If your email account is sending messages you didn’t write, people are getting strange emails "from you", or your website shows ads, redirects or a different site (often only on phones), act quickly. Here’s what to do.

If your email account was hacked

Signs: contacts receive messages you didn’t send (often fake invoices, "view this document" links, or payment-change requests), your Sent folder has messages you don’t recognize, you get lots of bounce-backs, or your password suddenly doesn’t work.

  1. Change the password now. Sign in at hubforteams.com > profile picture > Settings > Security. If you can’t get in, the account owner can reset it from the Client Area (My Services > Hub for Teams > User Accounts > key icon), or open a ticket and we’ll lock it immediately.
  2. Set your own recovery email and phone (Settings > Personal Info) so an attacker can’t reset the password to theirs.
  3. Turn on multi-factor authentication. See Using Multi Factor Authentication.
  4. Check for rules the attacker added: mail filters or forwarding that send your email to an outside address or delete replies. Remove anything you didn’t set up.
  5. Update the password everywhere it’s saved: phone, Outlook, other computers.
  6. Warn your contacts, especially anyone who may have received a fake invoice or bank-detail change.
  7. Open a ticket. We can check the sign-in and sending logs, remove any block on your address, and make sure the account is clean.
Important: Most email accounts are compromised through a phishing email: a fake "shared document", "voicemail" or "password expiring" message that leads to a fake login page. We will never email you a link asking for your password. When in doubt, go to hubforteams.com by typing it yourself.

If your website was hacked

Signs: visitors (often only on mobile) are sent to another site, spam links or pages appear in Google results, your antivirus or browser warns about the site, or a security scan (SiteLock/Imunify) reports malware.

  1. Open a ticket in the Support department right away and mark it urgent. Include the website address and a screenshot of what visitors see.
  2. Don’t just restore an old backup and move on. Attackers usually get in through an out-of-date plugin, theme or CMS (WordPress/Joomla), or an unsafe upload form, and they often hide files that survive a restore. We find the entry point and clean the site.
  3. Change all passwords for the site: WordPress/Joomla admin users, cPanel/FTP, and any developer accounts. Delete admin users you don’t recognize.
  4. Update everything: WordPress/Joomla core, all plugins and themes. Delete plugins and themes you don’t use.
  5. If Google flagged the site, request a review in Google Search Console once it’s clean.

Stay protected

  • Keep automatic backups with CodeGuard and consider SiteLock for daily malware scanning.
  • Use strong, unique passwords and a password manager. Turn on two-factor login for WordPress.
  • Add reCAPTCHA or a honeypot to contact forms so bots can’t abuse them.

See also: How to back up and restore your website · How to log in to Liberation Email / Hub for Teams and reset your password

Was this answer helpful? 0 Users Found This Useful (0 Votes)