An unfamiliar link on your website or an administrator you do not recognise deserves prompt attention. Not every error is an attack, but a return to normal does not prove the problem is gone. Before deleting files at random, decide who coordinates the response and which information must be preserved. The order of actions can make recovery much easier or much harder.
Record what you observed
Keep the time, URL, displayed message and a screenshot without personal information. Preserve provider alerts. Do not open suspicious files on your work computer or publish raw logs. A precise description helps a specialist distinguish injected redirects from caching problems or configuration mistakes.
Contain exposure with the technical owner
Depending on the incident, website access, administration or integrations may need restrictions. A temporary information page can protect visitors without removing the underlying cause. Avoid several contractors making uncoordinated changes at once. Maintain a timeline, including who restricted access and which copies were preserved.
Recover access from a trusted environment
Change passwords and revoke relevant sessions after evaluating the devices being used. Check users, recovery methods, API keys and hosting access. Changing one WordPress password may be insufficient if an attacker can modify files or access email. Do not send new secrets through a channel you suspect is compromised.
Address the cause before returning
Identify the vulnerable plugin, disclosed password or other entry point without assuming the first suspicious file is the only change. Compare against clean sources and examine the database, scheduled tasks and accounts. Evaluate backups before restoration because they may already contain the problem. Cleaning and updating need to be followed by verification, not merely reopening the homepage.
Assess the effect on customers
Determine whether personal data, orders or payments were affected and involve the people responsible for applicable obligations. Do not say “nothing was lost” without evidence. Communicate confirmed facts, available functions and the next update time. After recovery, watch for recurring signs and turn the cause into a concrete improvement: narrower access, updates, monitoring or better recovery.
Sources and further reading
A CloudCity editorial guide informed by the documentation below. Check the official source for rules and procedures that may change.