Hacked Site: Spam Removed and the Way In Closed
Your site looks fine to you. Google is showing pages about pills, watches or casinos. The attacker hid it from you deliberately.
Why cleaned sites get re-infected
Removing the pages is the easy half. If the way in is still open, it comes back better hidden.
-
Something gets in
An outdated plugin, a reused password, or a backdoor sitting in a file that looks legitimate.
-
Spam is shown to Google only
You browse the site and it looks normal. Search your brand and there are hundreds of pages you never wrote.
-
The route gets closed
Spam removed, backdoors deleted, credentials rotated, and Google told the site is clean again.
Your site looks completely normal. Then you search your own brand and Google shows pages about pharmaceuticals, replica watches or casinos.
You have been hacked, and the attacker was careful. They hid it from you and showed it to Google.
Every day it stays there costs you more.
The Honest Version: Cleaning the Pages Is the Easy Half
Removing spam is not fixing the hack
Anyone can delete the injected pages. If the way in is still open, they come back within days, often within hours, and usually better hidden the second time.
The hard part is the entry point
An outdated plugin, a stolen password, a compromised hosting account, or a backdoor left in a file that looks legitimate. Until that is found and closed, cleanup is temporary.
Why you did not notice
Good attacks show spam only to search engines and to visitors arriving from search. Log in and browse normally and everything looks fine, which is why most people find out from a customer or from Search Console.
What This Usually Looks Like
The common patterns, and how they announce themselves.
Pharma and replica spam
Hundreds of injected pages selling pills or watches, usually in their own directory.
Japanese keyword hack
Pages in Japanese appearing in your search results, often the first thing anyone notices.
Cloaked redirects
Visitors from Google get sent elsewhere. You click the same link and it works normally.
Spam injected into real pages
Hidden links added to your existing content rather than new pages. Harder to spot.
A security warning in the results
Google marking your listing as hacked or unsafe. Traffic collapses immediately.
A manual action
Google penalising you for content you did not put there.
How the Cleanup Runs
1. Find everything, including what is hidden from you
Checking the site the way a search engine sees it, not the way you see it logged in. That difference is where most of the spam lives.
2. Find the way in
Files, users, scheduled tasks and database entries. This is the step that decides whether it comes back.
3. Remove and close
Spam removed, backdoors deleted, credentials rotated, software updated. All of it, because a single missed backdoor undoes the rest.
4. Tell Google it is clean
Injected URLs removed properly, and a review requested if there is a warning or a manual action. Without this the damage in search outlasts the hack.
Before You Call Anyone
Change your passwords now. Hosting, WordPress, database, FTP. Do it before reading further.
Do not just restore a backup. If the backup was taken after the break-in, you restore the backdoor with it. Very common mistake.
Do not delete everything in a panic. Some of what looks suspicious is legitimate. Deleting the wrong file takes the site offline and makes diagnosis harder.
How to Confirm It Yourself in Five Minutes
If you suspect a hack but are not certain, these three checks will tell you.
1. Search your own site the way Google sees it
Type site:yourdomain.com into Google and look through the results. Injected pages are usually obvious, and they are visible here even though they are hidden from you when browsing normally.
This single check finds most infections.
2. Search for common spam terms on your domain
Try site:yourdomain.com viagra or site:yourdomain.com casino or site:yourdomain.com replica. If anything comes back, you have your answer immediately.
3. Check Search Console for a security notice
Google reports hacked content under Security Issues. If there is a message, the infection is confirmed and Google has already acted on it, which means the clock is running.
What to do the moment you confirm it
Change every password before anything else: hosting, admin, database and FTP. Then stop touching the site. Deleting files at random makes diagnosis harder and can take the site offline without removing the backdoor.
Why Speed Matters More Here Than Anywhere Else
Most SEO problems are patient. This one is not.
The spam keeps getting indexed
Every day it stays live, more injected pages enter the index. Cleaning up after two days is a different job from cleaning up after two months, and the second one costs considerably more.
The security warning does the real damage
Once Google marks your listing as hacked or unsafe, traffic collapses immediately and does not recover until the warning is removed. Browsers may also block the site entirely, which affects direct visitors as well as search.
And trust takes longest to return
Rankings usually recover reasonably quickly after a clean fix. What takes longer is customers who saw the warning. That is the part nobody can bill for and nobody can rush.
How Sites Actually Get In Trouble
Almost nobody is targeted personally. Most infections are automated, scanning the whole web for one of a handful of weaknesses.
Outdated plugins and themes
The most common route by a wide margin. A known weakness is published, automated tools start scanning for it within hours, and any site that has not updated is found. This is why updates matter more than any security plugin.
Reused or weak passwords
If your admin password appears in any past data breach, it is already in the lists these tools try. No amount of site security helps if the front door key is public.
Abandoned plugins
Software that no longer receives updates is a permanent open weakness. If a plugin has not been updated in two years, it is a liability regardless of whether it still works.
Shared hosting neighbours
On cheap shared hosting, an infection on somebody else’s site can sometimes reach yours. Rare, and worth knowing about when it is the only explanation left.
The pattern behind all of these
None of them require anyone to have singled you out. That is why sites with no traffic still get hacked, and why the answer is maintenance rather than obscurity.
Price and Turnaround
Scope |
Price |
Turnaround |
|---|---|---|
Standard site, clear infection |
$699 |
2 – 4 days |
Complex or repeated infection |
$1,099 |
1 week |
Cleanup plus security warning removal |
From $1,299 |
1 – 2 weeks |
Includes finding the entry point, not just removing the spam. If it comes back within thirty days from the same route, I fix it again at no charge.
Common Questions
How fast can you start?
Same day where possible. This is the one job where waiting genuinely costs you, because the spam keeps getting indexed.
Will my rankings recover?
Usually, if it is cleaned quickly and Google is told. A hack that sat for months does more lasting damage.
Can I just restore a backup?
Only if you are certain it predates the break-in, and most people are not. Restoring the backdoor is the classic mistake.
How did they get in?
Usually outdated software or a reused password. Finding out exactly is part of the job, because guessing means it recurs.
Will it happen again?
Not through the same route once it is closed. I will also tell you the two or three things that keep it from happening a different way.
Search your brand name right now
If you see pages you did not write, send me a screenshot. I will tell you free how bad it is and how fast it needs handling.
Or email info@shazzseo.com