Back to the knowledge base
Most common causes
- Outdated CMS (WordPress, Joomla, etc.).
- Weak passwords for FTP, email accounts, logins, or computers.
- Exposed website / high-profile target (e.g. political parties, local councils, etc.).
What do I do about my hacked website?
If you've been affected, you should do one of the following:
- Restore your website from a backup taken before the hack occurred.
- Contact your web developer and get help that way.
- Clean it up yourself — this requires more advanced knowledge.
- Start fresh with a brand new website built from scratch.
How do I protect myself?
To reduce the risk of being hacked, it's important to follow our advice.
- Keep your website up to date — we mean the code itself, not just the images and text.
- Use strong passwords for FTP, databases, email accounts, and computers.
- Bad password: fido1, Swedish personal identity number, qwerty123
- Good password: 98-s>aswOIG_!, Sv3aR1k3_!
- Don't use code that is no longer maintained (modules, plugins) — upgrade to newer alternatives instead.
- Don't share computer or email access with unauthorised users.
- Use antivirus protection on your own computer (Microsoft Defender, Avast, AVG, Malwarebytes, etc.).
- Avoid using public computers (e.g. at hotels or internet cafés).
- Be cautious on public networks.
What do we do if your website is hacked?
If your website has been hacked, it is your responsibility to fix it. We do not take responsibility for a hacked website. If the hack affects our other customers, we will suspend your account and notify you.