Handle a Google Attack Site report

To handle a Google Attack Site report (when a site is flagged for malware or phishing), you must clean your website's security vulnerabilities and request a review. First, verify ownership in Google Search Console, check the Security Issues menu to see the infected URLs, and follow the recovery steps.


Here is the detailed step-by-step guide to resolve the issue: 


1. Inspect and Clean the Website

  • Identify Malware: Use the Security Issues report in Search Console or scan your website files using security plugins (like Wordfence for WordPress) or online scanners like Sucuri SiteCheck.
  • Remove Malicious Scripts: Delete backdoors, spam scripts, or unauthorized files injected by hackers.
  • Update Systems: Instantly update your CMS (e.g., WordPress, Joomla), themes, and plugins to their latest versions to patch security vulnerabilities.


2. Request a Review from Google

  • Ensure all compromised files are removed and your system is fully secure.
  • Open the Security Issues report inside your Google Search Console dashboard.
  • Click the Request Review button.
  • Provide detailed explanations of the exact fixes you implemented to speed up Google's verification process, which usually takes a few days.


3. Report False Positives or Phishing

If you believe your site is clean and flagged by mistake, or if you need to report a phishing clone targeting your brand, submit a direct report through Google Safe Browsing for further investigation.

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.