We recently caught a quiet security breach on one of our servers, and it’s a good lesson in how modern SEO attacks operate.
It started when a search for our domain pulled up thousands of indexed spam pages filled with foreign gambling keywords. Direct visitors saw our real site, but Googlebot was seeing something completely different.
This technique is called SEO Cloaking.
Attackers modified our web server rules to intercept incoming search engine crawlers, quietly serving them hidden spam pages while keeping human traffic clean to avoid early detection.
How They Got In
An outdated, unused WordPress plugin sitting on a neglected subfolder. One unpatched file was all it took to elevate permissions.
What We Did
- Purged the exploit and scrubbed the server configuration.
- Implemented automated file-integrity monitoring (FIM) to flag unauthorized config edits instantly.
- Hardened file permissions and wiped all unmaintained plugin code.
- Requested re-indexing via Google Search Console.
Security isn't a set-it-and-forget-it deal—it's routine maintenance.
Quick check for your site: Search
site:yourdomain.comin Google right now. If you see pages or languages you don't recognize, you have an active injection.
Need a Second Pair of Eyes?
Want a second set of eyes on your WordPress setup or server security? Reach out to our team—we’ll help ensure your infrastructure stays locked down.