Pharmacy spam in my Google results
The pharma hack turns your site into advertising for online pharmacies. What makes it different from most spam infections is that it often doesn't create many new pages at all: it rewrites the titles and descriptions of the pages you already have, so your page count never jumps and nothing in your dashboard looks wrong. The evidence shows up in Google, or in an embarrassed email from a customer.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- Your listings in Google mention pharmaceutical brand names, pills, or an online pharmacy
- The title or description in search results doesn't match what's actually on the page
- Your homepage and pages look completely normal when you visit them
- Searching "site:yourdomain.com" shows pharmacy text attached to your real pages, sometimes with no new pages at all
- A customer or colleague tells you before you notice it yourself
- Search Console reporting keywords you have never written about
Why it happens
Cloaking
The malware checks who is asking. Search engine crawlers are served the spam version of the page, while ordinary visitors and logged-in administrators get the normal one, which is why the site looks fine to you.
Injected titles and meta descriptions
Rather than publishing new pages, this hack commonly rewrites the title and description your existing pages send to search engines. Nothing changes in the WordPress editor, so the page content you can see is genuinely unchanged.
Hidden links and text
Blocks of pharmacy links added to pages, footers, or widgets and then hidden with CSS so search engines read them and visitors don't see them.
Code in the database, not just in files
Much of this infection lives in database records, including options and post content, which is why file-only scans and reinstalling WordPress core frequently miss it.
An outdated plugin or theme
The usual entry point, along with a stolen administrator account. Once in, the attacker adds a backdoor so the spam can be restored after a shallow cleanup.
What to do right now
Do this
- Search "site:yourdomain.com" on Google and read the titles and descriptions carefully, since that is where this hack shows itself
- Check Search Console for the Security Issues report and for query terms you never targeted
- Use the URL Inspection tool in Search Console to see how Google renders one of your pages, which reveals cloaked content your browser doesn't show
- Change your WordPress and hosting passwords, and check for administrator accounts you don't recognize
Don't do this
- Don't edit the titles back by hand. They are being generated for crawlers, so your correction never reaches the spam version
- Don't reinstall WordPress core and call it done. The injected content usually lives in the database and in plugin or theme files, which a core reinstall doesn't touch
- Don't block Googlebot to stop the spam being seen. That removes your genuine pages from search along with the spam
How we fix it
- 1Confirm exactly what search engines are being served, so we're working from the cloaked version rather than the clean one you see
- 2Remove the injected code from files and from the database, including rewritten titles, descriptions, and hidden link blocks
- 3Clear any spam pages and fake sitemap files the infection created, and repair your real sitemap
- 4Find and remove the backdoor and close the vulnerability that allowed it, then remove rogue accounts and scheduled tasks
- 5Ask Google to re-crawl your genuine pages, and request a security review if your site has been flagged
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
How is this different from the Japanese keyword hack?
They're the same family of attack with different goals. The Japanese keyword hack usually publishes large numbers of new spam pages selling counterfeit goods, so your indexed page count jumps. The pharma hack more often rewrites what your existing pages tell search engines, so the page count stays the same and the spam appears attached to your real URLs. If you're seeing hundreds of new pages, our Japanese keyword hack page describes that version.
Why can't I see the spam on my own pages?
Because you're not who it's shown to. The code checks whether the visitor looks like a search engine crawler, and often keeps quiet for logged-in administrators. Search Console's URL Inspection tool shows you the version Google gets, which is usually the moment it becomes obvious.
Will my rankings recover once it's cleaned?
Most sites do recover once the spam is gone and Google re-crawls the pages, though it isn't immediate and we can't control Google's timing. Cleaning it early makes a real difference, because the longer the spam stays indexed, the more of your listings are affected.
Other symptoms
- Visitors get redirectedYour site sends people to spam, scam, or adult sites, often only on mobile or from Google.
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Strange pages in GoogleJapanese, pharma, or casino pages you never created show up under your domain.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- You're locked outYour admin password stopped working, or there are admin users you didn't create.
- It keeps coming backYou cleaned the site, and the malware was back within days.
- Card skimmer on checkoutCustomers' card details are being captured at checkout by injected code.
- Fake login pagesSomeone is hosting fake bank or Microsoft login pages in a hidden folder on your site.
- A scanner says I'm infectedWordfence, Sucuri, or another plugin reports malware you can't get rid of.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)