# What Google Does When Your Website Gets Hacked

> Small sites are not targeted, they are scanned. Here is how Google defines hacked content, what it does to your listing, and what recovery actually involves.

[Home](https://seoagencynaples.com/) / [Blog](https://seoagencynaples.com/blog/) / Technical SEO Site Protection
# Your Website Was Not Targeted, It Was Scanned: What Google Does When a Site Is Hacked
Almost every owner says the same thing afterwards: we are too small, why would anyone bother with us. The premise is wrong, and Google’s own definition explains why.

By [Jamie Kloncz](https://seoagencynaples.com/jamie-kloncz/), Founder and CEO, SEO Elite Agency ** 14 min read ** Published August 21, 2026

Google defines hacked content as any content placed on a site without permission, due to vulnerabilities in a site’s security [1](#ref-1). That definition contains the answer to the question every small business asks after a compromise. The route in is a weakness in software, not a decision that your business was worth attacking. Nobody chose you. Something found an unlocked door and walked through it.
The consequences are not confined to your server. Google states that pages affected by a security issue can appear with a warning label in search results, or an interstitial warning page in the browser when a user tries to visit them [2](#ref-2). A prospective customer can be warned away from your business by their own browser before they read a single word you wrote.
This guide covers what Google actually documents: how it defines the problem, the four forms it names, what happens to your listing, and how recovery works including the timeline Google publishes. It also names the thing most security marketing gets wrong about small businesses, which is the belief that being small is itself a form of protection.

## The cause Google names is a vulnerability, not a target list
Google’s definition attributes hacked content to vulnerabilities in a site’s security. That is a statement about software rather than about who you are. Obscurity offers no protection, because the process that finds an unpatched weakness does not evaluate the business behind it first.
Take the definition seriously as engineering rather than as marketing. Google says hacked content is any content placed on a site without permission, due to vulnerabilities in a site’s security [1](#ref-1). A vulnerability is a property of the code you are running, and it is the same property on a Naples plumber’s site as on a large retailer’s if both run the same outdated component.
That is why "we are too small to be worth it" is the wrong model. The question was never whether your business is interesting. It is whether the software you run has a known weakness that has not been closed yet. Small sites are frequently easier, not harder, because they tend to run more third-party components and update them less often.
The useful reframe for an owner is that this is a maintenance problem wearing a scary costume. It behaves less like a burglary and more like an unserviced roof in a Southwest Florida summer. Nothing is targeting your roof either. The weather simply finds whatever was already weak, and the only variable you control is how long you leave it that way.

## The four forms Google names, and why some are hard to notice
Google names code injection, page injection, content injection and redirects. Two of the four are designed to be invisible to the owner: hidden links added to pages you already have, and redirects that fire for some users but not for you.
Google sets out four types [1](#ref-1). Code injection is malicious code placed into existing pages, often as JavaScript or inside iframes. Page injection is the addition of new spammy or malicious pages to your site. Content injection is subtler manipulation of pages you already have, including hidden links or hidden text added with CSS or HTML. Redirects send some of your users to harmful or spammy pages.
The word doing the most work there is "some". A redirect that fires for every visitor would be caught within an hour, because you would catch it yourself. A redirect that fires for a fraction of mobile visitors arriving from search, and never for someone typing the address directly, can run for months while the owner sees a perfectly normal website every time they check.
Content injection has the same property. Hidden text and hidden links do not disturb your layout, which means the site looks correct to you while carrying content you did not write. This is why "the site looks fine" is not evidence of anything, and why the first genuine signal is often the Search Console report rather than your own eyes.
If you want to know what your site currently looks like to a machine rather than to you, that is part of what our [free SEO audit](https://seoagencynaples.com/free-seo-audit/) checks, and our [technical SEO services](https://seoagencynaples.com/technical-seo-services/) cover the remediation side. We will also tell you when the honest answer is that nothing is wrong, which is the answer more often than security marketing suggests.

