Why Restoring a Backup Doesn’t Fix a Hacked Website

Your site gets hacked, and the answer seems obvious: roll back to a backup from before it happened. The site looks normal again, and you breathe out.

Then, days later, the same spam pages appear, or the same redirect, or the same Google warning. You restored a clean-looking backup and the hack came back anyway.

This is one of the most common recovery mistakes, and it’s understandable, because restoring a backup is exactly what backups are for. This guide explains why it often fails after a hack, when a backup genuinely helps and how to recover so the problem stays fixed.

What a Backup Actually Contains

A backup is a snapshot of your site at a moment in time. It captures your files, your database and your settings exactly as they were. That’s the whole point, and it’s also the problem.

If your site was vulnerable at the time of the snapshot, the backup is vulnerable too. It faithfully preserves whatever was true when it was taken: the outdated plugin, the weak admin password, the forgotten user account. Restoring it puts all of that back.

Why Restoring a Backup Usually Brings the Hack Back

There are four reasons a restore fails to end a compromise.

1. The vulnerability is still there

Most hacks begin with a weakness: an outdated plugin, an abandoned theme, a nulled (pirated) download or a stolen password. A restore doesn’t fix any of these. If the attacker got in through a plugin flaw last week, the restored site still runs that same plugin, so they simply walk back in.

2. The backdoor may be in the backup

Attackers rarely rely on one entry. They leave backdoors, small hidden files or database entries that let them return whenever they like. If the backdoor was planted before your backup was taken, the backup contains it. You restore the site and the backdoor together, and the attacker still has a key.

3. You may not know when the compromise began

To restore safely, you need a backup from before the break-in. But many compromises sit quietly for weeks before anything visible happens. Casino spam, hidden redirects and credential theft are often designed to stay invisible. If you pick a backup from the day before you noticed the problem, it may already be infected.

4. The stolen credentials survive the restore

A backup of your site files doesn’t change the passwords the attacker already stole. If they captured your admin login, hosting password or FTP details, those still work after the restore. They can log straight back in and reinfect the site, and the restored site never gets a chance.

The Hidden Danger: Restoring Destroys Evidence

There’s a second cost that people rarely consider. Restoring over a compromised site overwrites the evidence of how the attacker got in.

Without that evidence, nobody can say which plugin was exploited, which account was used or what else was touched. Without knowing the entry point, you can’t close it, and a site whose entry point stays open is a site that gets hacked again. This is why we always advise taking a forensic copy and preserving the logs before touching anything. Our guide on what to do in the first hour of a WordPress hack explains how.

Signs You’ve Been Reinfected After a Restore

If you’ve already restored a backup, watch for these signs that the compromise survived:

  • The same spam pages, redirects or defacement reappear within days
  • Pages you don’t recognise show up in Google again (see our guide to casino and gambling pages under your domain)
  • Google Search Console shows a returning security issue
  • Admin users you didn’t create reappear
  • Your hosting provider flags the account again
  • Your site is flagged with a warning such as “Deceptive site ahead”

A hack that returns after a restore is almost always a sign the entry point or a backdoor is still in place.

When a Backup Is Genuinely Useful

Backups aren’t useless after a hack. They simply aren’t a cure by themselves. They’re valuable in three ways.

As a reference. Comparing your files against a known-good backup helps identify which files were changed or added by the attacker, so a cleanup can be precise.

As a safety net. If a cleanup goes wrong, or if data is destroyed rather than just infected, a backup lets you recover content. This matters most for attacks that delete or encrypt data.

As a rollback after the cause is closed. Once the entry point is found and fixed, and credentials are reset, restoring clean content from a verified-clean backup can be a legitimate recovery step.

The key is the sequence. A backup works after you’ve found and closed the way in, not instead of doing so.

How to Recover Properly

A reliable recovery follows this order:

  1. Contain the attacker’s access before anything else.
  2. Preserve the logs and take a forensic copy of the compromised site.
  3. Find the entry point by working out how they got in.
  4. Remove everything malicious, including backdoors and hidden files, in both files and database.
  5. Check for rogue users and scheduled tasks that could reinstall the malware.
  6. Reset every credential the attacker could have reached.
  7. Update and patch WordPress core, themes and plugins, and delete anything unused.
  8. Restore content from a verified-clean backup only if needed, such as when data was actually lost.
  9. Re-scan after a couple of weeks to confirm the site stayed clean.

Notice where the restore sits in that list. It’s a late step, and only sometimes a necessary one.

How to Make Your Backups Work for You

Good backup habits make recovery easier even though they can’t replace a cleanup.

