Signs and what to do first
Is Your Joomla! 3 Site Hacked?
If you are reading this because something feels wrong with your site, here is how to tell, and what to actually do about it. Note upfront: a security patch prevents known vulnerabilities from being exploited. It does not clean up a compromise that already happened. If your site is already hacked, cleanup is a different job, and the two should not be confused.
Common signs of a compromised Joomla! 3 site
- Spam pages appear that you never created, often for pharmaceuticals, gambling, or counterfeit goods, sometimes only visible to search engines and not to a normal visitor.
- Unexpected redirects send visitors, or just visitors coming from search engines, to an unrelated site.
- A defaced homepage, the most visible and least ambiguous sign.
- A warning from your hosting provider about malware, outgoing spam, or a suspended account, since hosts often detect compromise before the site owner does.
- Unfamiliar admin users in the Joomla! user list that nobody on your team created.
- Your domain gets blacklisted by Google Safe Browsing or an antivirus vendor, which you would typically notice as a browser warning when visiting your own site.
What to do first
- Do not panic and delete files at random. That destroys evidence you might need to understand how the attacker got in, and it can make cleanup slower, not faster.
- Restrict access if you can. Taking the site offline or putting it behind a maintenance page limits ongoing damage while you sort things out.
- Contact your hosting provider. They can often tell you what they are seeing on their end, and some hosts will suspend an account automatically until it is cleaned.
- Get help from someone who does this professionally. A proper cleanup means finding and removing the actual backdoor the attacker left behind, not just deleting the spam pages you can see, otherwise the same hole gets used again within days.
Prevention versus cleanup
These are two different jobs. Prevention means closing known vulnerabilities before anyone exploits them, which is what our Joomla! 3 Security Patch does: it fixes the 50 documented vulnerabilities in the Joomla! 3 core. Cleanup means finding and removing an attacker who already got in, which requires different tools and a different process entirely.
If your site shows any of the signs above, get in touch and we will help you assess and fix it: artd.ch/kontakt. Once a compromised site is actually clean, applying the security patch is still worth doing, so the same vulnerability cannot be used again.