SEO results hacked?
-
Hi there,
Since last Saturday I noticed a big traffic drop on at least the following two pages:
http://www.smartphonehoesjes.nl/apple/ and http://www.smartphonehoesjes.nl/apple/iphone-6/.I did some research and I noticed something realy strange. Unknown sites seems to hijacked my organic results by using the exact same page title and META description but leading traffic to another their domain. Look at those pictures: http://imgur.com/v6kglLU and http://imgur.com/Whx4l8K.
Edit: a competitor seems to have a same problem: http://imgur.com/Zzhter4. I just fetched both URL's in GWT as Google. In Bing there is a little sign of this problem too, so this is not a Google only thing.
Can anybody please help me here? This has cost me some real money since Saturday.
Tnx in advance.
Marcel
-
Hi Dirk,
After contacting Google by phone and mail, filing a few more spam reports and refreshing textual content, we got our results back and traffic/revenue has grown since. We are very happy, and no other pages got attacked (yet).
Thanks for your help.
Marcel
-
Marcel,
When you contact the site owners - a good guideline on 'how to clean' can be found here: https://codex.wordpress.org/FAQ_My_site_was_hacked (specifically for Wordpress) - more in general: http://www.google.com/webmasters/hacked/ - it could be that the hackers gained access by a security issue with the slider (http://wptavern.com/critical-security-vulnerability-found-in-wordpress-slider-revolution-plugin-immediate-update-advised) so they should certainly check that Wordpress & it's plugins are up-to-date.
Good luck!
Dirk
-
Hi Dirk,
Let's hope the hacker only copied a few pages and not the entire site. What could a site like soft-solutions possibly do to clean their site? I think it's worth a chance to ask planchemag and wearemash to do the same. My new URL shows up if you search for 'iphone 6 / 6s hoesje', that's something positive. I filed a request for deletion of the old and hacked URL of the iPhone 6 page, hopefully Google throws it out and picks up the new and clean one like it does with the other search query.
I can do nothing but wait now I guess. I will keep you updated here.
Marcel
-
Hi Marcel,
I have the impression that soft-solutions.nl already discovered that they have been hacked & have cleaned their site in the mean time.
It's possible that the hacker only copied 1/2 pages - it's however more likely that they copied the full site but that the other pages haven't been indexed yet. Idem for copyscape - if the hack only occurred recently, these tools (and Google) haven't been able to pickup all pages yet.
When I search for 'iphone 6 hoesje' I get the planchemag.com site. As all these pages are duplicates, it's Google who's deciding which page it's going to show. Google decided that in some cases the hacked version is the preferred one, for other queries people will still get to your site. It probably depends on the anchors the hackers used to the hacked site. The volume of iphone 6 is probably higher than iphone 5 queries, so they will probably have used anchors containing 'iphone 6' to point to the site.
Dirk
-
Hi Dirk,
That second result is our homepage, I see that this one got indexed at the exact same time our own homepage got indexed. However, Google shows our (the good one!) homepage in the search results.
That's quite ironical indeed, the webdesign company.
The other result redirects to planchemag.com, which only gives one result on a site:www.planchemag.com/. What about this one?
Is it possible this hack only limits to those two pages?I used the tool copyscape.com and it seem to be only the following pages that are affected:
What about this one: search for site:soft-solutions.nl and you'll find our iPhone 5/5s pagina. Search for 'iPhone 5 hoesje' and Google shows our correct page as a result. How is this possible?
Marcel
-
Hi Marcel,
If I do a site:www.wearemash.com there seem to be only 2 pages from your site indexed at the moment - possible that the other ones haven't been picked-up by Google yet. Quite ironical that the domain wearemash.com belongs to a web design company.
rgds,
Dirk
-
Hi Dirk,
I just set the redirect, just to be sure. This is a realy bad thing, people can abuse Google to negatively impact a whole company and lots of individuals. That should not be possible, hope Google will fix this soon!
You assume the whole site will go down in Google and not only those two pages? This will be terrible.
