← All guides

Japanese keyword hack: why Google shows Japanese text under your site

Your search results show Japanese titles for pages selling watches or handbags you have never heard of. That is a specific, common hack with a specific fix. Here is what it does, the one step most cleanups miss, and how to get the results out of Google.

16 September 2026, 3 min read. From the cleanup where we found the attacker listed as a verified owner of the site in Search Console.

You search for your company and the results show pages on your domain with Japanese titles, selling branded goods at suspicious prices. Clicking them from Google shows the spam page. Typing the address shows nothing, or your normal site. Customers are asking. This is the Japanese keyword hack, and it is one of the most common infections we clean.

What it actually does

The attacker creates hundreds or thousands of pages on your domain, in a folder with a random name, full of Japanese text and affiliate links to counterfeit goods. They use your site’s existing search reputation to rank those pages. The pages are often served only to Google’s crawler and to visitors coming from Google, so you do not see them. They also add a sitemap of the spam pages so Google finds them quickly.

Then the part most people miss: they add themselves as an owner of your property in Google Search Console, using a verification file they uploaded. That lets them submit sitemaps, request indexing, and watch your traffic. It also means they keep that access after you clean the files, unless you remove them.

The fix, in order

  1. Snapshot the site as it is.
  2. Search Console first. Open Users and permissions. Remove any owner or user you do not recognise. Then find and delete the verification file or tag they used, or they can simply re-verify. Search Console shows which method each owner used.
  3. Find the spam pages. Search site:yourdomain.com and note the folder names. On the server, look for new folders with random names, and for PHP files in the uploads folder. Look at .htaccess and the sitemap files for entries you did not create.
  4. Find the door. Nearly always an outdated plugin or theme with a known hole, or a compromised password. Check every version against current, and check the users list for accounts you did not create.
  5. Clean by replacement. Fresh copies of core, theme and plugins. Delete the spam folders. Search the database for injected content. Remove scheduled tasks you do not recognise.
  6. Rotate every password and the secret keys. Database, admin users, hosting, SFTP.
  7. Update everything and remove what you do not use.
  8. Tell Google. In Search Console, use the removals tool for the spam folder so the results disappear faster, submit your real sitemap, and if there is a security issue listed, request a review after the cleanup is complete.

Getting the results out of Google

The spam pages now return “not found”, which is correct. Google drops them over days to weeks. The removals tool speeds up the visible part. The site’s own rankings usually recover once the spam is gone, though a site that was heavily infected for months can take longer to settle.

Why it comes back

Three reasons, in order: the attacker’s Search Console access was not removed, the entry point was not found, or a scheduled task was left in place. If your cleanup covered the files but not those three, expect a second round.

Our scanner will show you the software versions the attackers were targeting, and whether Google currently flags the site. The site: search and the Search Console owners list are the two checks to do right now if any of this sounds familiar.

See where your own site stands.

The scanner checks the things this guide talks about, in about ten seconds, no signup.

Tell us about the site.

A straight answer and a fixed quote, usually the same day.