Firstly don't panic.
Then follow these steps.
- Change all passwords for all services hosted with us, that includes, control panel, FTP & email accounts, MySQL databases and CMS systems you host. make sure you use separate new complex passwords for each login.
- If you haven't already then open a ticket with us describing the site that has been hacked and any other information you may have that could help us, we need to see the hacked files in place ourself to understand the entry point of the hackers and gather evidence if needed.
- After we have confirmed you can proceed you should remove all website files from the site and upload a known good local backup (you are taking regular local backups aren't you?), if you don't have a local backup then we may have a backup prior to the hack attempt if caught early enough, but as we state in our terms of service our backups are not guaranteed.
- Restore your database from a known good version. If you must use the latest database data then you should manually check all database fields for data possibly inserted by the hacker.
- If you are using a common CMS like WordPress or Joomla then you should update it to the latest secure version and don't forget to update all third-party components.
Please follow our other security articles on how to secure your site once it is clean.
