Japanese keyword hack: strange pages in my Google results
The Japanese keyword hack fills your site with hundreds or thousands of spam pages in Japanese, usually selling counterfeit goods. The same attack appears with pharmacy and casino content. Your real pages often keep working normally, which is why owners usually find out from Google rather than from their own site.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- Japanese titles and text in your Google results when you search "site:yourdomain.com"
- Pages you never created, often in folders with random names
- Search Console reporting a spike in indexed pages, or new keywords you don't recognize
- An administrator account in WordPress that nobody on your team created
- Your homepage and real pages still looking completely normal
Why it happens
An out-of-date plugin or theme
The usual way in. A known vulnerability in outdated code lets an attacker upload files.
Generated spam pages
The malware creates pages on the fly, so the spam doesn't sit in your WordPress Pages list where you'd see it.
Cloaking
The spam is shown to search engines but often hidden from normal visitors, which is why it shows in Google and not in your browser.
Injected sitemaps
Extra sitemap files are added so Google indexes thousands of spam pages quickly.
A rogue admin account
Attackers add their own administrator so they keep access even after a password change.
What to do right now
Do this
- Search "site:yourdomain.com" on Google to see the scale of it
- Check Users in WordPress for accounts you don't recognize
- Check Search Console for a sudden jump in indexed pages and for new sitemaps
- Change all passwords and get the site cleaned
Don't do this
- Don't delete the pages one at a time. They regenerate while the malware is still there
- Don't delete unknown admin accounts and assume it's over. The backdoor is usually in the files
- Don't block Googlebot to hide the spam. That hurts your real pages too
How we fix it
- 1Find and remove the files generating the spam, including scheduled tasks that rebuild them
- 2Clean injected database content and remove rogue accounts
- 3Remove the fake sitemaps and repair your real one
- 4Ask Google to drop the spam URLs and re-crawl your genuine pages
- 5Close the vulnerability that let them in, then update and harden the site
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
Why is it in Japanese?
The attackers are selling counterfeit goods to a Japanese-speaking audience and are borrowing your domain's reputation to rank. Pharmacy and casino versions of the same attack are just as common.
My site looks fine. Is it really hacked?
Yes. This attack deliberately hides from ordinary visitors and shows itself mainly to search engines, which is why the evidence turns up in Google rather than on your screen.
Will all those spam pages disappear from Google?
They drop out once the pages are gone and Google re-crawls the site. We speed that up by cleaning the sitemaps and requesting removal, but the final timing is Google's.
Other symptoms
- Visitors get redirectedYour site sends people to spam, scam, or adult sites, often only on mobile or from Google.
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- You're locked outYour admin password stopped working, or there are admin users you didn't create.
- It keeps coming backYou cleaned the site, and the malware was back within days.
- Card skimmer on checkoutCustomers' card details are being captured at checkout by injected code.
- Fake login pagesSomeone is hosting fake bank or Microsoft login pages in a hidden folder on your site.
- Pharmacy spam in GoogleYour search listings mention pills or pharmacies, even though your pages look normal.
- A scanner says I'm infectedWordfence, Sucuri, or another plugin reports malware you can't get rid of.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)