Your church website has been hacked. Do this first.

When a church website is hacked, take it offline or into maintenance mode first, change all passwords second, and only then investigate. Restoring a backup without finding the entry point reinstalls the vulnerability. Most church site compromises come from an unpatched plugin rather than a guessed password.

Most common entry point Unpatched plugin Not a guessed password
Straightforward cleanup 1 to 2 days Longer if it went unnoticed for months
Google review after cleanup a few days A failed review costs another cycle
Prevention from $400 per year Far below cleanup and lost trust

What should happen in the first hour?

Take the site offline or into maintenance mode. A compromised church website may be serving malware or fraudulent pages to visitors, and every hour it stays up extends the harm to the congregation.

Then change every password: hosting, content system, database, and the email accounts used for password resets. Do this from a device you trust.

Do not restore a backup yet. Restoring first destroys the evidence needed to find how the attacker got in.

How do we find out how they got in?

Server access logs show what was requested and when. The entry point is usually visible as unusual requests to a specific plugin or upload path shortly before the first signs of trouble.

The overwhelming majority of church website compromises come through an unpatched plugin or theme rather than a guessed password. This matters because it determines the fix: patching, not just new passwords.

Can we just restore a backup?

Only after the entry point is known and closed. Restoring a backup returns the site to its previous state, including the vulnerability that was exploited, and reinfection usually follows within days.

The correct order is: identify the entry point, patch it, then restore from a backup that predates the compromise, then change passwords again.

Google has flagged the site. How do we clear it?

Once the site is genuinely clean, request a review through Google Search Console. Reviews typically resolve within days, but a failed review because the site was still infected costs another cycle.

Verify thoroughly before requesting. Attackers commonly leave a second way back in, so a site that looks clean on the surface may not be.

How do we stop it happening again?

Apply updates monthly rather than when convenient, remove plugins that are no longer used, and enforce two-factor authentication on every administrator account.

Test a backup restore once a year. An untested backup is an assumption. Ongoing care packages start at $400 and cover exactly this work, which is cheaper than the cleanup it prevents.

Frequently asked questions

Why would anyone attack a church website?

Almost never deliberately. Automated scans look for unpatched software across millions of sites and exploit whatever they find. The church is not the target; the vulnerability is.

Is our member data at risk?

If the site stored member or giving data, treat it as exposed until proven otherwise, and check your local notification obligations. Sites that store nothing have far less at stake.

How long does cleanup take?

A straightforward case is a day or two. Cases where the compromise went unnoticed for months take longer, because the attacker has had time to establish more than one way back in.

Should we tell the congregation?

Yes, if any visitor could have been affected or personal data was stored. A short, factual note does far less damage than the story emerging later.

Can you help if you did not build the site?

Yes. Cleanup and hardening are available for sites built elsewhere, after a review of how the site is put together.

Written by Bernd Broschek, web developer and founder of Christian Web Designer in Schwaz, Austria, building websites for churches, ministries and Christian organisations since 2015. Last reviewed 23 August 2026.

Talk it through first

A short call costs nothing and usually clarifies whether this is the right next step for your organisation.

Get in touch