Marcel
-
Hi Marcel,
Don't think that it will change a lot. If the hack is done in the same way as the other cases (which seems to be the case), they copied your entire site into the site which has been hacked. They present this version to Google (cloaking - as you can see in the cached version) - but "normal" visitors are redirected to a different e-commerce site. To make sure the hacked site is positioned well, they point hundreds of links from other hacked sites to the cloned version of your site. So whatever you change on your site, will not impact the cloned version, which will keep it's position, until Google takes action.
It's a quite a simple trick, and to be very honest, I am surprised that Google is not capable to detect it.
rgds,
Dirk
-
Hi Dirk,
This should be a Google task to prevent her customers/users from those kind of hackers right?
Do you think that redirecting my iPhone 6 page to a new URL would help? I can imagine the hackers hijacked an URL, when I pick a new one and 301 redirect the old one to the new, will my own result show up again?
I already spoke with Google this morning and they are going to look after it.
Marcel
-
Hi Marcel,
It seems to be a plague recently- there where similar cases on Moz the last two weeks: http://moz.com/community/q/chinese-site-ranking-for-our-brand-name-possible-hack (similar situation as you) - a site being hacked http://moz.com/community/q/getting-different-search-queries-in-google-webmaster. It seems the hackers are exploiting a vulnerability in the slider used on these Wordpress site.
Apart from filing spam reports there is not much more you can do. You could inform the site owners that their site has been hacked & ask them to clean it, but I fear that these hackers are capable to switch sites quite fast.
Good luck,
Dirk
-
Hi Matt-POP,
Thanks for this opening, didn't look at it this way. All our domains got replaced by wearemesh in the cached page. The VWO code looks like ours, so do you really think they were testing? All of the source code is ours, also the canonical, only the domain got replaced by theirs..
We are using VWO but we are doing it by ourself. I'm not sure VWO is the problem.
This problem occured last Saturday. What we did on Friday is make our website mobile friendly for the scheduled 21st of April mobile Google update. Is this coincidence? The two companies who helped us with this change, made some changes to the canonical tags among other things.
A strange thing here is that a competitor has a same problem, wouldn't that seem like a conscious action (hack)?
@Patrick: We don't know them, for sure. If you go to the unkknown website, you see that they don't use our meta data, so that's the strange part.
Update: the domain www.wearemesh.com now redirects to www.ovsee.com, the same website you got redirected to when you click on the hacked result of the competitor I wrote about. The visual URL there is Finan.nl. This Ovsee.com looks like the perpetrator. But I still can't get a grip on it.. the other hacked result leads to www.planchemag.com which redirects to http://planchemag.fr.
What can I do to get my results back? I already filed a spam report in GWT.
Thanks again,
Marcel -
Their Google cache results were somehow corrupted temporarily:
http://webcache.googleusercontent.com/search?q=cache:http%3A%2F%2Fwww.wearemash.com%2F
There's a VWO code in there:
So it looks like they were split testing. The canonical is set to their domain which is why they took over results temporarily on these search terms.
It looks like the split test somehow grabbed your page info & theirs and split tested it giving theirs a canonical on your content. That would do it.
Are you using VWO? Are you using these guys to do your conversion optimisation? You may have the same conversion company who made a mistake or you may have the same VWO designer. I'm not sure how it got there but looking at the code, VWO does look to probably factor into the problem.
-
Hi Marcel
Quick question - I know you said "unknown", but are you sure that this site has nothing to do with your site? Like, did they develop or design your site at all?
Here is a help section from Google on these sorts of issues - it covers everything from cloaking to content scraping, and doorway pages to other spam types.
I would try contacting the webmaster of this site and asking them to remove your titles/meta descriptions. If they do not respond, or are not willing to cooperate, reference the resource above as Google has steps to take to ensure action is taken against sites that do this sort of thing.
Hope this helps! Let me know if you have any questions or need more help, good luck!
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
"Fake" market research reports killing SEO
Our robotics company is in a fast growing, competitive market. There are an assortment of "market research" companies who are distributing press releases about their research reports (which are of less than dubious quality). These announcements end up being distributed through channels with high domain authority. The announcements mention many companies in the space that the purported report covers - including ours. As a result, our company name and product brand is suffering since the volume of press announcements is swamping our ratings. What would you do? Start writing blog postings on topics and post through inexpensive news feeds? Somehow contact the firms posting the contact and let them know they are in violation of our trademarks by mentioning our name? Other ideas?
