How the attack works
Attackers target queries with commercial urgency and low-quality incumbents: cracked software, invoice or form templates, driver downloads, tax deadlines, breaking news. They mass-produce pages, often on compromised domains with existing authority, and cloak - showing search crawlers clean content while sending real visitors to a payload.
Why legitimate sites get used
A hacked WordPress install with an outdated plugin is cheaper than buying authority. Typical footprints are a hidden directory of spam pages, injected redirects that only fire for visitors arriving from a search engine, and a modified sitemap that quietly submits the new pages for indexing.
Signs your site has been poisoned
A sudden jump in indexed pages in Search Console, impressions for queries unrelated to your business, 'Deceptive site ahead' warnings, unexpected sitemap entries, or Search Console reporting a manual action for hacked content. The Security Issues report is the fastest confirmation.
Cleaning up and recovering
Take the site offline or into maintenance mode, restore from a clean backup, patch every plugin and rotate all credentials including database and FTP, remove injected files and cron jobs, then request a review in Search Console. Removing the pages without closing the entry point guarantees reinfection.
Prevention that actually matters
Keep the CMS and plugins updated, enforce two-factor authentication on admin accounts, monitor indexed page counts weekly, alert on unexpected sitemap growth, and review server logs for crawler-only content differences. Automated crawl monitoring catches most of this within a day.