Source: Google Search Central and Search Console Help Download SVG

## What it does to your listing, and how you find out
Google reports findings in the Search Console security issues report, covering hacked content, malware and unwanted software, and social engineering. Affected pages can carry a warning label in results or trigger an interstitial warning in the browser, which is a conversion problem before it is a technical one.
The report is where this becomes visible to you. Google states that if its evaluation determines a site was hacked, or that it exhibits behavior that could harm a visitor or their computer, the security issues report shows the findings, grouped into hacked content, malware and unwanted software, and social engineering [2](#ref-2). When nothing is found, the report shows a green check mark instead.
The customer-facing consequence is the part worth budgeting for. Affected pages can appear with a warning label in search results, or produce an interstitial warning page in the browser when someone tries to visit [2](#ref-2). For a local service business that is not an abstract risk. It is a person deciding not to call you, and never telling you why.
Which leads to a practical recommendation that costs nothing. Have Search Console set up and have the notification email go somewhere a human reads. A great many small businesses discover a compromise from a customer or from a browser warning, when the report was sitting there unread. We wrote separately about the other things that report tells you in [why a site is not showing up on Google at all](https://seoagencynaples.com/blog/website-not-showing-up-on-google/).

## Recovery, and the timeline Google publishes
Fix every affected area, verify the fix, then request a review in the security issues report describing what you corrected. Google says most reviews take several days or weeks, and asks you not to resubmit before a decision. That waiting period is the real cost.
The sequence Google describes is straightforward: fix all issues across the site, test that the fixes hold, then select Request Review in the security issues report with a description of the corrections you made [2](#ref-2). The order matters for the same reason it does with a suspended Business Profile. A review requested against a site that is still compromised is a review that will fail.
On timing, Google states that most reconsideration reviews can take several days or weeks, and that in some cases it may take longer than usual, and it asks you not to resubmit before receiving a decision [2](#ref-2). Sit with that for a moment as a business owner rather than as a technician. That is potentially several weeks of trading while your listing may carry a warning.
That published timeline is the strongest argument for spending on prevention rather than on cleanup, and it is an argument from Google’s own documentation rather than from fear. The cleanup bill is finite and knowable. The weeks of warned-off customers while you wait for a review are neither.

- **Set up Search Console and read the alerts.** The security issues report is where Google tells you. Route the notification to somebody who actually opens it.
- **Do not assume the site is fine because it looks fine.** Two of the four types Google names are built to be invisible to the owner.
- **Fix everything before requesting anything.** Google asks you to fix and test across the whole site first. A review against a live compromise fails.
- **Request the review with a description of what you corrected.** Say specifically what was wrong and what you changed.
- **Then wait without resubmitting.** Google says several days or weeks, and asks you not to resubmit before a decision.
- **Close the window that let it happen.** The cause Google names is a vulnerability, so recovery without patching just resets the clock.

## What actually reduces the risk, stated honestly
Nothing makes a website immune, and anyone promising that is selling something. What genuinely helps is shortening the window between a fix being published and applied, keeping fewer components installed, and detecting problems early rather than discovering them from a customer.
Start with the lever that matches the cause. Since Google attributes hacked content to vulnerabilities in a site’s security [1](#ref-1), the measurable variable is how long a known vulnerability remains open on your site. A fix published on Monday and applied six months later leaves a window that had nothing to do with how interesting your business is. Applying updates promptly is unglamorous and it is the main event.
The second lever is surface area. Every additional plugin, theme or integration is more code you did not write and cannot audit, each with its own update cycle and its own maintainer who may or may not still be paying attention. Removing components you no longer use is free and reduces the number of doors that exist at all.
The third is detection. Given that two of the four types Google names are designed to be invisible to the owner [1](#ref-1), the question is not only whether you can prevent a problem but how quickly you would know. Monitoring that tells you something changed is worth more than a promise that nothing ever will.
And the honest boundary: we are not going to tell you that any product, ours included, makes a site impossible to compromise. It does not exist. What is achievable is a shorter exposure window, fewer components to defend, and faster detection. Anyone offering more than that is describing a guarantee nobody in this field can make. It is worth applying [the same vetting questions](https://seoagencynaples.com/blog/how-to-choose-an-seo-company/) to a security vendor that you would apply to an agency.

