What should you communicate to your customers after a website hack?
An inaccessible website, an unusual page displaying unexpected content, customers redirected to a fake payment page… When a website is hacked, the first reaction is obviously to try to stop the attack and restore the site.
But another question quickly arises: what should you tell your customers? Should you warn them immediately? Wait until you know more? Publish a message on your website? And above all: in which cases are you legally required to communicate?
Because after a cyberattack, communication is not only about protecting the company's image. It can also enable your customers to take immediate action to protect themselves. Here are the right steps to take :
Before communicating, understand what actually happened
When a hack is discovered, the first pieces of information are often incomplete. Your website may be inaccessible without your customers' data having been accessed. Conversely, a website may continue to operate perfectly while a hacker has managed to access its database discreetly.
Before making any public statement, you should therefore quickly bring together the people capable of establishing the initial facts: your web or IT provider, the company director and, depending on your organization, your communications manager, DPO or legal advisor.
The objective is not to wait until the entire investigation is complete, but to answer a few essential questions:
- What happened?
- Which part of the website is affected?
- Is the attack still ongoing?
- Could personal data have been accessed, modified or stolen?
- Which users may be affected?
- Do they need to take immediate action?
Cybermalveillance.gouv.fr recommends that companies affected by a cyberattack set up a crisis management team, maintain a timeline of events and preserve evidence of the attack. This initial analysis is important for resolving the technical issue, but also for avoiding a common mistake in crisis communication: turning a hypothesis into a certainty too quickly.
Saying in the first few hours that “no data has been compromised” may seem reassuring. But if the investigation later proves otherwise, the cybersecurity issue also becomes a matter of trust.
It is better to acknowledge what you do not know yet than to reassure people with information you cannot confirm.
Check whether the hack must be reported to the CNIL
This is probably one of the most important questions to ask after a website hack. And one distinction is essential: A hacked website does not automatically mean that you need to report the incident to the CNIL.
The CNIL becomes involved when there is a personal data breach. In other words, when an attack results in, among other things, the loss, modification, destruction, unavailability or unauthorized access to data relating to individuals.
Let's take two examples.
👉🏻 A hacker modifies the homepage of a corporate website for a few minutes without accessing any personal data. The website has indeed been hacked, but there is not necessarily a personal data breach.
👉🏻 Conversely, if a hacker accesses the customer database of an e-commerce website and retrieves names, email addresses, passwords or contact details, this is clearly a personal data breach.
When should you notify the CNIL?
The rule depends on the level of risk created for the individuals concerned. If the breach is unlikely to result in a risk to their rights and freedoms, it must be documented internally, but there is no need to notify the CNIL. If it does present a risk to individuals, the company must notify the CNIL without undue delay and, where possible, no later than 72 hours after becoming aware of the breach.
This deadline does not mean that the entire technical analysis must be completed within three days. The CNIL specifically states that you should not wait until you have all the information if the breach has already been established: an initial notification can be submitted and then supplemented when the investigation provides new information.
When should you also notify customers?
An additional step is required when the breach is likely to result in a high risk to the individuals concerned. In this case, they must also be informed without undue delay, subject to the exceptions provided for by the GDPR. The level of risk depends in particular on the nature of the data exposed, its sensitivity, the number of people affected and the potential consequences.
The leakage of a password, banking information or information that could enable identity theft obviously does not present the same risk as the exposure of information that was already publicly available.
The CNIL therefore summarizes the approach as follows:
- no risk: internal documentation;
- risk: documentation + notification to the CNIL;
- high risk: documentation + CNIL + notification of the individuals concerned.
If in doubt, it is better to quickly consult your DPO, legal advisor or the CNIL rather than let the deadline pass.
Inform first those who need to take action
A cyberattack does not necessarily require immediately publishing a lengthy statement on LinkedIn or on the company's homepage. The priority is to identify who actually needs the information. If customer accounts have been compromised, their owners should be notified first. If a fake payment page may have been displayed on your website, the people who placed an order during the affected period should also be identified as quickly as possible. If your website is simply temporarily unavailable and no data has been compromised, a short message about the service disruption may be sufficient.
The ANSSI specifically recommends adapting communication to the different stakeholders and closely coordinating communication and operational incident management.
The appropriate channel will then depend on the situation: email, phone, social media, a message from another company website, etc. One point to keep in mind, however: if your website or email system is part of the compromised systems, avoid using them blindly to communicate. Your provider should first be able to confirm that the channel you are using is reliable.
Clearly explain what happened… and above all, what the customer should do
When a customer receives a message announcing a hack, they rarely have questions about the technical vulnerability that was exploited. Above all, they want to know: Am I affected? Which data has been compromised? What are the risks? And what should I do?
Your communication should therefore answer these questions directly. When individual notification is mandatory under the GDPR, the CNIL requires that the communication explain, in clear and precise terms:
- the nature of the breach;
- its likely consequences;
- the measures taken to address it or limit its consequences;
- the contact details of a person who can be contacted for further information.
It also recommends adding, where relevant, actions that individuals can take to protect themselves.
For example:
- change their password;
- change the same password on other services if it has been reused;
- monitor transactions carried out on their account;
- remain cautious of future emails or calls using the compromised information;
- contact their bank if payment data may be affected.
The objective is not to find wording that minimizes the incident. It is to provide enough information for customers to understand the situation and take action.
Communicate at the right time, even if everything has not yet been resolved
Cyber crisis communication rarely happens in a single message. In the first few hours, you probably will not yet know the exact origin of the attack, its definitive scope or when the situation will return to normal. That is not necessarily a reason to remain silent. When customers need to take immediate precautions, waiting until the technical analysis is complete may actually increase the consequences of the attack.
An initial message can simply state: “Here is what we know today. Here is what we have already done. Here is what we are still investigating.”
It can then be updated as new information becomes available.
This approach also helps avoid another common mistake: announcing within the first few hours that “the problem will be resolved this afternoon” when no one can yet guarantee it.
In its cyber crisis communication guide, updated in June 2026, the ANSSI recommends communicating based on verified information and regularly updating the various stakeholders throughout the crisis.
Your communication must therefore evolve alongside your level of knowledge.
Once the website is secured, don't forget to close the crisis
Restoring the website is not necessarily the end of the incident. Once the source of the attack has been identified and the risk has been brought under control, it may be useful to issue a final communication to the people who were informed during the crisis.
There is no need to go into every technical detail.
Simply explain:
- what ultimately happened;
- whether the scope has changed since the initial communications;
- the measures that have been implemented;
- whether users still need to take any action;
- and, where possible, that the service has now returned to normal.
This final communication is important. Someone who has been informed about a cyberattack may remain uncertain for several days if they receive no further updates. Confirming that the investigations are complete and that the necessary measures have been taken genuinely helps bring the crisis to an end.
Preparing your communication before you need it therefore remains one of the best ways to communicate effectively when an incident occurs.
When a website is hacked, the instinct may be to communicate as little as possible for fear of worrying customers or damaging the company's image. Conversely, trying to communicate every detail immediately can also create confusion.
The right approach lies somewhere in between: establish the facts, comply with your obligations, quickly notify people when they need to take action, and communicate only what you are able to confirm. The right approach lies somewhere in between: establish the facts, comply with your obligations, quickly notify people who need to take action, and communicate only what you are able to confirm.
And as is often the case in communication, the best time to prepare for a crisis is before it happens. Clarifying your messages, stakeholders and organization in advance allows you to be faster, more consistent and more composed when you actually need to communicate.
Ultimately, this is the same logic we advocate with ComInTime!