· updated 2026-10-07
Discovering a breach makes you want to fix everything immediately. Unfortunately some of those quick actions destroy the information needed to answer how it happened.
What not to do
- Do not delete suspicious files. Their creation time and content are the reference point for the whole investigation.
- Do not restore from a backup. It overwrites the current state. If you do not know when the infection started, you do not know whether the backup is clean.
- Do not reinstall WordPress. Overwriting core files erases the traces of modification.
- Do not change server configuration or rotate logs. Access logs are often the only way to establish the time of entry.
What to do instead
- Restrict public access to the site — maintenance mode or a block at server level.
- Take a copy of the current state: files and database, with the date in the name.
- Save access and error logs — they are often retained only for a short period.
- Write down when and how you noticed the problem. This detail is needed later for the report.
- Only then start the investigation or call someone.
If the site belongs to an institution or processed personal data, reporting deadlines start running in parallel — covered in a separate article.