How the Japanese keyword hack works
Attackers place a script on your server that generates spam pages on the fly. Those pages are usually shown only to search engine crawlers, so visitors and the site owner see a normal website. Often the attacker also adds their own account to your Google Search Console property and submits a spam sitemap, so new pages get indexed quickly.
Signs you are affected
site:yourdomain.comin Google shows Japanese titles and descriptions.- Unknown owners or sitemaps appear in Google Search Console.
- Your sitemap lists thousands of URLs you never created.
- Traffic from organic search drops while indexed page count rises.
- Random-looking PHP files in the web root or in
wp-content, or a modified.htaccess.
Check from the outside
Our free security check fetches your home page as both a browser and a crawler, inspects your sitemap for spam URLs and detects Japanese or pharma spam content that should not be there.
Cleaning it up
- Remove unknown users and sitemaps from Google Search Console before anything else.
- Find the generator script and every backdoor: compare files against clean WordPress, theme and plugin copies.
- Check
.htaccess,index.phpand the database for injected rules and content. - Rotate all passwords, database credentials and WordPress salts; update everything.
- Make the spam URLs return
404or410so Google drops them, and submit a clean sitemap. - Monitor indexed pages for several weeks — the spam takes time to leave the index.
Frequently asked questions
How long until the Japanese pages disappear from Google?
After the cleanup and with the spam URLs returning 404 or 410, most pages drop out within a few weeks. Large infections can take longer; a removal request in Search Console speeds up the worst ones.
Is my customer data at risk?
The spam itself targets search traffic, but whoever planted it had code execution on your server. Treat it as a full compromise and rotate every credential.
Can a security plugin fix it?
Plugins catch known file signatures but often miss database injections, server rules and Search Console takeovers. A manual review is usually needed.