What to do in the two hours after a compromise
The very first hours aren't for a deep cleanup, but for stopping the ongoing exploitation and preserving what will later help work out how the intrusion happened. Here's the order to act in, and what's best avoided when rushing.
The sequence for the first two hours
-
Limit access without cutting everything off
Switching the site to maintenance mode or blocking public access stops active exploitation. Avoid deleting the hosting account or resetting the server: that can wipe out the access logs you'll need afterwards to work out how the intrusion happened.
-
Change the server access passwords first
Hosting, FTP/SSH and database first: these are the credentials that let you regain control if the attacker also captured the CMS admin password. The CMS admin password follows immediately after.
-
Keep a record before deleting anything
A suspicious file, a redirect, an unfamiliar admin account: note the exact path, the modification date and a copy if possible, before removing it. That record later helps identify the entry point and confirm it was properly closed.
-
Check who else has access to the site
FTP access given to a former contractor, a third-party integration still connected to the admin area: these secondary access points are often forgotten in the rush, even though they can be the real entry point.
-
Notify the host if other sites could be affected
On shared hosting, an infection sending mass spam or consuming resources abnormally can affect other customers on the same server; flagging the situation also avoids the account being suspended without warning.
Why order matters more than speed
Rushing to clean everything at once, before getting a sense of how far the problem goes, often means missing the actual entry point. The site looks clean for a few days, then the infection returns, because the access the attacker used was left open.
Changing some passwords while leaving others unchanged produces the same result: if the FTP password was also captured but only the CMS admin one gets changed, the FTP access stays an open door, invisible from the admin interface.
That's why the sequence here starts with the access points that let you regain full control, before even tackling visible injected content.
Once things are stable
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.