TideRelay Technologies Logo

Your website has been hacked. The first 24 hours.

Is your website defaced, redirecting to gambling sites, or flagged by Google? Here is the exact hour-by-hour triage you need to follow to save your business.

·4 min read·TideRelay

You open your company website on your phone, expecting to see your services page. Instead, you see a black screen with foreign text. Or worse, the site immediately redirects to an offshore gambling platform. Or perhaps Google Chrome has plastered a massive red warning across the screen telling visitors your site is "dangerous."

Do not panic, but do not ignore it either.

When a Nigerian business website gets hacked, the damage is rarely just digital. If an IOC is trying to view your procurement documents, or a customer is trying to pay for a product, a hacked site destroys your credibility instantly.

Here is the exact hour-by-hour triage you need to follow to stop the bleeding, restore your site, and ensure it never happens again.

Hour 1: Contain the damage (Take it offline)

Your first instinct might be to try and fix the code while the site is still live. Do not do this. While you are trying to find the bad code, the hacker's script is likely sending spam emails from your domain or infecting your visitors.

If your site is actively redirecting to malicious pages, you must take it offline immediately.

Contact your hosting provider (such as Qservers, Whogohost, or your international host) or the developer who built the site, and ask them to suspend the public-facing site. Ask them to put up a simple static "Under Maintenance" page. This stops Google from crawling the malicious content and protects your customers.

Hour 2: Change passwords in the correct order

Hackers get in because a password was weak, or a plugin was vulnerable. If you try to clean the site without changing the locks, they will just walk back in.

You must change your passwords in a specific order:

  1. Your hosting control panel (cPanel/WHM): Change this first. If a hacker has this, they control everything.
  2. Your domain registrar account: Ensure they have not initiated a domain transfer to steal your URL.
  3. Your website admin accounts (e.g., WordPress Admin): Log in and delete any admin users you do not recognise. Then change your own password.
  4. Your database passwords: You will likely need your developer to do this, but the database connection string must be updated.

Do not use your old password with a "1" at the end. Use a password manager and generate a 16-character random string.

Hour 4: Find the entry point and clean the site

This is where you need technical help. Simply deleting the weird files you see will not work. Modern malware hides "backdoors" deep inside your server. If you do not find the backdoor, the hacker will reinfect the site tomorrow.

Your developer needs to scan the server logs to find out how the hacker got in. Was it an outdated contact form plugin? A brute-force attack on a weak password? A vulnerability in the theme?

Once the vulnerability is identified, the safest way to clean the site is to completely delete the infected files and restore the site from a known, clean backup taken before the hack occurred.

Hour 12: Request a Google review

If your site was hacked for a few days before you noticed, Google probably noticed first. They will flag your site as "Deceptive" or "Hacked," and this flag will remain even after you have cleaned the site.

To remove the red warning screen in Chrome, you must prove to Google that the site is clean.

Log into Google Search Console. Navigate to the "Security Issues" tab. Click the button to request a review, and write a short, clear explanation of exactly what steps you took to clean the site (e.g., "We identified an outdated plugin, restored from a clean backup, and updated all passwords"). Google usually reviews and clears these flags within 24 to 72 hours.

The uncomfortable truth: Why it happened

Nobody says this, but we will: your website was hacked because nobody was maintaining it.

Hackers are rarely targeting your specific Port Harcourt business. They run automated scripts that scan millions of websites looking for outdated software. If your developer built your site two years ago and you have never paid anyone to update the core software, patch the plugins, or run security scans, your site was an open door.

A website is not a static flyer. It is software exposed to the internet. If it is not patched regularly, it will inevitably be compromised.

How to make sure it never happens again

Restoring a hacked site is expensive and stressful. Preventing it is boring and cheap.

At TideRelay, we do not just build websites and abandon them. We provide ongoing, proactive website hosting and maintenance plans in Port Harcourt. We handle the daily backups, the security patching, the firewall configuration, and the uptime monitoring so you never have to wake up to a defaced website.

We publish our maintenance plan rates openly on our pricing page, so you know exactly what it costs to keep your digital infrastructure secure.

If your site has been compromised, or if you know nobody has updated your site in years and you want to secure it before a crisis hits, contact us today. We will audit your current setup and lock it down.

Have a project in mind?

Get a fixed quote from a Port Harcourt team.

Start a project
← All articles