Japanese Keyword Hack and SEO Spam: How to Clean Your Site and Google Results
How to fix the Japanese keyword hack, pharma hack and other SEO spam on WordPress: spotting cloaked spam pages, removing rogue Search Console owners, cleaning files and removing spam URLs from Google.

On this page
- SEO spam is often cloaked: Googlebot sees spam pages while visitors see your normal site.
- Remove rogue Search Console owners, spam sitemaps, generator scripts and backdoors.
- Let spam URLs return 404/410, don't block them in robots.txt, and use the Removals tool.
You search for your business on Google and see pages with Japanese text, cheap medicines, replica goods or casino keywords under your domain. Your website looks fine when you visit it. This is an SEO spam hack: attackers use your site's reputation to rank their spam pages.
Common types
- Japanese keyword hack: thousands of auto-generated pages with Japanese text selling counterfeit goods
- Pharma hack: spam pages or hidden links for medicines
- Hidden link injection: invisible links to spam sites added to your pages
- Doorway pages: spam pages that redirect visitors to other sites
How to confirm it
- Search
site:yourdomain.comon Google and look for unfamiliar pages or languages - Check Search Console: Security issues, Pages (indexing) and Sitemaps for sitemaps you didn't submit
- Use Search Console's URL Inspection on a spam URL to see what Googlebot sees
Spam is often cloaked: shown to Googlebot but not to normal visitors, which is why the site looks fine to you.
Step 1: Remove rogue Search Console owners
Attackers often verify themselves as owners of your site in Search Console so they can submit spam sitemaps. Go to Settings → Users and permissions, remove anyone you don't recognise, and delete their verification method (such as an HTML verification file or meta tag) from your site.
Step 2: Find and remove the spam generator
- Look for unfamiliar PHP files and folders in the root and wp-content
- Check .htaccess for rewrite rules sending spam URLs to a script
- Look for injected code in theme files, plugins and wp-config.php
- Check the database for spam posts, pages and hidden links
Then follow the full malware clean-up process and remove backdoors, or the spam will return.
Step 3: Make spam URLs return 404 or 410
Once cleaned, spam URLs should return "not found" (404) or "gone" (410). Google drops them as it recrawls. Don't redirect them to your homepage.
Step 4: Don't block spam URLs in robots.txt
If you block them, Google can't recrawl them to see they're gone, so they may linger in results longer.
Step 5: Speed up removal
- Use Search Console's Removals tool to temporarily hide the worst URLs
- Submit your real sitemap and remove spam sitemaps
- Request a review in Security issues if a manual action or warning appears
Thousands of spam URLs can take weeks to drop out completely. Keep monitoring with site: searches.
Step 6: Protect your rankings
Spam can hurt your real rankings while it's live. After cleaning, check your important pages are indexed and performing; see Search Console reports explained.
Prevent it
Keep plugins updated, remove unused ones, secure logins and monitor Search Console email alerts. See why WordPress sites get hacked and WordPress malware removal.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