- Apply updates quickly. The exposure window is the variable you control.
- Remove plugins, themes and integrations you no longer use.
- Keep Search Console connected and route its alerts to a human.
- Assume "it looks fine to me" proves nothing about hidden content.
- Treat any promise of total protection as a reason to ask harder questions.

Test yourself
## Do you know what a compromise actually costs you?
Five questions from Google’s own hacked-content documentation and the Search Console security issues report, both linked in this guide.

- 1 How does Google define hacked content? Any content Google dislikes Content placed on a site without permission, due to vulnerabilities in the site’s security Content copied from another site Spam written by the owner **Answer:** Content placed on a site without permission, due to vulnerabilities in the site’s security Google defines hacked content as any content placed on a site without permission, due to vulnerabilities in a site’s security. Read the second half of that carefully, because it names the cause. The route in is a weakness in the software, not a judgement that your business was worth attacking. That distinction changes what you should actually do about it.
- 2 What can visitors see when a site has a security issue? Nothing, it is silent A warning label in search results or an interstitial warning page in the browser A slower page load A notice only the owner sees **Answer:** A warning label in search results or an interstitial warning page in the browser Google states that affected pages can appear with a warning label in search results, or an interstitial warning page in the browser when a user tries to visit. That is the part owners underestimate. The damage is not only technical; a prospective customer can be told by their own browser that your site may harm their computer, before they ever see a word you wrote.
- 3 Which of these is NOT one of the four hacked-content types Google names? Code injection Page injection Password theft Redirects **Answer:** Password theft Google names four types: code injection, where malicious code is injected into existing pages, often as JavaScript or into iframes; page injection, where new spammy or malicious pages are added; content injection, where existing pages are subtly manipulated with hidden links or text; and redirects, where some users are sent to harmful or spammy pages. Password theft is a real risk but it is not one of the four categories Google sets out here.
- 4 How long does Google say a security review takes after you request one? Under 24 hours Several days or weeks Exactly 72 hours Google publishes no guidance **Answer:** Several days or weeks Google says most reconsideration reviews can take several days or weeks, and that in some cases it may take longer than usual. It also asks you not to resubmit a request before you get a decision. That timeline is the reason prevention is worth more than remediation here: the cost is not just the cleanup, it is the trading days you spend carrying a warning label while you wait.
- 5 What is the strongest practical defence for a small business site? Being too small to be interesting Keeping software patched so known vulnerabilities close quickly Removing your site from Google Changing your password monthly **Answer:** Keeping software patched so known vulnerabilities close quickly Since the cause Google names is a vulnerability, the lever is how long a known vulnerability stays open on your site. Obscurity is not a defence, because the process that finds these weaknesses does not evaluate who you are before it tries the door. Reducing the window between a fix being published and a fix being applied is the single most useful thing a small site can do.
Honest self-check. There is no sign-up, and nothing is stored.

Questions answered
## Straight answers to the common questions
The questions readers ask about this topic, answered directly. **No forms, no sales pitch.**

JAMIE KLONCZ · SEO AGENCY NAPLES ************** ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

← PREV NEXT → [FREE AUDIT →](https://seoagencynaples.com/free-seo-audit/)

