Home About

Services

Custom Web Design Custom eCommerce Custom Web Apps Search Engine Optimisation Speed Optimisation SEO Blog Writing Maintenance & Hosting Hacked Website Repair Projects Blog Contact Free Quote
Security 6 min read

The Japanese Keyword Hack: What It Is and How to Fix It

Japanese characters appearing in your Google listings, and pages you never wrote? What the Japanese keyword hack does, why your site looks perfectly normal, and how it is really fixed.

Cleaning up the Japanese keyword hack on a website

You search your own business name and something is wrong. Under your homepage sit page after page of results in Japanese, selling branded trainers and handbags, all on your domain. You click one and it looks nothing like your website. You log in and everything appears completely normal. This is the Japanese keyword hack, and the reason it runs for months on most sites is that the owner is the last person it shows itself to.

What is the Japanese keyword hack?

The Japanese keyword hack is an infection that secretly creates thousands of Japanese-language spam pages on your website, usually selling counterfeit goods. The pages exist only for search engines, so your own site looks untouched. Google indexes them under your domain, and your search listings fill with text you never wrote.

Why does my site look completely normal?

Because the malware serves different content depending on who is asking. This is called cloaking. When Googlebot requests a page it gets the spam; when you visit, you get your real website. Some versions only trigger for visitors arriving from Google, which is why the person who reports it is almost never the owner.

It is the same principle behind the redirect infections covered in why your website redirects to spam, applied to whole pages rather than a bounce. If you want to confirm what search engines actually see rather than what your browser shows you, the checks in how to check if your website is hacked are the right starting point.

How do I know if I have it?

Three checks settle it quickly. Search site:yourdomain.ie in Google and look for pages you did not write. Open Search Console and look for a sudden spike in indexed pages. And check the Users and permissions list for an owner you do not recognise, because this hack very often adds one.

The detail that catches people out: the fake Search Console owner

This is what makes the Japanese keyword hack different from an ordinary infection. Attackers frequently verify themselves as an owner of your property in Google Search Console, usually through a verification file or a DNS record they were able to add once they had access.

That matters for two reasons. It lets them submit sitemaps for their spam pages, so their junk gets indexed faster and more thoroughly. And it means that even after you clean every file on the server, they still hold a legitimate line of communication with Google about your website. Cleaning the site without removing that owner leaves the job half done, and this step gets missed constantly.

Illuminated street signage at night
Plenty of Japanese text is exactly where it belongs. Yours should not be on your own website.

Where does the infection actually live?

Rarely in one place. On the sites we have cleaned, the components are spread deliberately so that deleting any single one changes nothing:

  • Generated spam pages, often thousands, created on the fly rather than saved as files you can spot by browsing.
  • A modified sitemap feeding those URLs straight to Google.
  • A backdoor, typically an innocuous-looking file in a plugin or uploads folder, which restores everything after a clean.
  • Database entries holding the spam templates and keyword lists.
  • An added administrator account, sometimes dormant for weeks before it is used.

Why deleting the spam pages never works

Because the pages are the output, not the infection. Remove them and the backdoor regenerates the lot, often overnight. We have seen owners clear the same spam URLs repeatedly for weeks before accepting that something is putting them back, which is exactly the pattern described in how WordPress malware removal actually works.

A clean that holds means finding every copy of the spam generator, the backdoor that restores it, the account that lets them back in, and the original entry point that allowed all of it. Miss any one and you are back where you started within days.

How do I fix the Japanese keyword hack properly?

Change every password from a device you trust, then remove the unknown Search Console owner immediately. Have the site cleaned at file and database level, close the entry point, and only then ask Google to recrawl. Removing the fake owner first matters, or the attacker simply resubmits the spam.

The clean-up is only part of it. Your search results will keep showing Japanese pages until Google recrawls and drops them, and that takes time and the right requests. Our guide to recovering your SEO after a hack covers how listings come back, and the full first-aid sequence is in what to do when your website is hacked.

If the site is a business asset and you would rather it was handled properly the first time, our hacked website repair service covers the full sequence: every spam page and generator removed, the backdoor found, the fake owner revoked, the entry point closed, and a monitoring period afterwards to confirm it stayed gone.

Frequently asked questions

Why Japanese, when my business is in Ireland?

The language is chosen by whoever runs the spam campaign, not by anything about your website. The pages target Japanese shoppers searching for branded goods, and your domain is simply borrowed reputation. The same infection appears with other languages, but the Japanese variant is by far the most common.

Will this get my site removed from Google?

It can. Google may apply a manual action for pure spam, which removes or heavily demotes your listings. That is recoverable, but only after a verified clean and a reconsideration request, so the sooner the infection is dealt with the less there is to undo.

How did they get in?

Most often an out-of-date plugin or theme with a known vulnerability, occasionally a weak or reused admin password. The specific door matters, because closing it is the difference between a clean that lasts and one that fails within a week.

My host ran a scan and found nothing. Am I in the clear?

Not necessarily. Host scanners look for known malware signatures and regularly miss cloaked spam, because the infected pages never appear to a normal request. If Google is showing pages you did not write, trust the search results over the scan.

Can I just restore a backup?

Usually not. This infection often sits quietly for weeks or months, so recent backups tend to contain it, and a restore does nothing about the entry point or the fake Search Console owner. Clean properly first, and keep backups as the safety net rather than the fix.

Seeing Japanese pages in your search results? We remove the spam, the backdoor and the fake owner, then close the door they came in through. Get emergency help.

Want this handled for you?

We design, build and grow fast custom websites for Irish businesses.