Start over
Throw everything away and start over.
A small business reported payment issues with its online store. Upon investigation, we found 24,476 hidden spam entries—invisible to visitors but readable by Google. We cleaned up the store in a single pass without losing a single legitimate record.
The company first found us through SEO years ago and later built its own WooCommerce store. During the pandemic, our collaboration slowed down, but we never lost touch. A small follow-up inquiry brought us back to the site—and led us to our findings.
It was no longer possible to complete orders properly in the shop. Credit card payments weren't working. A quick fix was supposed to solve the problem—a routine task, or so it seemed.
The database contained thousands of entries unrelated to the trade. An administrator account that no one knew about. Hidden casino text mixed in with legitimate products. The site wasn't broken—it had been hijacked.
The attackers gain access through a plugin vulnerability. They create a dormant user account and wait.
Hidden casino text is moved to the shop page. Invisible via CSS, but fully readable by Google.
The attackers enter random text into the database. This is how they check to see if anyone responds. No one responds.
New casino posts are added regularly in over ten languages. A new administrator account was created in April 2026.
What the adjustment actually means
Before deleting any data, we verified that the actual store content remained intact. All 23 genuine product categories were unaffected. A file system audit revealed no backdoor code. The attack was carried out exclusively through the database.
// Removed from the database
: spam_pages: 17
, spam_posts: 293 + 82
, spam_categories: 24,476
hidden_divs: 6 // genuine products
rogue_accounts: 2
typo_redirect: 1//
integrity after cleanup
real_categories: 23
file_backdoors: 0
data_loss: 0
status: "clean"
xmlrpc abgeschaltet01 · Prevention is better than cure. An unattended system quietly falls into disrepair. The attack took root during this period of neglect.
02 · Black Hat SEO damages the reputation. No theft of money or data—just abuse of the domain’s reputation. The damage manifests itself in visibility over the years.
03 · Relationship beats transaction. Contact was never lost. A small follow-up inquiry led to the site’s rescue.
Yes. This case has been completely anonymized—with no mention of the industry, location, or domain. We treat security incidents confidentially.
The core cleanup of this store was completed in one workday. The amount of work required depends on the extent of the infestation.
Once Google re-evaluates the cleaned-up page, visibility may return. We’ll monitor this in the weeks that follow.
We’ll take a look at your WordPress or WooCommerce installation: hidden content, unauthorized accounts, database clutter, and visibility history. You’ll receive a clear report.