How Do I Know if My Website Has Been Hacked? (Signs)

unflagdomain Team·UPDATED August 25, 2026

Most owners find out their website was hacked from a warning sign, not a crash. The clearest signals are a browser security warning, strange new pages, unexpected redirects, a sudden traffic drop, spammy search results, or a notice from your host. Many hacks stay hidden for weeks, so checking matters.

TL;DR: Hacked sites rarely "look" broken. The real tells are browser warnings, injected spam pages, redirects to shady sites, and a sudden traffic crash. Hacked sites can stay undetected for weeks, so don't wait for a meltdown (Sucuri Website Threat Report found reinfection and long dwell times are common). Scan, confirm the hack, clean it, then ask each vendor to re-check.

If you're reading this because something feels off, you're already doing the right thing. The hardest part of a website hack is that it's often invisible to the owner. Your homepage loads fine, your login works, and yet attackers may be quietly serving spam or malware to your visitors. Below is a plain-English checklist of the signs, followed by exactly what to do. For the full repair walkthrough afterward, see our guide on how to clean a hacked website.

How do I know if my website has been hacked?

You know your website's been hacked when you see one or more concrete signs: a red browser warning, pages you never created, redirects to other sites, a traffic collapse, spammy search listings, or an alert from your host. Hacks are common, with reputable researchers tracking millions of new malicious URLs each week flagged by Google's own systems.

The tricky part is that no single sign proves a hack on its own, and the most damaging hacks are designed to stay hidden from you specifically. Attackers often "cloak" their content, showing the spam only to search engines or first-time visitors while you, the logged-in owner, see a perfectly normal site.

In our experience running unflag, the owners who get hit hardest aren't the ones who ignore an obvious defacement. They're the ones whose site looks completely fine to them while their reputation quietly erodes across the security vendors we scan. When we check a domain, we run it against 124 active security vendors at once, and we routinely find a site flagged by several of them while the owner is convinced everything is normal. By the time a customer calls, the damage has already spread across multiple blocklists.

Most website compromises are designed to hide from the site owner through cloaking and conditional redirects, so a normal-looking homepage is not proof of safety. Google's threat researchers flag large volumes of new malicious URLs continuously (Google Threat Analysis Group), and many infections persist undetected for weeks.

free blacklist scan

What are the warning signs your website has been hacked?

The signs your website has been hacked fall into eight common buckets, and most hacked sites show at least two or three at once. Look for browser warnings, unknown pages, redirects, traffic drops, search-result spam, host notices, performance changes, and modified files. WordPress powers around 43% of all websites, so plugin-based attacks are especially widespread.

Run through this list honestly. The more boxes you tick, the more likely it's a real compromise rather than a glitch.

1. A browser or search warning appears

The loudest sign is a full-page warning instead of your site. Chrome may show "Deceptive site ahead" or "Dangerous," and search results can carry a "This site may be hacked" label. These come from security vendors, not your host. Google's Safe Browsing protects billions of devices worldwide, so these warnings reach a huge audience fast.

If you're seeing these specifically, we've written dedicated breakdowns of the this site may be hacked warning and what triggers it. A warning is the clearest possible confirmation that a vendor's scanner found something on your domain.

2. Pages you never created start showing up

Hacked sites often sprout dozens or hundreds of spam pages selling counterfeit goods, fake pharmaceuticals, or pirated content. You'll spot them in your search results or your CMS page list. In the flagged-domain cases we handle at unflag, owners almost never discover the spam in their own admin panel. They find it by searching site:yourdomain.com on Google and stumbling on pages they never wrote — usually after a vendor we later contact has already flagged the domain for that exact injected content.

3. Your site redirects somewhere else

If clicking your link sends visitors to a gambling, adult, or scam site, that's a classic injected redirect. These often trigger only for mobile users or visitors arriving from Google, which is why you might not see it on your own desktop. Test from your phone, in an incognito window, and through a search-result click.

4. Traffic drops off a cliff

A sudden, unexplained traffic crash often means search engines have started suppressing or warning about your site. When Google flags a site as hacked, it can label or demote those results, and click-through to flagged pages falls sharply. Check your analytics for an abrupt drop that lines up with no other change you made.

5. Spammy results in Google

Search site:yourdomain.com and review every result. Pharmaceutical keywords, foreign-language gibberish, or odd file names in your URLs are strong evidence of injected content. This is one of the fastest free checks any non-technical owner can run in under a minute.

6. Your host or a vendor emails you

Hosting providers and security vendors routinely scan for malware and suspended or flagged sites. An email saying your account was suspended, your site contains malware, or your domain hit a blocklist is a direct signal. Don't dismiss it as phishing without verifying through your host's official dashboard.

WordPress runs roughly 43% of all websites, making outdated plugins and themes the most common entry point for site compromises (W3Techs). Vulnerable plugins, not core software, account for the vast majority of infected CMS sites according to security vendors' annual vulnerability reports.

7. Performance and behavior change

Unexplained slowdowns, server resource spikes, new admin users you didn't add, or sudden bounces in your outbound email can all point to a compromise. Attackers use hacked sites to send spam or mine cryptocurrency, which shows up as load you can't explain.

