Analytics and Tracking

Security Issues Report

The Search Console report where Google lists hacking, malware or phishing it has found on your site.

Quick facts: Security Issues Report

Category
Analytics and Tracking
Level
Intermediate
Affects
Search visibility, browser warnings, ad approval, customer trust, data protection duties
Where to see it
Google Search Console, Safe Browsing site status, malware scanners, server logs
In this article4
  1. How the Security issues report works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

The Security issues report is the section of Google Search Console where Google tells you it has found your site hacked, serving malware or unwanted software, or tricking visitors with deceptive pages such as phishing forms. An empty report is the result you want.

How the Security issues report works

Google’s crawlers and its Safe Browsing systems check pages as they find them. When they detect a problem on a property you have verified in Google Search Console, it appears under Security and Manual Actions, then Security issues, and verified owners receive an email. The report groups problems into three families:

  • Hacked content: code, pages or links added by an attacker. A common pattern on small business sites is thousands of spam pages selling counterfeit goods or pharmaceuticals, sometimes in Japanese, sitting alongside the real site.
  • Malware and unwanted software: files or scripts that install harmful software or change a visitor’s browser.
  • Social engineering: deceptive pages that imitate a bank, a delivery firm or a login screen to steal details.

Each issue lists sample affected URLs. Once you have fixed everything, you use the Request review button in the report and explain what you did. Review times vary by issue type, from about a day to several weeks.

This report is separate from the manual actions report, which covers penalties for breaking Google’s spam policies rather than security compromises.

Why it matters

Google may label your result “This site may be hacked” or remove pages, and browsers that use Safe Browsing, including Chrome, Firefox and Safari, can show a full red warning screen before anyone reaches your site. Visits from search and ads collapse almost immediately, and Google Ads can disapprove ads that point to a compromised site.

For a UK business there is a second issue. If the attack exposed enquiry form submissions, customer accounts or order details, it may be a personal data breach. Under UK GDPR you must report a breach to the ICO within 72 hours of becoming aware of it, unless it is unlikely to pose a risk to people’s rights and freedoms.

Common mistakes

  • Not having Search Console set up, or sending its alerts to a former employee or an old agency’s inbox.
  • Deleting the visible spam pages but leaving the backdoor the attacker used, so they return within days.
  • Restoring a backup that contains the same out-of-date plugin, which reopens the same hole.
  • Requesting a review before the clean-up is complete, which delays recovery further.
  • Assuming that because rankings look normal, the warning does not matter.

How to act on it

Check the report each month and confirm who receives Search Console email. Keep your CMS, theme and plugins updated, since a missed security patch is the most common route in on WordPress sites, and run a regular malware scan.

If an issue appears: change every password (hosting, CMS, FTP, database, email), remove unknown admin users, update everything, scan the files and database for injected code, and check the server for scheduled tasks you did not create. Make sure spam URLs now return a 404 or 410 and are not in your sitemap. Then request a review with a clear account of what you found and fixed, and decide whether the ICO needs to be told.

Recovering a hacked site’s search visibility, and closing the gaps that let it happen, is part of my technical SEO work.

Do and do not

Do

  • Check the report monthly and confirm who receives alerts
  • Find and close the route the attacker used
  • Request a review only when the clean-up is complete

Do not

  • Delete spam pages and stop there
  • Restore a backup with the same vulnerable plugin
  • Ignore a possible personal data breach

Questions people ask about this

How do I know if Google thinks my site is hacked?

Open Google Search Console, go to Security and Manual Actions, then Security issues. If Google has detected a problem it is listed there with sample URLs, and verified owners are emailed. You might also see "This site may be hacked" under your result in Google, or a red warning page in Chrome.

How long does it take Google to remove a security warning?

After you request a review, Google re-checks the site. Review times vary by issue type, from about a day for some problems to several weeks for hacked spam. The warning is only removed if the review finds the site clean, so finish the whole clean-up before you ask.

Does a hacked website have to be reported to the ICO?

Only if the attack involved personal data, such as enquiry details, customer accounts or orders. UK GDPR then requires you to report it within 72 hours of becoming aware, unless the breach is unlikely to pose a risk to people's rights and freedoms. If you are unsure, record your reasoning and check the ICO's guidance on personal data breaches.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.