Vayle
← Guides

What Actually Happens When a Small Business Website Gets Hacked

Nobody targeted you. A bot found old software and took the site as a resource. Here is how you find out, what it costs, and what actually prevents it.

Dark editorial hero card reading What actually happens when a small business website gets hacked, with the line Nobody targeted you

Nobody chose you. A bot found a known hole in software you stopped updating, and it took your site as a resource, the same way it took four thousand others that week.

That matters, because it changes what you should do about it. You are not defending against an attacker with a grudge. You are keeping a door shut that a machine checks every few days.

Who would even bother hacking my site?

Nothing about your business. It is your server and your domain they want.

A site that has been quietly compromised is usually doing one of four jobs. Sending spam from your server, which is free postage for somebody else and a ruined sending reputation for you. Hosting pages of junk links that have nothing to do with you, so somebody else's site ranks. Redirecting phone visitors somewhere else while your desktop browser shows the normal homepage, which is why owners often cannot see the problem themselves. Or, if you take payments on your own checkout, quietly reading what people type into the card fields.

None of that needs you to be big or interesting. It needs you to be reachable and out of date.

How would you find out?

Almost always from somebody else, and later than you would like.

A customer calls and says your site is throwing a red warning at them. That warning is not your host being dramatic. When Google determines a site has been compromised, the affected pages can appear with a warning label in search results or an interstitial warning page in the browser, which is set out in Google Search Console Help's documentation for the Security Issues report. To the person trying to book you, that screen says your business is dangerous.

Or your host suspends the account. Hosting companies act fast on outbound spam because their own IP reputation is on the line, and the first you hear about it is often the site already being offline.

The one channel that tells you early is the Security Issues report itself, in Google Search Console. It is free, it takes a morning to verify your domain, and most of the small sites we look at have never had it set up. If you do nothing else after reading this, do that.

What does it actually cost?

The cleanup is rarely the expensive part.

The expensive part is the days. Your site is down or flagged while it is sorted out, and that lands whenever it lands, which is often the week you were running something. Your email deliverability takes the hit from the spam that went out under your domain, so for a while afterwards ordinary messages from you land in junk folders. If your forms were already unreliable, this makes it worse, and contact form emails that never arrive is a separate mess you now cannot tell apart from this one.

Then there is the search side. The warning can be reviewed and lifted, but the pages of junk that were indexed under your domain do not vanish because you deleted the files. Cleaning that up is slower than cleaning the server.

And if you take card payments through your own checkout, there is a conversation you do not want to have, which is telling customers you cannot say for certain what was captured while the site was compromised. That is the scenario worth spending real money to avoid.

Why do these sites get in?

Three unglamorous doors, in roughly this order.

Software nobody updated. Plugins, themes and the platform core. Vulnerabilities get published, which is how the fix gets distributed, and the same publication tells every scanner exactly what to look for. An unpatched site is not hiding. It is announcing a version number.

Logins. One admin account, a password used somewhere else, no second factor. Nothing clever required.

Things still installed that you stopped using. The booking plugin you tried for a month, the old theme sitting beside the live one, the staging copy at a forgotten subdomain. Deactivated is not removed, and unused code still runs when someone asks it to.

The common thread is not carelessness. It is that nobody owns the site any more. The person who built it moved on, the login is in an email thread from two years ago, and there is no month where updating it is somebody's job. If you are not sure who holds the keys at all, who owns your website is the first thing to straighten out.

Do backups save you?

Only if they are recent, kept somewhere other than the site, and tested.

Three failure modes, all of which we have watched happen. The backup lives on the same hosting account, so when the account is suspended or wiped, so is the backup. The backup exists but nobody has ever restored one, and the day you need it you find it has been failing silently for months. Or the restore works perfectly and puts back the same unpatched software that let them in, so you get to do it again next week.

A backup is a rollback, not a fix. You restore, then you patch, then you change every password, and only then do you ask Google to review the warning.

Is a hosted platform safer?

Meaningfully, yes, and it is worth saying plainly because it affects what you build on.

On Shopify or a comparable hosted platform, the server and the core application are somebody else's job, and that is the layer most small sites get hit through. Your exposure moves to the apps you install, the staff accounts you hand out, and any custom code in the theme. Smaller surface, not zero. The trade-offs beyond security are covered in Shopify vs Wix vs a custom build.

A self-hosted site can be just as safe. It just does not stay that way on its own.

What does keeping it safe actually involve?

Less than people expect, but it has to happen on a schedule rather than when someone remembers.

Updates applied and then checked, because an update that quietly breaks your booking form is its own outage. Backups off the server, and a restore actually tested. Two-factor on every admin account, and no shared logins. Anything unused deleted rather than deactivated. Search Console connected so the Security Issues report has somewhere to shout. Uptime monitored, so you learn the site is down before a customer teaches you.

That is what our care plan is, and it starts at $129 a month and scales with the site. The full breakdown of what sits in it is on pricing, and the wider question of what a site costs to keep alive across a year is in what a website costs per year. Whether you have us do it, your developer do it, or you put a recurring reminder in your own calendar matters far less than that somebody does.

If you want to know where your site currently stands, send us the URL for a free teardown. We will tell you what it is running, what is visibly out of date, and whether Google is already flagging anything, whether or not you work with us.

See what's quietly costing you sales

Send us your site and we'll send back 3 to 5 prioritized fixes for design, speed, conversion and accessibility. Free, within 2 business days.