MB Bluejuice
Security

The first hours after a breach: what not to do

Four instinctive actions that look sensible but destroy the data an investigation needs.

· updated 2026-10-07

Discovering a breach makes you want to fix everything immediately. Unfortunately some of those quick actions destroy the information needed to answer how it happened.

What not to do

  • Do not delete suspicious files. Their creation time and content are the reference point for the whole investigation.
  • Do not restore from a backup. It overwrites the current state. If you do not know when the infection started, you do not know whether the backup is clean.
  • Do not reinstall WordPress. Overwriting core files erases the traces of modification.
  • Do not change server configuration or rotate logs. Access logs are often the only way to establish the time of entry.

What to do instead

  1. Restrict public access to the site — maintenance mode or a block at server level.
  2. Take a copy of the current state: files and database, with the date in the name.
  3. Save access and error logs — they are often retained only for a short period.
  4. Write down when and how you noticed the problem. This detail is needed later for the report.
  5. Only then start the investigation or call someone.

If the site belongs to an institution or processed personal data, reporting deadlines start running in parallel — covered in a separate article.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.