· updated 2026-10-07
Most infected sites we investigate do not look broken. It is in the attacker’s interest to stay unnoticed for as long as possible, so the symptoms are usually indirect.
What visitors see
- The site redirects to unfamiliar addresses — especially on mobile or when arriving from Google.
- The browser shows a “this site may harm your computer” warning.
- Adverts or links appear that you never added.
- Google results show foreign text or non-Latin characters under your title.
What administrators see
- User accounts you did not create.
- File timestamps changed without your action — especially
wp-config.php,.htaccessand the theme’sfunctions.php. - Unknown
.phpfiles inwp-content/uploads, where they should never exist. - A plugin you did not install, or one with no description.
- You cannot log in although the password is correct.
What the server sees
- CPU load jumps with no increase in traffic.
- Thousands of queued emails to unknown recipients.
- Your IP appears on spam blacklists.
One sign is enough to justify a check. If you find several, do not delete files and do not restore from a backup — that destroys the evidence. The correct order is described on our incident response page, and an initial check is available through the free security check.