site was doing while under someone else’s control. Compromised sites are rarely broken on purpose; they’re put to work, invisibly to the owner and perfectly visibly to search engines.

The reach. Whether it went past your own site — to customer data, to other sites in the same hosting account, or to third parties harmed by traffic your domain sent them.

How this series is structured

Like approaching a scene: from the perimeter, inward, and only as far as you need to go.

Parts 1 to 3 stay outside. Google’s index, Search Console, your server logs. All of it is a record about your site, held somewhere else. Reading it changes nothing, destroys nothing, and — this matters more than it sounds — tells nobody you’re looking. Most of what you’ll learn comes from here, which is fortunate, because it’s also the part you can do yourself.

Part 4 crosses the line, quickly. The one step you rush, because the scene may not be empty.

Parts 5 to 10 slow down again, because by then you’re working on a copy and nothing can be lost.

The order matters. Evidence decays at different speeds, and you collect in the order things disappear rather than the order you’d like to read them.

The rule

Four words that govern everything past Part 4:

Destroy nothing. Take nothing. Leave nothing. Run nothing.

Destroy nothing — on a hacked site, the evidence and the infection are the same files. Take nothing — copy, never move; where a file sits is evidence in itself. Leave nothing — everything you add is something you’ll later have to rule out. Run nothing — typing a suspicious file’s address into your browser doesn’t display it, it executes it.

And one more, which sounds like folk wisdom and isn’t:

Trust nothing but your instincts.

Every checkable signal in a modern compromise has been engineered to check out. The filenames look right. The site loads. The scanner reports clean. The host says resolved. What can’t be engineered against is an experienced person’s sense that something is off — and if you’re reading this, that sense was probably correct before any evidence was.

Act on that feeling immediately — by preserving, not by concluding. Then slow down and let the evidence decide what it meant.


The ten parts

1. What a site: Search Shows Ten seconds, no login, no server access, and it changes nothing. What the result count means when it’s too high and when it’s too low, why a spam URL that shows “page not found” proves nothing, and why you check every domain in your account rather than the one that raised the alarm. This is how the compromise behind this series was found.

2. What Google Search Console Knows Exact numbers instead of estimates, the day it started stamped by a third party, and copies of the spam pages stored by Google. Includes the report that detects cloaking for free, and the account setting that lets an intruder keep reading your data after a complete server rebuild.

3. Server Access Logs The most practical article here, and the one thing that’s urgent — logs are on a delete timer. What 200, 404, 410 and 500 actually mean, how to strip out crawler noise, how to spot a login that succeeded, and the two-line pattern that timestamps a break-in to the second.

4. Observing the Scene Crossing the line. Why the capture is the only thing you ever rush, what a backup will never contain, and why deleting their accounts before you’ve closed the door isn’t remediation — it’s provocation.

5. Investigating the Scene The long one. How they lie about time, identity and file type; the directories that deserve a slow look and why; the WordPress components that never appear on the plugins page; and the three files that define what your site is rather than what it shows.

6. Analysis of the Site Turning findings into conclusions without fooling yourself. Labelling what’s proven against what’s inferred, reading what wasn’t touched, and why every false positive in this investigation was more convincing than the truth.

7. Tough Decisions Clean or rebuild. Fight or leave. Including the two nobody writes about: how much investigation you’re actually paying for, and when the right answer is to stop fighting and walk away.

8. Who Do You Have to Tell Your host first, and why the hour you spend capturing before you call is the best hour in this series. What to ask them for so the answer isn’t generic. What you owe customers, what you owe the strangers sharing your server, and what actually happens when you report it.

9. Spam Link Tactics How twenty pages became 8,452, why you were served your own website while Google was served something else, and why the search damage outlives the cleanup. Plus the removal mistake that makes it permanent.

10. Site Hardening What would actually have stopped this one, what would have caught it eleven months sooner, and what’s worth doing anyway despite changing nothing here. Ends with the cleanup order that breaks the reinfection loop.


Where this sits

Stage Question
Emergency Authority It’s happening now — stop it
Invasion Investigation (you are here) The fire is out — understand it
Hardening and prevention Stop it happening again
Recovering rankings and trust Get back what it cost

The first series ends on verify before you declare recovery. This is what verification involves.

About the evidence in this series

Every example comes from a single compromise investigated end to end: five domains in one hosting account, seventeen months, entered through a file the owner’s own software had been asked to leave on the server. No exploit was involved and none was needed.

Where a conclusion is inferred rather than proven, it says so — including the entry point, which after eight months of work remains the best supported explanation rather than a demonstrated fact. Six earlier conclusions were wrong and were corrected. Those corrections are in here too, because an investigation that never overturns anything usually just never tested anything.

There are no exploit instructions. These articles describe how intrusions work well enough that you can find one in your own evidence, and no further.


Not sure what you’re looking at? ProVAE builds and recovers websites in Douglas, Georgia, serving South Georgia.