To handle a Google Attack Site report (when a site is flagged for malware or phishing), you must clean your website's security vulnerabilities and request a review. First, verify ownership in Google Search Console, check the Security Issues menu to see the infected URLs, and follow the recovery steps.
Here is the detailed step-by-step guide to resolve the issue:
1. Inspect and Clean the Website
- Identify Malware: Use the Security Issues report in Search Console or scan your website files using security plugins (like Wordfence for WordPress) or online scanners like Sucuri SiteCheck.
- Remove Malicious Scripts: Delete backdoors, spam scripts, or unauthorized files injected by hackers.
- Update Systems: Instantly update your CMS (e.g., WordPress, Joomla), themes, and plugins to their latest versions to patch security vulnerabilities.
2. Request a Review from Google
- Ensure all compromised files are removed and your system is fully secure.
- Open the Security Issues report inside your Google Search Console dashboard.
- Click the Request Review button.
- Provide detailed explanations of the exact fixes you implemented to speed up Google's verification process, which usually takes a few days.
3. Report False Positives or Phishing
If you believe your site is clean and flagged by mistake, or if you need to report a phishing clone targeting your brand, submit a direct report through Google Safe Browsing for further investigation.