8. Files and code look modified

If you're comfortable looking, check for recently modified core files, unfamiliar .php files, or obfuscated code blocks (long strings of eval, base64_decode, or gibberish). In our experience, a single modified timestamp on a core file you didn't touch is often more reliable evidence than any single visible symptom, because attackers rarely cover their tracks perfectly. We don't scan or clean files ourselves — we trust your cleanup and then clear the residual blocklist flags it leaves behind — but the domains that reach us almost always have a file-level change like this at the root of the flag.

cleanup walkthrough

How can I confirm whether my website is actually hacked?

You confirm a hack by combining a free external scan with a few manual checks, since no single tool catches everything. Scan your domain against major blocklists, search site:yourdomain.com, and test redirects from mobile and incognito. Reputable vendors report that the majority of compromised sites are reinfected when cleanup is incomplete, so thorough confirmation matters.

Start with the free, no-signup route. You can run a free blacklist and security scan of your domain to see whether Google, antivirus engines, or reputation services are already flagging you. That tells you instantly whether the problem has gone public.

Then layer manual checks on top: search your own domain, click through from search results on a phone, log into your CMS and review users and pages, and ask your host to run a server-side malware scan. If two or more independent signals agree, treat it as a confirmed hack and move to cleanup.

One important caveat. A clean scan doesn't always mean a clean site. Scanners catch known signatures and public blocklist entries, but a fresh or cloaked infection can slip past automated checks. When symptoms persist despite a clean scan, trust the symptoms.

What should I do if my website has been hacked?

If your site's been hacked, work in order: take a backup, clean the infection, harden access, then ask each flagging vendor to re-check you. Cleaning before requesting reviews is non-negotiable, because vendors re-scan and will simply re-flag a site that's still infected. Most vendors review removal requests within 1 to 7 days once a clean site is submitted.

Clean the site first

Remove the injected content, update every plugin, theme, and core file, rotate all passwords, and remove unknown admin users. Your host or a security plugin can usually handle the heavy lifting. Our step-by-step cleanup guide covers this in detail for non-technical owners.

Confirm it's genuinely clean

Re-scan and re-check site:yourdomain.com after cleanup. Don't request a single vendor review until the spam pages, redirects, and modified files are gone. Asking for a re-check on a still-infected site wastes days and can extend how long the warning sticks.

Ask each vendor to re-check, separately

Here's the part owners underestimate. A flagged site is usually on several blocklists at once, and every vendor has its own form, email, or process. Google's Safe Browsing review is a manual request you submit in Search Console — there is no API and no instant button. Antivirus vendors each use their own dispute channel. For a website or URL flag (not a flagged file or EXE, which is a separate process), you request a re-evaluation of your domain specifically.

This vendor-by-vendor chase is exactly what unflagdomain was built to take off your plate. Once your site is genuinely clean, it sends each flagging vendor a properly formatted removal request, with your email set as the reply-to so responses land in your inbox. To be clear: the vendors decide whether and when to delist — what's guaranteed is that a correct request actually reaches every one of them.

One honest note: nobody can promise a vendor will delist you or give an exact date. The vendors review and decide. What you can control is cleaning thoroughly and making sure a correct removal request reaches each one.

Conclusion

Knowing how to tell if a website's been hacked comes down to watching for a handful of concrete signs: browser warnings, unfamiliar pages, sneaky redirects, a traffic crash, spammy search results, and host alerts. None proves a hack alone, but two or three together almost always do. Because the worst infections hide from you specifically, proactive checks beat waiting for a customer complaint.

If you've spotted the signs, move fast and in order: back up, clean, confirm, then request re-checks from every vendor flagging you. Start with a free scan to see who's flagging your domain, then follow our hacked website cleanup guide to remove the infection before you ask anyone to re-review.

warning explainer

// FAQ
  • Look for concrete signs: a red browser warning, pages you never created, redirects to shady sites, a sudden traffic drop, spammy search results, or a notice from your host. No single sign is proof, but two or three together usually confirm a hack. Run a free blacklist scan to check fast.

  • Yes, and it's common. Attackers often cloak injected spam or redirects so they appear only to search engines or first-time mobile visitors, not to the logged-in owner. Many infections stay hidden for weeks. That's why proactively searching site:yourdomain.com and scanning your domain matters more than waiting for an obvious crash.

  • It means Google's Safe Browsing scanner found content it believes was added by an attacker, like spam pages or redirects. The label appears in search results and can become a full browser warning. You clean the site, then request a manual review in Search Console; there is no instant removal button.

  • Run your domain through a free blacklist checker that scans major security vendors at once. It shows whether Google, antivirus engines, or reputation services are flagging you and how each one's removal works. This is the fastest way to learn who's blocking you before you start any cleanup or removal requests.

  • Take a full backup, then clean the infection: remove injected content, update all plugins, themes, and core files, rotate passwords, and delete unknown admin users. Confirm it's genuinely clean with a re-scan before requesting any vendor reviews, since vendors re-scan and will re-flag a site that's still infected.