Emails Claiming Your Website Was Hacked: Real Alert or Scam?

By · Updated · 7 min read

Most unsolicited emails telling you your website has been hacked are not security alerts. They're sales prospecting or extortion, sent in bulk to thousands of domains at once by people who have never looked at your site. But "most" isn't "all", and the reason these emails work is that occasionally one of them is right. So the answer is never to dismiss it or to panic — it's to verify the claim yourself, from sources you already control, without clicking anything in the message.

That check takes about five minutes. Here's how to do it, and how to recognise which of the four kinds of email you're actually holding.

The four emails that all look the same

Genuine automated alerts come from services you signed up for: Google Search Console, your security plugin, your uptime monitor, your host's scanner. You'll recognise the sender, and the message will point at something specific.

Genuine notices from your host arrive when their scanner finds something or another network complains about your server. These tend to be blunt and specific, they often carry a deadline, and sometimes your site is already suspended by the time you read it.

Cold sales outreach is the big one by volume. An agency runs an automated scanner across a large list of domains, and anything that trips a rule generates an email offering to fix it. Some of these firms do real work. The scan behind the email is still shallow, and the alarm is deliberately loud.

Extortion is the fourth kind: a demand for cryptocurrency, a deadline, and a threat to leak your database, deface your site or report you somewhere. Almost all of it is bluff sent to enormous lists.

Verify it without touching the email

The single most useful habit here is to never follow a link in a message like this. Don't click, don't reply, don't open attachments. Go to the sources directly and see whether the claim holds up.

Open Google Search Console yourself by typing the address, and look at the Security Issues report. If Google believes your site is compromised, it will say so there, and that is authoritative in a way an email never is. My guide to reading those reports covers what each type means.

Search Google for site:yourdomain.com and page through the results. You're looking for pages you never created — pharmaceutical listings, foreign-language titles, nonsense URLs. That's the classic fingerprint of an SEO spam infection, and it shows up here long before anything looks wrong on your actual website.

Log into your hosting control panel and check for genuine tickets or notices. If your host really did contact you, it will be in your account, not only in your inbox.

Then load your own site on a phone using mobile data rather than wifi, and while logged out. A large share of infections deliberately behave for logged-in administrators and desktop visitors, and only misbehave for a mobile visitor arriving from search. Checking from the browser you always use is precisely the blind spot these hacks are built around.

Finally, run an independent scan — mine is free — and check whether you're on any blacklists. Between those and Search Console you'll have a clear answer.

Signs the email is not genuine

It never names anything. This is the giveaway. A real finding cites a file path, a URL, a detection name, a date. Fakes stay vague because the sender has nothing: "critical vulnerabilities", "malicious activity detected", "your site is at risk". If it can't tell you where, it hasn't looked.

It wants a deadline and a payment. Urgency is the whole product. Genuine alerts from Google or your host don't come with a countdown to a crypto wallet.

The reply address doesn't match the sender. Worth ten seconds in your mail client's "show original" view. Mismatched reply-to addresses, free mail domains and lookalike domains all show up here.

It's addressed to nobody. Sent to an address scraped from your site's contact page or your domain registration, with no name, or a greeting built from your domain.

It claims authority it can't have. Nobody at Google emails individual site owners about malware. Those messages go through Search Console.

The "proof" is a password. A recognisable old password in the subject line feels devastating and means nothing about your website — it came from a breach of some unrelated service years ago. If you still use it anywhere, change it, and then ignore the email.

Signs it might be real

It's specific. A named file, a full URL to a page on your site, a date. Go and look at that path. If the file is there and you didn't put it there, the email is right.

It came through a channel you can verify. A ticket visible in your hosting account, an alert inside Search Console, a notice from a plugin you actually installed.

It matches something you'd already half-noticed. Slow pages, a spike in traffic to URLs you don't recognise, contact form spam, customers mentioning odd redirects. My guide to detection indicators lists what these look like.

Your host suspended you. That's not a warning, it's the consequence — and it's real. I've written separately on getting a suspension lifted.

