Japanese keyword hack

Japanese SEO spam in your Google results

Search for site:yourdomain.com and you see hundreds of pages in Japanese selling counterfeit goods. The pages do not exist in your admin panel, but Google has indexed them. This is the Japanese keyword hack.

Free, passive check — no sign-up. Results in about 20 seconds.

How the Japanese keyword hack works

Attackers place a script on your server that generates spam pages on the fly. Those pages are usually shown only to search engine crawlers, so visitors and the site owner see a normal website. Often the attacker also adds their own account to your Google Search Console property and submits a spam sitemap, so new pages get indexed quickly.

Signs you are affected

Check from the outside

Our free security check fetches your home page as both a browser and a crawler, inspects your sitemap for spam URLs and detects Japanese or pharma spam content that should not be there.

Cleaning it up

  1. Remove unknown users and sitemaps from Google Search Console before anything else.
  2. Find the generator script and every backdoor: compare files against clean WordPress, theme and plugin copies.
  3. Check .htaccess, index.php and the database for injected rules and content.
  4. Rotate all passwords, database credentials and WordPress salts; update everything.
  5. Make the spam URLs return 404 or 410 so Google drops them, and submit a clean sitemap.
  6. Monitor indexed pages for several weeks — the spam takes time to leave the index.
Deleting spam pages alone does not help: the generator recreates them. The backdoor has to go.

Frequently asked questions

How long until the Japanese pages disappear from Google?

After the cleanup and with the spam URLs returning 404 or 410, most pages drop out within a few weeks. Large infections can take longer; a removal request in Search Console speeds up the worst ones.

Is my customer data at risk?

The spam itself targets search traffic, but whoever planted it had code execution on your server. Treat it as a full compromise and rotate every credential.

Can a security plugin fix it?

Plugins catch known file signatures but often miss database injections, server rules and Search Console takeovers. A manual review is usually needed.

Need it fixed?

We clean compromised websites, close the entry point and give you a written report of what we found and changed.