---
title: "How to detect, analyze, and recover a hacked site"
manual: "TYPO3 Explained"
version: "main"
permalink: "https://docs.typo3.org/permalink/t3coreapi:security-detect-analyze-repair@main"
source: "Security/HackedSite/Index.rst"
rendered: "2026-09-20T15:52:37+00:00"
---

# How to detect, analyze, and recover a hacked site {#security-detect-analyze-repair}

If your TYPO3 site has been hacked, simply restoring a backup is not enough.
You must determine how the breach happened and take steps to prevent it
from recurring.

This chapter provides a structured response plan, including detection,
containment, investigation, and recovery. These actions help limit damage
and improve future resilience.

**Steps to take when a site got hacked**

-   [Detect a hacked website](https://docs.typo3.org/permalink/t3coreapi:detect-a-hacked-website@main)
-   [Take a hacked website offline](https://docs.typo3.org/permalink/t3coreapi:take-a-hacked-website-offline@main)
-   [Analyzing a hacked site](https://docs.typo3.org/permalink/t3coreapi:analyzing-a-hacked-site@main)
-   [Repair/restore](https://docs.typo3.org/permalink/t3coreapi:repair-or-restore-a-hacked-site@main)
-   [Further actions](https://docs.typo3.org/permalink/t3coreapi:further-actions-after-recovering-from-a-hack@main)