The extortion email specifically

Don't pay. These campaigns work on volume: send the same threat to fifty thousand addresses, and a handful of people pay for something the sender never had. Paying also marks you as someone who pays, which tends to invite a second round.

The common variants threaten to deface your site, to leak a customer database, to flood you with junk traffic, or to report you to Google for something you didn't do. What they nearly always lack is any evidence. Ask yourself what the sender has actually shown you. If the answer is nothing — no sample record, no file, no screenshot of anything that couldn't be seen from the outside — you're looking at a form letter.

That said, verify rather than assume. Occasionally an extortion email follows a genuine compromise, and the sender is simply monetising access they already have. The five-minute check above settles it, and it settles it far more reliably than reading the email again.

If you do hold customer data and you find genuine evidence of a breach, that shifts from an IT problem to a legal one, with notification obligations that vary by where your customers live. Talk to someone qualified in your jurisdiction rather than guessing.

The "we found problems, we can fix them" pitch

These deserve their own mention because they're not quite scams and not quite honest. A firm scans a large list of sites automatically and emails whatever comes back. The findings are often technically true and practically meaningless: a version number visible in your page source, a missing security header, an entry on some obscure blacklist that stopped mattering years ago. Sometimes they're outright wrong, flagging a false positive that any real check would clear.

You don't have to write them off, and you certainly don't have to hire them. Take the specifics, verify them yourself, and decide from there. The one thing not to do is grant access to anyone who cold-emailed you. Whatever the state of your site before that decision, handing control to an unverified stranger reliably makes it worse.

What to do once you know

If it was fake, delete it. Don't reply, don't unsubscribe, don't engage — replying only confirms a live address. Report it to your mail provider as phishing if you like, and move on.

If it was real, stop reading email and start working. My first-hour checklist lays out the order: take a full backup before you change anything, rotate your passwords, then find how they got in rather than just cleaning up what they left. If Google has already labelled you, the "this site may be hacked" guide covers getting that removed.

And if you'd rather have someone confirm it either way, that's a fair thing to want. Send me what you received and I'll tell you straight whether it's worth worrying about — that conversation is free, and quite often the answer is that you can safely delete it.

Common questions

I got an email saying my website was hacked. Is it real?

Usually not, but verify rather than assume. Most unsolicited emails of this kind are automated sales outreach or extortion sent in bulk to thousands of domains. The test is specificity: a genuine finding cites a file path, a URL or a detection name, while a fake stays vague. Never click links in the message. Instead check Google Search Console directly, search Google for site:yourdomain.com and look for pages you did not create, and load your own site on a phone while logged out.

Should I pay if someone emails demanding bitcoin over my website?

No. These campaigns rely on volume, sending identical threats to enormous mailing lists in the hope that a few recipients pay for access the sender never had. Paying also identifies you as someone who pays and tends to invite a second demand. Ask what evidence you were actually shown; if there is no sample data, no file path and nothing that could not be seen from outside your site, it is a form letter. Verify your site independently, then delete the email.

The email included one of my real passwords. Does that mean my site is hacked?

Almost certainly not. That password came from a data breach of some unrelated service, and those credential lists are traded freely. Seeing it is alarming but tells you nothing about your website. If you still use that password anywhere, change it there, and enable two-factor authentication where you can. Then treat the email itself as spam.

Does Google email site owners about malware?

Not directly in the way these scam emails imply. Genuine notifications about a compromised site appear in Google Search Console under Security Issues, and that report is the authoritative source. If an email claims to be from Google, ignore its links and log into Search Console yourself by typing the address. If the report is empty, Google has not flagged your site.

A company emailed saying they scanned my site and found vulnerabilities. Should I hire them?

Take the specifics, verify them yourself, and decide without any time pressure. These pitches come from automated scanners run across large lists of domains, and the findings are often technically true but practically minor, such as a visible version number or a stale blacklist entry. Some are simply wrong. Whatever you decide, never grant control panel or admin access to someone who cold-emailed you.