Hacked Site Had 260k Pages Indexed in Just 3 days. How?

zfa116

Newbie
Joined
Dec 15, 2022
Messages
34
Reaction score
9
A few weeks ago, my client's website was hacked.

Hackers were able to index 260k pages practically overnight.

HOW?!

There must be a way someone knows how to do something like this.

And no, 'build backlinks' or 'internal links' is not the answer...

Anybody have any ideas?
 

Attachments

  • Screenshot 2025-12-31 at 9.27.32 AM.png
    Screenshot 2025-12-31 at 9.27.32 AM.png
    122.3 KB · Views: 80
Google has a ton of loopholes. They don't know how to fix it, so they just patch it. Hackers know many things that get fixed if they become public knowledge, so they won't share it.
 
Google has a ton of loopholes. They don't know how to fix it, so they just patch it. Hackers know many things that get fixed if they become public knowledge, so they won't share it.
This is fair, but doesn't hurt to ask haha Tis the season of giving!
 
were those 260K page full of junk/spam content or something useful articles?
Spam products that were injected into the site. They literally had nothing to do with our site and maybe 300 words of content on each one.
 
That's a pretty sophisticated attack, injecting 260k pages of spam content overnight. I'm curious, were the hackers able to exploit a vulnerability in your site's CMS or was it a case of compromised server access? Also, have you noticed any other suspicious activity on the site since the attack, such as unusual login attempts or malicious file uploads? It's possible that the hackers may have left a backdoor for future exploitation. Did you manage to identify the source of the attack or was it a zero-day exploit?
 
That's a pretty sophisticated attack, injecting 260k pages of spam content overnight. I'm curious, were the hackers able to exploit a vulnerability in your site's CMS or was it a case of compromised server access? Also, have you noticed any other suspicious activity on the site since the attack, such as unusual login attempts or malicious file uploads? It's possible that the hackers may have left a backdoor for future exploitation. Did you manage to identify the source of the attack or was it a zero-day exploit?
It was crazy. We believe it was through WP File Manager but we're still not certain. We think we were able to clean up everything and secure the site, but the damage of the indexed pages are still there. How they indexed them is what has me confused. The site started with 10k pages that took months to fully index, how did they do it so fast? They did, also gain access to the search console so i'm suspecting it had something to do with that. Maybe with help of the google api. But even that has it's limits. 260k? It's an unreal number.
 
It's actually pretty easy. It's called Crawl Control. Basically you use the robots.txt and code in the page to tell google what pages should crawl first. Being new pages and lots of them discovered by interlinking, that was easy.
 
If its an authority site, that huge indexing spike may be possible, they just need to send URLs to some indexing services to draw the Google bot.
 
It's actually pretty easy. It's called Crawl Control. Basically you use the robots.txt and code in the page to tell google what pages should crawl first. Being new pages and lots of them discovered by interlinking, that was easy.
I've yet to hear anyone mention indexing 260k pages overnight as 'easy'. They didn't touch the robots.txt file or any of our sitemaps. They didn't submit any new sitemaps to search console. So what it boils down to is a line of code on each page?
 
If its an authority site, that huge indexing spike may be possible, they just need to send URLs to some indexing services to draw the Google bot.
It has some authority, but not much... That's one of the many reasons why this is weird.
 
It has some authority, but not much... That's one of the many reasons why this is weird.

Authority + ecommerce type site

It's possible, or maybe coincidence, definitely not black hat things, the indexing may drop gradually after the initial big numbers.
 
That's crazy. Sorry if I missed it, but what was their goal? To use those pages to link back to their site, affiliate links, etc.?
 
It was crazy. We believe it was through WP File Manager but we're still not certain. We think we were able to clean up everything and secure the site, but the damage of the indexed pages are still there. How they indexed them is what has me confused. The site started with 10k pages that took months to fully index, how did they do it so fast? They did, also gain access to the search console so i'm suspecting it had something to do with that. Maybe with help of the google api. But even that has it's limits. 260k? It's an unreal number.
It's not hard to do if you control and exploit a network of hacked websites.....few years back I found a vulnerability in a national newspaper website and used it for like 2 years to index anything in minutes....it got patched after I got greedy.
 
Likely a mass-generated doorway page or auto-spun content setup by the hacker Google indexed them fast because they were live and crawlable.
 
the same issue that happened to my website: first the hacker made the site a no-indexed tag for every one of my posts; I realized that and corrected it to indexed, but still the posts are not indexed by Google. If I make a new post, Google will indexed that post after 2-3 days and will deindex the post
 
That's crazy. Sorry if I missed it, but what was their goal? To use those pages to link back to their site, affiliate links, etc.?
I guess was just to build out a million ecomm pages on the site. I didn't see where the checkout links went but they were all random products. Shoes, belts, games...
 
Incredible how quickly hackers can exploit vulnerabilities—reminds us how important website security really is.
 
Back
Top