White Hat / Black Hat SEO | | amelanson1 -
How to make second site in same niche and do white hat SEO
Hello, As much as we would like, there's a possibility that our site will never recover from it's Google penalties. Our team has decided to launch a new site in the same niche. What do we need to do so that Google will not mind us having 2 sites in the same niche? (Menu differences, coding differences, content differences, etc.) We won't have duplicate content, but it's hard to make the sites not similar. Thanks
White Hat / Black Hat SEO | | BobGW0 -
Looking for recent bad SEO / black hat example such as JC Penney example from 2011
I am giving a presentation in a few weeks and looking for a "what not to do" larger brand example that made poor SEO choices to try and game Google with black hat tactics. Any examples you can point me to?
White Hat / Black Hat SEO | | jfeitlinger0 -
Do pingbacks in Wordpress help or harm SEO? Or neither?
Hey everyone, Just wondering, do pingbacks in Wordpress help or harm SEO? Or neither?
White Hat / Black Hat SEO | | jhinchcliffe1 -
Dust.js Client-side JavaScript Templates & SEO
I work for a commerce company and our IT team is pushing to switch our JSP server-side templates over to client-side templates using a JavaScript library called Dust.js Dust.js is a JavaScript client-side templating solution that takes the presentation layer away from the data layer. The problem with front-end solutions like this is they are not SEO friendly because all the content is being served up with JavaScript. Dust.js has the ability to render your client-side content server-side if it detects Google bot or a browser with JavaScript turned off but I’m not sold on this as being “safe”. Read about Linkedin switching over to Dust.js http://engineering.linkedin.com/frontend/leaving-jsps-dust-moving-linkedin-dustjs-client-side-templates http://engineering.linkedin.com/frontend/client-side-templating-throwdown-mustache-handlebars-dustjs-and-more Explanation of this: “Dust.js server side support: if you have a client that can't execute JavaScript, such as a search engine crawler, a page must be rendered server side. Once written, the same dust.js template can be rendered not only in the browser, but also on the server using node.js or Rhino.” Basically what would be happening on the backend of our site, is we would be detecting the user-agent of all traffic and once we found a search bot, serve up our web pages server-side instead client-side to the bots so they can index our site. Server-side and client-side will be identical content and there will be NO black hat cloaking going on. The content will be identical. But, this technique is Cloaking right? From Wikipedia: “Cloaking is a SEO technique in which the content presented to the search engine spider is different from that presented to the user's browser. This is done by delivering content based on the IP addresses or the User-Agent HTTP header of the user requesting the page. When a user is identified as a search engine spider, a server-side script delivers a different version of the web page, one that contains content not present on the visible page, or that is present but not searchable.” Matt Cutts on Cloaking http://support.google.com/webmasters/bin/answer.py?hl=en&answer=66355 Like I said our content will be the same but if you read the very last sentence from Wikipdia it’s the “present but not searchable” that gets me. If our content is the same, are we cloaking? Should we be developing our site like this for ease of development and performance? Do you think client-side templates with server-side solutions are safe from getting us kicked out of search engines? Thank you in advance for ANY help with this!
White Hat / Black Hat SEO | | Bodybuilding.com0 -
How Is Your Approach Towards Adult SEO?
I would like to know how SEOMoz community members approach adult SEO. How do you approach a project when you get one (if you do it that is). If you dont do adult SEO, why do you not do it? Is it because it's much more difficult than normal SEO or do you not want to associate yourself with that industry?
White Hat / Black Hat SEO | | ConversionChamp0 -
Ever seen a black hat SEO hack this sneaky?
A friend pointed out to me that a University site had been hacked and used to gain top Google rankings. But it was cloaked so that most users wouldn't notice the hack. Only Googlebot and visitors from Google SERPs for the spam keywords would see a hacked version. See http://www.rypmarketing.com/blog/122-how-hackers-gained-an-easy-1-google-ranking-using-a-university-website.whtml (my blog) for screenshot and specifics. I've dealt with hacks before, but nothing this evil and sneaky. Ever seen anything like this? This is not our client, but was just curious if others had seen a hack like this before.
White Hat / Black Hat SEO | | AdamThompson0