- **Why would anyone hack a small local business website?** The premise is usually wrong, and Google’s own definition explains why. Google describes hacked content as content placed on a site without permission due to vulnerabilities in the site’s security. The cause it names is a weakness in software, not a judgement that your business was worth attacking. A vulnerability in a component is the same vulnerability whether the site belongs to a Naples plumber or a national retailer. Small sites are often easier rather than harder, because they tend to run more third-party components and update them less frequently.
- **What does Google do to a website it considers hacked?** Google reports its findings in the Search Console security issues report, which covers hacked content, malware and unwanted software, and social engineering. The consequence that reaches your customers is more serious than the report itself: Google states that affected pages can appear with a warning label in search results, or produce an interstitial warning page in the browser when someone tries to visit. For a local business that means prospective customers can be warned away before they ever see your content, and most of them will never tell you it happened.
- **My site looks completely normal. Does that mean it is fine?** No, and this is the most common false reassurance in the whole topic. Two of the four hacked-content types Google names are specifically designed not to disturb what you see. Content injection adds hidden links or hidden text using CSS or HTML, so your layout looks untouched. Redirects may fire for only some users, which frequently means mobile visitors arriving from search rather than someone typing your address directly. The owner sees a normal site every time they check while the problem runs for months. Check the report, not the homepage.
- **How long does it take to recover in Google after a hack?** Google says most reconsideration reviews can take several days or weeks, and that in some cases it may take longer than usual, and it asks that you do not resubmit a request before receiving a decision. The process is to fix every issue across the site, test that the fixes hold, then request a review in the security issues report describing what you corrected. Requesting a review while the site is still compromised wastes the attempt. That published waiting period, during which your listing may carry a warning, is usually a larger cost than the technical cleanup itself.
- **Will keeping software updated actually prevent this?** It closes the specific route Google names, which is the most useful thing available to you, but nothing makes a site immune and you should be skeptical of anyone who says otherwise. Since compromise follows from vulnerabilities, the variable you genuinely control is how long a known vulnerability stays open on your site. A fix published months ago and never applied is an open door regardless of how small or uninteresting your business is. Reducing installed components you do not use shrinks the number of doors that exist in the first place.
- **How would I even know if my site had been compromised?** Ideally through the Search Console security issues report, which is why having it connected and routing its notifications to somebody who reads email is genuinely worth the ten minutes. Google shows a count of security issues when problems exist and a green check mark when none are found. In practice a great many small businesses learn about it from a customer, or from a browser warning somebody screenshots and sends them, while the report sat unread. Detection speed matters here more than most things, because the damage accrues quietly the whole time.
- **Can any provider guarantee my website will not be hacked?** No, and treat the offer itself as information about the provider. Nobody can make that guarantee, ours included, because it would require certainty about vulnerabilities that have not been discovered yet. What is genuinely achievable is a shorter window between a fix being published and applied, fewer installed components to defend, monitoring that tells you quickly when something changes, and a clear plan for the recovery process if it happens anyway. If a vendor promises immunity, ask them to explain the mechanism, then compare the answer against what Google documents about how sites get compromised.

## References

- Google Search Central. What is hacking or hacked content?. accessed August 2026. [https://developers.google.com/search/docs/advanced/security/what-is-hacked](https://developers.google.com/search/docs/advanced/security/what-is-hacked)
- Google Search Console Help. Security issues report. accessed August 2026. [https://support.google.com/webmasters/answer/9044101](https://support.google.com/webmasters/answer/9044101)

Written by
## [Jamie Kloncz](https://seoagencynaples.com/jamie-kloncz/)
Founder and CEO, SEO Elite Agency
Jamie Kloncz is the founder and CEO of SEO Elite Agency, the firm behind SEO Agency Naples. An engineer who scaled his own plumbing business to 3 million dollars in revenue and led growth for over 200 teams, he built this agency on one principle: every SEO action must connect directly to revenue, not vanity metrics.
[More about Jamie →](https://seoagencynaples.com/jamie-kloncz/)

Free · No pressure
## See where your business actually stands
Start with a free audit of your rankings, Google Business Profile, technical health, and AI-search visibility, with a prioritized plan and an honest quote for your situation.
[Get your free audit](https://seoagencynaples.com/free-seo-audit/)

Keep reading
## Related guides
[Technical SEO Bot Traffic Is Poisoning Your Search Console Data, and Google Does Not Say It Filters It Out Read guide →](https://seoagencynaples.com/blog/bot-traffic-search-console-data/)[Technical SEO Why Your Website Is Not Showing Up on Google (and How to Get Indexed) Read guide →](https://seoagencynaples.com/blog/website-not-showing-up-on-google/)[Local SEO Your Google Business Profile Got Suspended: A Naples Reinstatement Guide Read guide →](https://seoagencynaples.com/blog/reinstate-suspended-google-business-profile-naples/)
