One of the cruellest things about a hacked website is how invisible it can be. To you, logged in from your own computer, the site looks completely normal. Meanwhile it may be serving malware to visitors — and Google may have already flagged it, buried it, or removed it from search entirely. Here's how that happens and how to stop it.

How a hack becomes a disappearance

When a site is compromised, attackers often inject hidden pages, spam links or malicious scripts. Google's crawlers discover this. To protect its users, Google demotes or de-indexes the site and may show a red "this site may harm your computer" warning. Your listings vanish, and the warning scares off anyone who does find you.

The owner is usually the last to know

Malware frequently hides itself from logged-in administrators and from repeat visitors, showing only to new visitors from search. That's why "it looks fine to me" is not evidence your site is clean.

The warning signs

  • A sudden, unexplained drop in search traffic or rankings
  • A "Not secure" or malware warning shown to visitors
  • Search results showing pages or text you didn't create
  • Customers mentioning odd redirects or pop-ups
  • A message in Google Search Console about security issues

Why Google drops you so fast

Google's priority is protecting searchers. A site serving malware is an active threat, so the response is swift and severe — often before you've noticed anything. Recovering trust takes far longer than losing it, which is why early detection matters so much.

It can take one crawl to lose your rankings to a hack, and weeks of clean-up and review requests to earn them back.

Catching it early

The two free foundations: verify your site in Google Search Console (it emails you about security issues) and run periodic checks through a free site-safety scanner. But both are reactive and easy to forget. Continuous monitoring is what turns "we found out in six weeks" into "we found out in six hours."

How to recover if it happens

  1. Take the site into maintenance mode to protect visitors.
  2. Restore from a known-clean backup, or have the malware professionally removed.
  3. Change every password — CMS, hosting, FTP, database.
  4. Update all software to close the hole that let them in.
  5. Request a review in Google Search Console to clear the warning and rebuild trust.
Prevention is dramatically cheaper

Every step above is stressful and slow. Continuous monitoring plus the basics — updates, strong logins, backups — prevents the vast majority of these incidents in the first place.

Common questions

How quickly can a hacked site be de-indexed?

It can happen within a single crawl cycle — sometimes hours to days after the compromise is detected by Google.

How long does recovery take?

Cleaning the site can be quick, but restoring rankings and clearing warnings after a Search Console review often takes days to weeks.

Will I definitely know if I've been hacked?

Not necessarily — modern malware hides from owners. Verifying Google Search Console and using monitoring are the reliable ways to know.

Want this handled for you? Run a free audit and ranker.bot will find the issues, prioritise them, and fix the ones you approve — in plain English, no agency retainer.