March 22, 2017 By Mark Samuels 2 min read

Chronicles of site hacking continue to increase, and businesses must take steps to ensure their online properties are safe and secure.

Google recently reported hacked site numbers increased by about one-third (32 percent) through 2016. The search giant added it does not expect this trend to slow down this year, since cybercriminals become increasingly aggressive in their tactics.

Who Gets Hacked?

Google found that hacked sites are often affected in similar ways. One of the most popular methods of attack is the gibberish hack, where attackers create pages filled with keywords on a target site. These pages rank highly in search and can be used to redirect unsuspecting individuals to malicious content.

A second approach is the Japanese keywords hack, where attackers create Japanese text pages containing links to stores selling counterfeit goods. There is also the cloaked keyword attack, where pages appear to be part of an original, legitimate site but contain hidden links to dubious content.

Google expected the problem to increase further. In fact, the company suggested malicious actors will continue to capitalize on the internet by infecting more online properties as sites become outdated.

Staying Ahead of Attackers

Webmasters who fix problems via manual notification from Google can apply for a site review through a reconsideration request. Google reported as many as 84 percent of webmasters who apply for reconsideration successfully clean their sites.

However, webmasters will only receive a notification of infection if their sites are verified in Search Console, a free service that allows site owners to check site performance. Almost two-thirds (61 percent) of webmasters did not receive a notification from Google that their site was infected because they were not verified in Search Console.

Google encouraged site managers to register for Search Console, since the service remains the firm’s main communication channel for site health alerts.

How to Avoid Becoming a Hacked Site

IT managers and webmasters must be aware of the risk a hacked site poses. They should take preventative and proactive measures to keep errant individuals at bay.

The web has become the platform of choice for many attackers, and websites are not the only target. Experts have reminded developers to program defensively to prevent security bugs from cropping up in their online software. Security professionals should also be aware of vulnerabilities posted by connected Internet of Things (IoT) devices — ForeScout stated that some products can be compromised in as little as three minutes.

Google reminded webmasters that it is always best to take a preventative approach rather than having to deal with the aftermath of an attack. Site leaders should stay on top of updates from content management system providers as well as software and hardware vendors.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today