What is the Japanese Keyword Hack?
The Japanese Keyword Hack (also known as the Japanese SEO Spam Hack) is a malicious SEO campaign where hackers break into your WordPress site and create thousands of auto-generated pages filled with Japanese text and affiliate links to fake designer brand stores.
This hack destroys your website's SEO. If you Google your domain (e.g., site:yourwebsite.com), you will see hundreds of strange Japanese characters instead of your actual content.
Need immediate help?
If your site is currently hacked or showing warnings, our incident response team can help right now.
How Did They Get In?
In almost all cases, the hackers gained access through an outdated plugin, a weak admin password, or a vulnerable theme. Once inside, they modify your .htaccess file to cloak their spam pages (so you don't see them, but Google does) and add themselves as hidden owners in your Google Search Console.
Step-by-Step Cleanup Guide
1. Remove the Hackers from Search Console
Go to your Google Search Console. Navigate to Settings > Users and permissions. If you see unrecognized emails (often random Gmail addresses), remove them immediately. Also, check the "Ownership verification" settings and delete any HTML tags or files they uploaded to verify themselves.
Upgrade to Nexura Pro
Get enterprise-grade protection. Block zero-day exploits, advanced malware, and brute-force attacks instantly.
LIMITED TIME LAUNCH OFFER
2. Clean Your .htaccess File
Access your site via FTP. Open the .htaccess file. You will likely see massive blocks of complicated redirect rules designed to serve Japanese spam to Googlebot. Delete everything and replace it with the default WordPress .htaccess rules.
3. Scan and Remove Backdoors with Nexura
Cleaning the spam pages isn't enough; you must remove the backdoor the hackers used to get in, or the hack will return tomorrow.
- Install Nexura Security.
- Run a Deep Malware Scan. Nexura will identify the hidden PHP backdoors (usually disguised as legitimate core files).
- Use the Auto-Clean feature to quarantine these files.
4. Fetch as Google
Once your site is clean, go back to Google Search Console. Submit your sitemap again and use the URL Inspection tool on your homepage to request indexing. It may take a few weeks for the Japanese spam to completely fall out of Google's index, as Google needs to crawl the dead links and see they return 404 errors.
Prevent future infections by keeping Nexura's WAF active and ensuring all plugins are automatically updated.
