Search The Hostwinds Guides Knowledge Base

What Do I Do If I Get Hacked?

Share This Article

There may be a time that you notice that your web hosting account has been hacked and Hostwinds certainly understands that this is an overwhelming feeling.

While you may do your best to build your account and configure it in a way that you need, there are instances where your web hosting account may get compromised. Although this guide is not exhaustive, it will attempt to help you get back on track and we want you to know that we are always standing by to help you if your web hosting services have been hacked or if you feel that you may have been hacked.

Change Your Passwords

The first step to cleaning your account is to make sure all of your passwords have been changed to something secure. Start with changing each of your passwords for your account including the following:

  • cPanel Account Password
  • Email Account Passwords
  • FTP Account Passwords
  • Passwords for your Applications, such as WordPress, Joomla! or Drupal

Secure Password Generators

There are several secure password generators that you can use. There are also several password managers that you may choose to use. Here are a few to consider:

Run a Virus Scan On Your Computer

While it may not seem obvious, the files that are stored on your computer and sent via email, File Manager or FTP should be scanned for any viruses to rule this out.

  • Update your anti virus software
  • Run a Full Scan on your computer
  • We highly recommend setting up a frequent schedule to update your virus protection software and scheduling a full scan at least once per week
  • Ensure any software applications you have are up to date
  • Ensure any Operating System updates are installed
  • Ensure any other software that is running on your computer such as Google Chrome is up to date

If you are having trouble detecting a virus and having it removed, you may want to consult with your local computer repair technician for the best assistance and for professional help. There are many tools available online that can help keep your computer

Secure Your Web Hosting Account

For any Shared or Business web hosting account with Hostwinds, this is done through cPanel. You will want to access cPanel to ensure you can follow these recommendations:

  • Change your cPanel account password
  • Audit your cPanel account for anything that is not currently in use and can be removed or terminated such as the following:
    • Softaculous Apps Installer
    • FTP Accounts
    • Email Accounts
    • Add On Domains
    • Email Forwarders
    • Cron Jobs
    • DNS Zone entries
    • Website Redirects
  • Change your Application’s password such as your WordPress Administrator, Joomla! Administrator or Drupal Administrator if you are using a CMS
  • Change your email account passwords for your email accounts that may contain login information for your web hosting services

Update Applications

There are several great applications available for you to install on your account through Hostwinds. There are also several incredible plugins, themes and updates for your applications that are very important to make sure are kept up to date.

It is important to perform regular maintenance and keeping your applications, themes and plugins up to date and update them when necessary.

It is also highly suggested to take a backup of your applications prior to performing any updates in case the update fails, or causes your website to have any issues. Running the latest version of your application, CMS, plugins, themes is always highly recommended. Having a good backup available in the case it is needed is very important. This will allow you to quickly and easily restore your website to a fully operational state as quickly as possible

When Do I Ask For Help?

Our Support Team is standing by and we are willing and able to help you at any given moment. Please reach out to us 24/7/365 without delay so that we can provide you with the support that you need. Please get started by submitting a ticket.

Being hacked is time sensitive so as many details as you can provide in the Support Ticket will allow us to start helping you with cleaning up your account without any delay.

By following the steps above, you will be sure to take the first steps towards securing your account and taking the necessary measures to

Lock Your Applications Down During Cleanup

We suggest asking that your account is locked down to your computer’s IP Address or your web Developer’s IP Address while you perform the steps above. This will prevent your website visitors from accessing your website and any malicious material from infecting other visitors.

Contact Your Web Developers

If you have a web developer, you may want to contact them to help ensure that your site and any applications are all up to date. If you are using any custom scripts or website code, it is important that it is updated and secure to prevent this from happening again in the future.

Related Articles