Home/ Blog/Technical SEO
Technical SEO

My Site Got Hacked: How to Recover SEO Rankings After a Google Blacklist

Featured image
Advertisement
Advertisement

Part of the Website Security Checklist for SEO series. If you're here mid-crisis, skip straight to the recovery process.

Signs Your Site Has Been Hacked

Some infections announce themselves. Most don't — they sit quietly siphoning crawl budget and link equity into spam pages while you're none the wiser. Watch for:

  • A "Security Issues" notice in Google Search Console
  • Sudden, unexplained traffic drops with no corresponding algorithm update
  • Unfamiliar pages appearing in Search Console's indexed-pages report (often pharmaceutical, gambling, or counterfeit-goods content)
  • Search results showing your domain with title/description text you never wrote
  • A red "Dangerous site" interstitial when you visit your own site in Chrome
  • Antivirus or hosting provider warnings about outbound traffic from your server
1–7
days is the typical window before Google's crawlers detect malware after infection — by the time you notice, Google often already knows.

The Recovery Process

1

Confirm the Infection

Check Search Console's Security Issues tab and run your domain through the Google Safe Browsing Transparency Report. Cross-check with an external scanner like Sucuri SiteCheck — don't rely on a single source.

2

Isolate the Site

Take the site offline or put it in maintenance mode if the infection is actively serving malware to visitors. This limits damage while you work and protects your users.

3

Clean the Malware

Restore from a known-clean backup if you have one — it's faster and more reliable than manual removal. If you don't, use a malware removal tool (Wordfence, Sucuri) or a specialist, and check every admin account for unauthorized additions.

4

Patch the Vulnerability

Cleaning without patching just invites reinfection. Update the CMS core, every theme, and every plugin. Change all passwords and API keys. If you can identify the specific entry point, close it explicitly.

5

Request a Google Review

In Search Console's Security Issues tab, submit a review request once you're confident the site is fully clean. Be specific in your notes about what was found and fixed — vague submissions take longer to process.

6

Monitor Recovery

Once the warning lifts, watch Search Console's coverage and performance reports weekly. Re-indexing and ranking recovery happen gradually, not instantly.

Don't request a review before you're sure it's clean. A failed review delays the next attempt and signals to Google that the issue wasn't properly resolved. Verify thoroughly first.

How Long Recovery Takes

StageTypical Timeframe
Google detects the infection1–7 days after compromise
Cleanup & vulnerability patchHours to a few days, depending on severity
Google review responseSeveral days to a few weeks
Full ranking recovery60–180 days post-review

The variable that matters most isn't the hack itself — it's how quickly and thoroughly you respond. Sites that clean up fast and patch properly recover faster than sites that linger in a half-fixed state.

Preventing the Next One

Recovery is the expensive way to learn this lesson. The cheap way is the routine covered in the Website Security Checklist for SEO — keeping software updated, backing up regularly, and checking Search Console weekly. If your stack is WordPress specifically, the hardening steps in WordPress Security Basics close most of the doors attackers actually use.

Need Help with SEO, AEO or GEO?

Let's build a visibility strategy that works across Google, AI answers and generative search.

Start a Free Consultation
Advertisement