Table of Contents
- Introduction
- Why hosts suspend accounts for malware
- What your host usually tells you (and what it usually doesn't)
- What to do step by step
- Restore a clean backup, or clean the current site?
- How to stop it from happening again after reactivation
- When to get professional help
- Conclusion
Introduction
You open your site and it doesn't load. You check your email and find a message from your host: "We have suspended your account due to malicious activity" or "malware has been detected on your site." Your site is down right now, your customers can't access it, and you probably have no idea which file is the problem.
This is one of the most urgent situations you can run into, because it's not just a security problem: it's a business standing still until you fix it. Let's look at why this happens, what information to ask your host for, and what to do step by step to reactivate your account without it getting suspended again a few days later. If you want the full picture of what to do when your WordPress gets hacked, here's the general guide: My WordPress Site Was Hacked: What to Do Step by Step.
Why hosts suspend accounts for malware
A shared host runs dozens or hundreds of sites on the same server. If your WordPress is hacked and starts sending mass spam, consuming resources abnormally, or attempting to attack other sites on the same server, it puts every other customer on that server at risk, not just you.
That's why most hosts follow a "suspend first, ask later" policy: as soon as they detect suspicious activity, they cut access immediately to protect their infrastructure, often before giving you any detailed explanation of what happened.
What your host usually tells you (and what it usually doesn't)
The suspension email is usually generic: "malicious activity detected," "malware on your account," "phishing content." That's enough to know there's a real problem, but hosts almost never tell you exactly which file, plugin, or vulnerability was exploited.
That means the responsibility for diagnosing and cleaning the problem falls entirely on you: the host isn't going to do that work for you — they'll only tell you whether your site is still "dirty" or not once you request reactivation. One of the first things worth checking is whether there are admin users you don't recognize, since that's usually the backdoor the attacker keeps using even after your host has blocked public access.
What to do step by step
- Contact support and ask for as much detail as possible: what type of activity they detected, on what date, and whether they can share logs or the specific file that triggered the alert. Not every host provides this, but it's worth asking.
- Don't request reactivation before cleaning up. If they reactivate your account with the malware still present, it's very likely to get suspended again within hours or days.
- Diagnose and fully clean the malware before requesting reactivation, identifying the entry vector, not just the visible symptoms.
- Change every password (hosting, WordPress, FTP, database) as part of the process, not as an optional step.
- Document what you've cleaned up when requesting reactivation — some hosts ask for a summary of what was done before lifting the suspension.
Restore a clean backup, or clean the current site?
There's an important decision here that a lot of people don't think through carefully: if your host has a backup from before the infection, it can look like the fastest fix. But be careful — if you restore a backup from weeks ago, you lose all the content, orders, or changes made after that date. Before choosing this route, it's worth comparing how much recent content you'd lose against doing a targeted cleanup of the current site, which keeps all your content and only removes what's malicious.
How to stop it from happening again after reactivation
Once your account is reactivated, the work isn't done. If the entry vector that allowed the original hack is still open (a vulnerability, a weak password, an outdated plugin), it's only a matter of time before it happens again and your host suspends you once more. Hardening — stronger passwords, updating everything, blocking file editing from the dashboard, enabling two-factor authentication — is what separates a one-off reactivation from a permanent fix.
When to get professional help
If your account is suspended right now, every hour that passes is a business standing still. I can diagnose the problem, clean the malware, help you put together the information your host needs to reactivate your account, and harden your security so it doesn't happen again. Free 24h diagnosis here: Fix a hacked WordPress site
Conclusion
A malware suspension isn't just a technical formality: it's your business on hold until you fix it. Asking your host for the right information, fully cleaning up before requesting reactivation, and hardening security afterward are the three steps that keep this situation from repeating itself a few weeks later.