Active incident or hacked WordPress? Network / ransomware Hacked WordPress 423-888-0252 · 828-484-1257

Gambling / casino / loan spam

WordPress showing gambling links? That is a compromise, not a plugin glitch.

Search results for your pages now say casino, sportsbook, payday loan, or “best pills.” The homepage looks fine when you are logged in. That pattern is SEO spam on a hacked WordPress site — the same family as the old pharma hack.

Request cleanup See packages 423-888-0252

What this usually is

Attackers inject links and entire doorway pages aimed at Googlebot, or at visitors from certain countries and phones. You see the real site. Searchers see “online casino” and “cheap Viagra.” The injector often lives in a must-use plugin, a modified theme header, the wp_options table, or a file that wp-config.php loads. Deleting the visible link in the editor does nothing; it is regenerated on the next request.

What you are probably seeing

  • Google titles or descriptions mention casinos, betting, loans, crypto, or pharmaceuticals
  • View-source or a logged-out / incognito window shows links you do not see when logged in as admin
  • New posts or pages with slugs you did not write, often in another language
  • A “security” or “redirect” plugin you never installed
  • The spam vanished for a day after a host cleanup, then the casino titles returned

What not to do

  • Do not keep deleting the spam posts. They will come back until the injector is gone.
  • Do not change the theme and call it done. The dropper is often outside the theme.
  • Do not request a Google recrawl while the spam is still being generated. You will recrawl the casino titles.
  • Do not pay a “we will remove the gambling links from Google” outfit that never asks for SSH.

What we actually do

We find the generator — file, database option, or cron — remove the spam content and the door it used, then harden so a leftover admin account cannot put it back. Cleanup is Phase A (from $2,500). Recrawl in Search Console is a separate step after the public HTML is clean. We will tell you when it is honest to click that button. We do not invent a ranking recovery date.

Published rates live on the WordPress incident-response packages page: Phase A from $2,500, Phase B from $2,000, combined from $4,200. Remote nationwide. Onsite in the Tri-Cities and Western North Carolina if you want someone in the room. If the WordPress site is the front door to a larger business compromise, start at emergency incident response instead.

WordPress incident response on a Linux shell

If this is your WordPress site

Why does the homepage look fine?

Cloaking. The malware serves clean HTML to logged-in admins and a spam version to Googlebot or to phones. That is why “I looked at it and it is fine” and “Google says casino” can both be true.

Is this the same as a pharma hack?

Same family. The payload used to be pharmacy keywords. Now it is often gambling, sportsbooks, payday loans, or crypto. The cleanup is the same job: find the injector, not just the visible links.

Will Google drop the casino titles after cleanup?

Cleanup removes the junk. Getting Google to recrawl and drop the poisoned titles is a separate step once you can open Search Console. Recrawl work is quoted separately. We will tell you when the public site is clean enough to request that.

Need the site cleaned without taking the store down?

Tri-Cities 423-888-0252 · Western NC 828-484-1257