First: breathe. Compromises feel apocalyptic and are usually recoverable — sites survive hacks daily. What separates a bad week from a bad quarter is the order of operations in the first hours.
1. Change the passwords that matter, from a clean device
Registrar first (your domain is the crown jewel), then hosting, then the site admin — in that order, from a computer you trust. If email runs on the domain, assume it’s in scope and secure it too.
2. Preserve before you clean
The instinct is to delete the weird files immediately. Resist it for one hour: snapshot the compromised state (most hosts can make a backup on demand). The evidence tells whoever cleans it how the attacker got in — delete it and the door stays open for the sequel.
3. Contain visibly if needed
Defacement or malware warnings? A maintenance page beats an infected page. Your host can usually enable one fast — and if the host flagged or suspended the site, work with their process; fighting it wastes the day.
4. Restore is not remediation
Rolling back to a clean backup gets you running — running with the same hole that got you here. The vulnerability that was exploited is still in the restored copy. Patch the entry point (outdated plugin, weak admin password, end-of-life platform) or schedule the encore.
5. Get a second set of eyes
Especially if the site was already abandoned — hacks and abandonment travel together, because unpatched sites are the easy targets. The rescue process handles compromised sites routinely and judgment-free: stabilize, find the entry, close it, then make sure somebody’s watching so the next attempt bounces.