If your website has been hacked or tampered with, quick action is critical. In this article, you will learn what recovery options are available to you and what security measures you should take.
Recovery options
- Recovery by Hostpoint:
You can request an emergency restore in the Hostpoint Control Panel. Our Abuse team ensures that all data is restored properly. An emergency restore costs CHF 100. - Recovery with your own backup:
If you make regular backups of your website, you can also restore the data yourself. In this case, please still contact our Abuse Team in advance (abuse@hostpoint.ch). They will tell you exactly when your website was hacked and which backup is suitable. - Cleanup by external providers:
It may happen that a suitable backup of your website is not available, either from you or from us. This could be the case if, for example, your website was hacked a long time ago or your website was already infected when it was transferred to Hostpoint. In this case, we recommend that you hire an external service provider to clean up the website.
Sometimes it may make more sense to completely rebuild the website instead of restoring it. This is especially the case if a large number of files have been changed and cleaning them up would take a lot of time and money.
Security measures
No matter which option you choose, you should always follow these steps immediately after recovery:
- Log into the backend of your website and change the passwords of all registered users. Delete unknown users and disable inactive users.
- Change the password of the database user in the Hostpoint Control Panel.
- Update your website, CMS and all plugins and themes to the latest version.
Tip: Some CMS and plugins offer automatic updates. Activate this feature so that your website is always up to date. - Remove all unnecessary plugins and themes.
- Install and use a firewall. Specially developed plugins (e.g. Wordfence or Patchstack for WordPress) are available for the most common CMSs. For even more protection, we also recommend activating the OWASP CRS in the Hostpoint Control Panel.
- After the restoration, remove the Hostpoint Quarantined Files directory from the server.
An antivirus program can only find malware and hidden backdoors to a limited extent. There are cleanup plugins for CMS, but even these cannot fully guarantee that everything can be found and cleaned up.
If you still use old files from this directory, there is a very high risk of being hacked again.
If you need assistance with these steps, you can contact our Abuse Team at any time at abuse@hostpoint.ch.
Avoiding future attacks
To prevent further attacks on your website, follow the recommendations in the “How can I protect my website from attacks?” article.
For support requests please use this form instead.



