SEO Recovery After the Website Was Hacked
A hack filled the client's website with spam pages, injected links, malicious redirects and thousands of fake indexed URLs, damaging both rankings and trust. Meek Media cleaned the site, hardened its security, cleared the spam from Google's index, rebuilt the sitemaps and then worked through SEO recovery once the site was verifiably clean.
- Client
- Business website (name withheld)
- Services
- Technical SEO Services, SEO Services
- Privacy
- Client name withheld
How do you recover SEO after a website is hacked?
Clean first, then recover. Remove every spam page, injected link and malicious redirect, close the vulnerability that let attackers in, and make spam URLs return 404 or 410 so Google drops them. Rebuild sitemaps with only legitimate pages, request a review if Google flagged the site, then restore normal SEO work.
How did the hack damage the site's rankings and trust?
The attack went well beyond defacement. Spam pages had been added to the site, links had been injected into legitimate content, and malicious redirects were sending some visitors to places the business would never endorse. Google had indexed thousands of fake URLs, so searches connected to the site could surface content the business had never published.
This kind of compromise hurts in several ways at once. Rankings suffer because the site's content and link signals are polluted, and hacked spam is exactly what Google's systems are designed to demote. Trust suffers because visitors who land on spam or get redirected away rarely come back, and browsers or search results may warn people before they visit. Redirects are often built to be hard to spot, for example showing spam only to search engine crawlers or only to visitors arriving from search results, which means the site owner can browse normally and see nothing wrong. Recovery therefore had to happen in the right order: find everything, remove it, stop it happening again, then clear the index and rebuild search performance on a foundation that could be trusted.
What we found
- Spam pages had been created on the site
- Links had been injected into legitimate content
- Malicious redirects were sending visitors elsewhere
- Thousands of fake URLs were indexed in Google
- Rankings and trust had both been damaged
- Sitemaps no longer reflected the real site
How did Meek Media clean up and recover the site?
We sequenced the recovery the way Google's own guidance for hacked sites suggests: contain and clean before trying to recover rankings. SEO work on a site that is still compromised is wasted, because the spam simply returns. Once the site was clean and hardened, index cleanup, sitemap rebuilding and ranking recovery could proceed with confidence.
-
1
Identify the full scope of the compromise
We catalogued every symptom of the hack: spam URLs found through crawls and Google's index, injected links inside legitimate pages, and redirects that fired only under certain conditions. Pages were fetched as a search crawler and as a visitor arriving from search, since hacked redirects are often cloaked from site owners. Search Console's Security Issues and Manual Actions reports were checked for anything Google had already flagged.
-
2
Remove the spam and malicious code
Spam pages, injected links and redirect code were removed from files, the database and server configuration, wherever they had been planted. Where clean versions existed, compromised files were replaced with them rather than edited line by line. Every legitimate page was checked afterwards to confirm the injected content was gone and nothing important had been damaged in the cleanup.
-
3
Harden security and close the entry point
Cleaning a site without fixing how attackers got in usually leads to reinfection. The vulnerability was identified and closed, software was updated, all passwords and access credentials were changed, unknown user accounts were removed and file permissions were tightened. Hardening reduces the chance of a repeat attack and is a prerequisite for asking Google to reassess the site.
-
4
Clean up the index
Spam URLs were made to return 404 or 410 so Google would drop them as it recrawled, rather than redirecting them to real pages. Search Console's Removals tool can hide the most harmful URLs temporarily while permanent removal is processed. The spam URLs were not blocked in robots.txt, because Google must be able to crawl them to see they are gone.
-
5
Rebuild the sitemaps
The XML sitemaps were regenerated from scratch to list only legitimate, canonical pages, then resubmitted in Search Console. A clean sitemap helps Google rediscover the real site quickly and makes it easy to compare what was submitted against what is indexed. Regenerating them from scratch, rather than editing the old files, guarantees that nothing planted by the attackers carries over.
