WordPress Site Hacked? The Complete Recovery Guide (Japanese Keyword Hack, Redirects & Malware)

You searched your own company name and found pages in Japanese selling counterfeit handbags. Or a customer phoned to say your website sent them somewhere they'd rather not describe. Or Google Search Console just emailed you the words "security issue detected."
First: breathe. This is one of the most common attacks on the web, it did not happen because you're careless, and it is fully recoverable. We've cleaned up sites that had thousands of spam pages indexed, and they came back.
Second: move quickly anyway. Every hour the malware stays up, more spam pages get indexed, more visitors get redirected, and the deeper the hole Google puts you in. One documented case saw the injected content indexed in under a day, the hack happened overnight and the damage was in search results by morning. Speed matters more than perfection right now.
How to confirm you've been hacked
Run these three checks; they take five minutes:
- Google your site with
site:yourdomain.com. If you see pages you didn't create (Japanese product titles, pharma keywords, URLs like/ferfsedf/xkcd123.html), that's the Japanese keyword hack (also called Japanese SEO spam) or its cousin, spam link injection. - Visit your site from your phone, on mobile data, in an incognito window. Redirect malware often only fires for new visitors, on mobile, or for traffic arriving from Google, precisely so you never see it from your office chair.
- Check Google Search Console. Look at Security Issues, look for a sudden spike in indexed pages, and, critically, check Settings → Users and permissions for accounts you didn't add. Attackers frequently verify themselves as owners of your Search Console so they can push their spam pages into the index faster.
Also scan with a free external tool like Sucuri SiteCheck for a second opinion. Just know its limits: external scanners can only see your site's public front end. Malware buried in core files is invisible to them, so a clean external scan does not mean a clean site.
The recovery process, in order
Do these in sequence. Skipping ahead is how cleanups fail.
1. Contain. If your host has suspended the account, contact them and get your IP whitelisted so you can work. Change every password: WordPress admins, hosting control panel, SFTP, database. Delete any WordPress admin users you don't recognise, attackers routinely create their own.
2. Back up the infected site. Yes, really. A full copy of the hacked state means that if the cleanup breaks something, you can compare rather than guess.
3. Scan and clean with a proper malware tool. A server-side scanner (MalCare, Wordfence, Sucuri) that can read your actual files and database, not just the public pages. Here's the honest part most guides skip: manual cleanup usually fails. People who try it either miss a backdoor and watch the hack reappear within days, or delete legitimate code and break the site. If the scanner can't auto-clean, this is the point to bring in a professional, not the point to start deleting files that look suspicious.
4. Reinstall core, themes, and plugins from clean sources. Fresh copies of WordPress core and every plugin/theme, straight from the official repositories. Delete anything you're not using, deactivated plugins are still attack surface. Restore a default .htaccess file; injected redirect rules love hiding there.
5. Find how they got in, or you'll be back here next month. The usual doors: an outdated plugin with a known vulnerability, a weak or reused admin password, a nulled (pirated) theme, or another compromised site on the same hosting account. Update everything, enforce strong passwords and two-factor authentication, and if you're on bargain shared hosting, this is your sign to leave.
Cleaning up the Google mess
The malware is gone; the crater remains. Spam pages stay in Google's index after the files are deleted, and this is the phase everyone underestimates, real cases have watched indexed spam pages keep climbing by thousands for a week or more after a successful cleanup, purely from Google's crawl lag.
- Remove unauthorized Search Console users (again, verify this, it's the most-missed step).
- Use the Removals tool in Search Console for the spam URL patterns.
- Return 410 (Gone) for the spam URL patterns, telling Google those pages are permanently dead gets them dropped much faster than 404s.
- Fix your sitemap. The hack often replaces or floods your XML sitemap with spam URLs. Regenerate it clean and resubmit. (If spam URLs persist in the sitemap after reinstalling your SEO plugin, the generator is reading leftover junk in your database, that needs cleaning too.)
- Request a review if Google flagged the site with a deceptive-site warning or "This site may be hacked" label.
Expect search rankings to recover over weeks, not days. Painful, but they do recover.
What this actually cost you, and the cheap insurance you skipped
A hack like this typically costs far more in lost rankings, lost trust, and cleanup hours than years of basic prevention would have: managed updates, a real backup regime, security hardening, and monitoring that alerts someone the moment a strange admin user or file change appears. Nothing dramatic happens, until everything does, and then recovery costs more than prevention ever would. That's the entire case for a maintenance plan in one sentence.
When WordPress is the wrong tool for the job
WordPress isn't inherently insecure, but its security model is "you (or someone you pay) must maintain a stack of third-party plugins forever, and any one of them can open the door." For a content site, that's a manageable chore.
If your site handles customer accounts, payments, sensitive data, or business-critical operations, ask the harder question: should the thing your business depends on be assembled from 30 plugins written by 30 strangers? A custom-built application has a radically smaller attack surface, no plugin ecosystem to patch, no off-the-shelf vulnerabilities that ten thousand bots scan for the day they're published. Attackers target WordPress because it's 43% of the web; custom code makes you a much less economical target. If you've been hacked twice, the third cleanup usually costs more than starting the custom conversation. We do both, so you'll get a straight answer about which you need.
Hit by this right now?
Work the steps above in order. And if the scanner can't clean it, the hack keeps coming back, or you simply don't want to spend your week in file managers, our malware removal service handles the full sweep: cleanup, backdoor hunting, Google recovery, and hardening so there's no repeat performance. Fear of the next hack leads to stress, stress leads to shortcuts, shortcuts lead back to this article. Break the cycle once, properly.
May the Code Be With You.
WordPress Pro builds, fixes, and maintains WordPress sites, and builds custom solutions for businesses that have outgrown them. [Get emergency malware removal →]
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