  • Keep backups off the server. A backup stored on the same account can be encrypted, deleted or infected alongside the site.
  • Keep several versions over time. Multiple restore points let you find one from before a slow-burning compromise began.
  • Test your restores. A backup you’ve never restored is a backup you can’t trust.
  • Back up the database too, not just the files.
  • Monitor your site so you notice compromises early, because earlier detection means a cleaner backup is available.

If you want automated, off-server backups with sensible retention, look at Tremhost’s Backup Cloud.

Get Help Now: Armor SOS

If your site was hacked and a restore didn’t solve it, Armor SOS is Tremhost’s emergency cleanup service. We take a forensic copy before touching anything, so nothing is lost even if we have to roll back. We then contain the attacker’s access, remove every injected page, shell and backdoor, reset compromised credentials, handle Google and blacklist delisting, and give you a written report on how they got in. We also clean in place wherever possible, and we work on sites hosted anywhere. Triage is free and usually starts the same day.

Message Armor SOS now →

Stop Paying for Cleanups: Armor Shield

If your site takes payments or holds client data, Armor Shield is $29 per site per month. It includes firewall rules written for your specific application, unlimited malware cleanup whenever you’re compromised, Google and blacklist delisting handled by us, a monthly report and a named engineer with a four-hour response. Shield protects the edge and cleans the origin, and it won’t patch a vulnerable plugin for you, but it will tell you exactly what to fix. At that price it costs less than a single emergency cleanup.

See Armor Shield →

For simpler informational sites, Armor Guard gives you the firewall, DDoS protection and SSL for $9 a month. Cleanup is quoted separately on that plan.

Frequently Asked Questions

Should I restore a backup if my website is hacked?

Not as your first or only move. A backup usually contains the same vulnerability, and possibly the same backdoor, so restoring it often brings the hack back. Preserve the evidence, find and close the entry point and reset credentials first.

Why did my site get hacked again after I restored a backup?

The entry point was probably still open, a backdoor was in the backup, or the attacker still held stolen credentials. A restore changes none of those things.

How do I know which backup is clean?

It’s hard to be sure, because many compromises begin quietly before anything visible happens. A reliable approach is to compare the backup against known-good files and scan it, rather than trusting its date.

Can a backup contain malware?

Yes. A backup preserves whatever was on the site when it was taken, including malware, backdoors and vulnerable code, if the compromise had already begun.

Do I lose evidence if I restore over a hacked site?

Yes. Restoring overwrites the infected files, which can destroy the evidence of how the attacker got in. Take a forensic copy and preserve the logs before changing anything.

Are backups still worth having?

Absolutely. They’re a reference for cleanup, a safety net if data is lost and a rollback option once the cause is fixed. They just aren’t a cure on their own.

Does a firewall fix a hacked site?

No. A firewall blocks attacks before they reach your site, but it can’t remove malware that’s already installed. Cleanup and protection are separate jobs.

How much does hacked website cleanup cost?

With Tremhost, triage is free and cleanup is quoted after we see what we’re dealing with. On Armor Shield, cleanup is included at no extra charge, every time.

Hot this week

How to Remove the “Deceptive Site Ahead” Warning From Your Website

A customer messages you to say your website is...

Casino and Gambling Pages in Google Under Your Domain: How to Find and Clean the Hack

You search for your own business on Google and...

WordPress Hacked? What to Do in the First Hour (and What Not To)

You open your site and something is wrong. Maybe...

Cheap Cloudflare Pro, Just $9 Per Month

Get Cloudflare Pro through Tremhost for just $9/month Looking for...

Hosting Uptime Comparison: Which Providers Actually Deliver on Their 99.9% Promise?

A 99.9% uptime guarantee has become close to universal...

Topics

WordPress Hacked? What to Do in the First Hour (and What Not To)

You open your site and something is wrong. Maybe...

Cheap Cloudflare Pro, Just $9 Per Month

Get Cloudflare Pro through Tremhost for just $9/month Looking for...

Hosting Uptime Comparison: Which Providers Actually Deliver on Their 99.9% Promise?

A 99.9% uptime guarantee has become close to universal...

Best Web Hosting Providers of 2026: Full Comparison

Nearly every "best web hosting" roundup you'll find online...

Web Hosting Statistics 2026: Where the Industry Actually Stands

Anyone researching the web hosting industry quickly runs into...

DIY Website Builder vs Hiring a Web Designer: Which Is Right for Your Budget?

Every small business owner building their first website eventually...
spot_img

Related Articles

Popular Categories

spot_imgspot_img