-
6
Request review and recover SEO
A review request to Google only makes sense once the cleanup is complete and verifiable, and only if Google has flagged the site. Recovery work then focused on the real site: checking that important pages were indexed and correctly titled, restoring internal links affected by the cleanup and monitoring rankings and index coverage to confirm the spam was gone and legitimate pages were regaining visibility.
What We Delivered
- Full inventory of spam pages, injected links and malicious redirects
- Malware and spam removal across files and database
- Security hardening and credential reset
- Index cleanup of fake URLs with 404 or 410 responses
- Rebuilt and resubmitted XML sitemaps
- Security Issues and Manual Actions checks in Search Console
- Post-recovery indexing and ranking monitoring
What Other Teams Can Learn From This
Look at the site the way attackers hide it
Hacked sites often look perfectly normal to their owners. Spam and redirects may appear only to search crawlers, to visitors arriving from search results, or on mobile devices. If rankings drop suddenly or strange URLs appear in search, check the site from those perspectives and review what Google has actually indexed.
Order matters in recovery
Cleaning the index before closing the vulnerability, or requesting a review before the site is fully clean, wastes time and can repeat the whole cycle. Contain, clean, harden, then recover. It feels slower, but it is the only order that holds, because the spam cannot return once the way in is shut.
Let spam URLs die properly
Redirecting thousands of spam URLs to your homepage or blocking them in robots.txt feels tidy but slows cleanup. A clean 404 or 410 tells Google plainly that the page no longer exists, and it needs to be able to crawl the URL to see that. Patience here pays off, because the fake URLs fade out as Google recrawls them.
Frequently Asked Questions
How do I know if my website has been hacked for SEO spam?
Common signs include unfamiliar pages appearing in Google results for your domain, spammy titles or foreign-language snippets, sudden ranking drops, warnings in browsers or search results, and messages in Search Console's Security Issues report. Some spam and redirects only show to search engines or search visitors, so checking what Google has indexed is essential.
Should hacked spam URLs be redirected or removed?
They should usually return a 404 or 410 status so Google drops them from the index as it recrawls. Redirecting spam URLs to real pages can keep them lingering and confuses signals. The Removals tool in Search Console can hide urgent URLs temporarily while permanent removal takes effect.
Will rankings come back after a hacked site is cleaned?
Recovery is common once the spam is fully removed, the vulnerability is closed and Google has recrawled the site. Timing varies with how widespread the hack was and how quickly Google reprocesses the cleaned pages. Rushing a review request before the cleanup is complete tends to slow things down.
Do I need to ask Google to review my site after a hack?
Only if Google has flagged it. If Search Console shows a security issue or a manual action, request a review after the site is fully cleaned and secured. If nothing is flagged, fixing the site and letting Google recrawl it, helped by a clean sitemap, is the usual route to recovery.
Related Case Studies
Rebuilding a 10,000+ Page Website Without Losing SEO
A website with more than 10,000 pages needed a complete redesign, and thousands of those pages were indexed and ranking. Meek Media planned the rebuild so search value carried across: URL architecture, page templates, metadata migration, redirects, structured data, internal linking and a structured launch QA process that checked the new site before and after it went live.
Read the case study →
Recovering a Website After a Google Algorithm Traffic Collapse
After a major Google update, this site lost 60–80% of its organic traffic. Meek Media audited everything that shapes how Google judges a site: content quality, backlinks, site architecture, duplicate pages, search intent and technical SEO. We then rebuilt the organic strategy around the pages that deserved to rank, rather than chasing the update itself.
Read the case study →
Core Web Vitals Rescue for a High-Traffic Website
This website had strong traffic but failed Core Web Vitals. Heavy scripts, large images, layout shifts, slow server responses and third-party integrations were all dragging down the experience. Meek Media tackled the problem on two fronts, optimising the front-end architecture and the server infrastructure behind it, so pages loaded faster, responded quicker and stayed visually stable.
Read the case study →
Facing a similar problem?
Every engagement starts with a free audit. We find what is holding your site back, show you the fix, and scope the work to your goals before you commit.