Before You Start: Site Ownership

You must be able to verify ownership of the affected site. Standard verification methods include uploading a file to the root directory, authoring meta tags, or holding a Google Analytics administrative account for the property.

Step 1: Check for Unauthorized Search Console Access

The first recovery step after regaining ownership is to ensure the attacker has not taken over or altered your Search Console property. Open the Users and permissions page to review the list of users and owners. Remove anyone you do not recognize, and note their email addresses for later reference. If an unauthorized user holds the "owner" role, verification tokens must be cleared, including any stray meta tags on your homepage or HTML files on the server—deleting the user alone is not sufficient. For full details, see Google's verification documentation.

Next, audit the property's Settings page for tampering. Specifically, examine the configured Crawl rate; malicious actors sometimes lower it to keep search engine spiders away. Also review the removals tool and the Change of Address tool for entries you did not create.

Step 2: Determine the Attack Type

Use the Search Console Message panel and the Security Issues report to classify the compromise. This diagnosis is critical because the remediation path differs for a spam attack, a phishing scheme, and malware distribution.

Start by opening the Message panel. Look for critical Google notifications about spammy pages or links, phishing, or malware. Keep any phishing notification in place until the entire cleanup is finished.

Then, consult the Security Issues report:

  • A top-level heading of Malware with subcategories such as "Modified server configuration" or "Error template injection" indicates the site is being used to infect visitors. The attacker is likely leveraging your server to distribute software that steals confidential data or harms user devices. Proceed to the malware remediation guide.
  • A top-level heading of Hacked with categories like "Content injection" suggests the attacker injected spammy pages, text, or links into your site. Follow the spam damage assessment workflow.
  • Sites with a Phishing notification may show no entries in Security Issues. Phishing pages are built to harvest login credentials or financial details by impersonating trusted entities. The cleanup effort matches that for spam, so proceed to the spam damage assessment guide.