Act quickly and keep the evidence:
- Take the site offline or password-protect it so it stops serving malicious content - cPanel → Directory Privacy is the fast way.
- Change every password: cPanel, database users, admin accounts, FTP and mailboxes.
- Scan the account. Many hosts' tools and the Wordfence/Sucuri scanners will list infected files; look in
public_htmlfor unfamiliar PHP files with random names. - Restore a clean backup from before the compromise, then update everything before putting the site back.
- Open a ticket marked urgent - we can isolate the account, review logs and help you clean up.