Skip to content
WP Hack FixEst. 2005

Japanese keyword hack: strange pages in my Google results

The Japanese keyword hack fills your site with hundreds or thousands of spam pages in Japanese, usually selling counterfeit goods. The same attack appears with pharmacy and casino content. Your real pages often keep working normally, which is why owners usually find out from Google rather than from their own site.

We reply within 1 business day (Mon–Fri, 9–5 ET)

What you're seeing

  • Japanese titles and text in your Google results when you search "site:yourdomain.com"
  • Pages you never created, often in folders with random names
  • Search Console reporting a spike in indexed pages, or new keywords you don't recognize
  • An administrator account in WordPress that nobody on your team created
  • Your homepage and real pages still looking completely normal

Why it happens

An out-of-date plugin or theme

The usual way in. A known vulnerability in outdated code lets an attacker upload files.

Generated spam pages

The malware creates pages on the fly, so the spam doesn't sit in your WordPress Pages list where you'd see it.

Cloaking

The spam is shown to search engines but often hidden from normal visitors, which is why it shows in Google and not in your browser.

Injected sitemaps

Extra sitemap files are added so Google indexes thousands of spam pages quickly.

A rogue admin account

Attackers add their own administrator so they keep access even after a password change.

What to do right now

Do this

  • Search "site:yourdomain.com" on Google to see the scale of it
  • Check Users in WordPress for accounts you don't recognize
  • Check Search Console for a sudden jump in indexed pages and for new sitemaps
  • Change all passwords and get the site cleaned

Don't do this

  • Don't delete the pages one at a time. They regenerate while the malware is still there
  • Don't delete unknown admin accounts and assume it's over. The backdoor is usually in the files
  • Don't block Googlebot to hide the spam. That hurts your real pages too

How we fix it

  1. 1Find and remove the files generating the spam, including scheduled tasks that rebuild them
  2. 2Clean injected database content and remove rogue accounts
  3. 3Remove the fake sitemaps and repair your real one
  4. 4Ask Google to drop the spam URLs and re-crawl your genuine pages
  5. 5Close the vulnerability that let them in, then update and harden the site

Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing

Questions

Why is it in Japanese?

The attackers are selling counterfeit goods to a Japanese-speaking audience and are borrowing your domain's reputation to rank. Pharmacy and casino versions of the same attack are just as common.

My site looks fine. Is it really hacked?

Yes. This attack deliberately hides from ordinary visitors and shows itself mainly to search engines, which is why the evidence turns up in Google rather than on your screen.

Will all those spam pages disappear from Google?

They drop out once the pages are gone and Google re-crawls the site. We speed that up by cleaning the sitemaps and requesting removal, but the final timing is Google's.

Other symptoms

Hacked right now? Let's get it fixed.

Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)