Japanese Keyword Hack: How to Find, Remove and Recover From It

Thousands of Japanese spam pages under your domain in Google is a classic SEO spam hack. Here is how it works, how to find the infection, how to clean it properly and how to recover in search.
Japanese Keyword Hack: How to Find, Remove and Recover From It, MIVAQ guide cover

You search for your business in Google and find pages under your domain with Japanese titles advertising branded goods, discount electronics or other products you have never sold. Clicking them might show a shop, redirect you elsewhere or show your normal homepage. This is the Japanese keyword hack, one of the most common forms of SEO spam. Attackers use your domain’s reputation to rank their spam pages, and in the process they can damage your own rankings and trust. The good news is that it can be fully cleaned and recovered from with the right process.

This article is part of our complete guide: WordPress Security and Malware Removal: The Complete Guide.

How the hack works

Attackers gain access, usually through a vulnerable plugin or theme, a weak password or a compromised hosting account. They then plant code that generates pages on the fly, often thousands of them, each targeting a product keyword in Japanese. Common techniques include:

  • Cloaking: showing spam content to Googlebot while showing your normal site or a redirect to human visitors, so you do not notice.
  • Fake sitemaps: submitting their own sitemaps, sometimes even verifying their own Search Console account for your domain.
  • Rewrite rules: modifying .htaccess so random URLs are handled by a malicious script.
  • Database injections: storing content or code in the options table, posts or custom tables.
  • Backdoors: hidden files that let them return after a basic clean-up.

How to confirm you are affected

  1. Search site:yourdomain.com and look for Japanese characters in titles. Also try site:yourdomain.com 激安 or similar common spam terms.
  2. In Google Search Console, check Security & Manual Actions for hacked content notices.
  3. Check the Page indexing report for a large increase in indexed or crawled pages.
  4. Check Settings › Users and permissions in Search Console for owners you do not recognise. Attackers sometimes verify themselves as owners to submit spam sitemaps.
  5. Use URL Inspection’s live test on one of the spam URLs and view the rendered HTML. If Google sees spam content while your browser does not, cloaking is confirmed.

Step 1: Secure access first

  • Remove unknown owners and users from Search Console, and remove their verification tokens (HTML files or meta tags) from your site, or they can re-verify.
  • Change all passwords: WordPress admins, hosting, SFTP, database, email.
  • Remove unknown WordPress users.
  • Take a backup of the infected site for analysis.

Step 2: Find and remove the malicious code

Check .htaccess and server config

Look for unfamiliar rewrite rules sending requests to unknown PHP files. Restore a clean WordPress .htaccess and re-save permalinks.

Replace WordPress core

Download a fresh copy of the same WordPress version and replace wp-admin and wp-includes entirely. Compare root files like index.php and wp-config.php against clean versions; look for injected code at the top or bottom.

Reinstall plugins and themes

Delete and reinstall every plugin and theme from official sources. Remove anything nulled, abandoned or unused. Check wp-content/mu-plugins, which attackers like because those plugins load automatically and do not appear in the normal list.

Clean the uploads folder

There should be no PHP files in wp-content/uploads. Remove any you find, and block PHP execution there.

Search the database

Look for spam posts or pages, suspicious options (especially autoloaded ones with long encoded values), unknown admin users and malicious scheduled tasks. Search for Japanese text and common malware functions.

Look for backdoors

Search all files for patterns such as eval(, base64_decode(, gzinflate(, str_rot13( and assert(, and for recently modified files. Not every match is malicious, but each should be reviewed.

Step 3: Close the entry point

Identify how the attacker got in: an outdated plugin with a known vulnerability, a reused password, an unprotected admin account, or a compromised hosting neighbour. Update everything, remove the vulnerable component, enable two-factor authentication and apply the hardening in our WordPress security checklist. Without this step, reinfection is likely.

Step 4: Make spam URLs return 404 or 410

Once the code is gone, the spam URLs should return a 404 (not found) or 410 (gone) status. Test several with a header checker. If they still return 200 with your homepage content, something is still generating them, or a catch-all rule is in place. Do not redirect spam URLs to your homepage; that keeps them alive in Google’s eyes.

Step 5: Clean up in Google

  • Submit your genuine sitemap and remove any spam sitemaps from Search Console.
  • Request a review in the Security Issues report, explaining what you cleaned and how you fixed the vulnerability.
  • Use the Removals tool for the most visible spam URLs if needed; it hides them temporarily while Google recrawls.
  • Let Google recrawl the rest. Spam URLs returning 404 or 410 drop out over time.

The full process is in our guide to removing hacked spam URLs from Google.

How long does recovery take?

The security review is usually processed within days. Spam URLs can take weeks to a few months to fully disappear, depending on how many there were. Rankings for your real pages typically recover as Google reprocesses the site, provided it stays clean.

Preventing a repeat infection

  • Automatic updates for minor WordPress releases and trusted plugins, plus a weekly check for the rest.
  • Fewer plugins: every plugin is potential attack surface. Remove what you do not use.
  • Two-factor authentication for every administrator.
  • Least privilege: give editors and authors only the roles they need.
  • File integrity monitoring that alerts you when core or plugin files change unexpectedly.
  • Search Console alerts: make sure notifications go to an inbox someone reads.
  • Off-site backups kept for at least 30 days, so you can restore from before an infection if needed.

Why quick fixes fail

We often meet site owners who removed the spam posts they could see, or ran a scanner and deleted flagged files, only for the spam pages to return a week later. The Japanese keyword hack nearly always includes a backdoor, and often hides code in the database or in must-use plugins. A thorough clean-up and closing the vulnerability are both essential.

We can handle it for you

Cleaning this hack properly takes experience. Our WordPress malware removal service covers clean-up, root cause, hardening and Google recovery. See also signs your WordPress site is hacked and our hacked WooCommerce recovery guide.

Related guides and services

Get expert help

If Japanese spam pages are appearing for your domain, we can remove the infection, close the entry point and help clear the spam from Google. Start with our WordPress malware removal service, browse real client results in our case studies, or contact us for a free, no-pressure review of your website.

Frequently asked questions

Why are Japanese pages showing for my website?

Your site has most likely been hacked with SEO spam that creates pages targeting Japanese keywords.

Does the Japanese keyword hack only affect WordPress?

No. It can affect any CMS or server, but WordPress sites with outdated plugins are frequent targets.

Should I use 404 or 410 for spam URLs?

Both work. 410 signals the pages are permanently gone and may be dropped slightly faster.

Will my rankings recover?

Usually yes, once the site is clean, secured and Google has recrawled it.

Keep reading

How to Start a Shopify Store – MIVAQ complete guide cover
ShopifyWeb
Step-by-step guide to starting a Shopify store in 2026: costs, plans, themes, products, payments, shipping, SEO and a full launch checklist.
Wix & Squarespace SEO – MIVAQ complete guide cover
SEOWeb
The complete 2026 guide to Wix SEO and Squarespace SEO: setup, titles, images, speed, local SEO, schema, redirects and fixing sites not
How to Build a WordPress Website – MIVAQ complete guide cover
WebWordPress
Step-by-step guide to building a WordPress website for your business in 2026: costs, hosting, themes, plugins, SEO, speed, security and a launch

Need help putting this into practice?

We turn ideas like these into working websites, stores and growth plans. Tell us what you are working on.