The Security issues report is the section of Google Search Console where Google tells you it has found your site hacked, serving malware or unwanted software, or tricking visitors with deceptive pages such as phishing forms. An empty report is the result you want.
How the Security issues report works
Google’s crawlers and its Safe Browsing systems check pages as they find them. When they detect a problem on a property you have verified in Google Search Console, it appears under Security and Manual Actions, then Security issues, and verified owners receive an email. The report groups problems into three families:
- Hacked content: code, pages or links added by an attacker. A common pattern on small business sites is thousands of spam pages selling counterfeit goods or pharmaceuticals, sometimes in Japanese, sitting alongside the real site.
- Malware and unwanted software: files or scripts that install harmful software or change a visitor’s browser.
- Social engineering: deceptive pages that imitate a bank, a delivery firm or a login screen to steal details.
Each issue lists sample affected URLs. Once you have fixed everything, you use the Request review button in the report and explain what you did. Review times vary by issue type, from about a day to several weeks.
This report is separate from the manual actions report, which covers penalties for breaking Google’s spam policies rather than security compromises.
Why it matters
Google may label your result “This site may be hacked” or remove pages, and browsers that use Safe Browsing, including Chrome, Firefox and Safari, can show a full red warning screen before anyone reaches your site. Visits from search and ads collapse almost immediately, and Google Ads can disapprove ads that point to a compromised site.
For a UK business there is a second issue. If the attack exposed enquiry form submissions, customer accounts or order details, it may be a personal data breach. Under UK GDPR you must report a breach to the ICO within 72 hours of becoming aware of it, unless it is unlikely to pose a risk to people’s rights and freedoms.
Common mistakes
- Not having Search Console set up, or sending its alerts to a former employee or an old agency’s inbox.
- Deleting the visible spam pages but leaving the backdoor the attacker used, so they return within days.
- Restoring a backup that contains the same out-of-date plugin, which reopens the same hole.
- Requesting a review before the clean-up is complete, which delays recovery further.
- Assuming that because rankings look normal, the warning does not matter.
How to act on it
Check the report each month and confirm who receives Search Console email. Keep your CMS, theme and plugins updated, since a missed security patch is the most common route in on WordPress sites, and run a regular malware scan.
If an issue appears: change every password (hosting, CMS, FTP, database, email), remove unknown admin users, update everything, scan the files and database for injected code, and check the server for scheduled tasks you did not create. Make sure spam URLs now return a 404 or 410 and are not in your sitemap. Then request a review with a clear account of what you found and fixed, and decide whether the ICO needs to be told.
Recovering a hacked site’s search visibility, and closing the gaps that let it happen, is part of my technical SEO work.
