March 22, 2017 By Mark Samuels 2 min read

Chronicles of site hacking continue to increase, and businesses must take steps to ensure their online properties are safe and secure.

Google recently reported hacked site numbers increased by about one-third (32 percent) through 2016. The search giant added it does not expect this trend to slow down this year, since cybercriminals become increasingly aggressive in their tactics.

Who Gets Hacked?

Google found that hacked sites are often affected in similar ways. One of the most popular methods of attack is the gibberish hack, where attackers create pages filled with keywords on a target site. These pages rank highly in search and can be used to redirect unsuspecting individuals to malicious content.

A second approach is the Japanese keywords hack, where attackers create Japanese text pages containing links to stores selling counterfeit goods. There is also the cloaked keyword attack, where pages appear to be part of an original, legitimate site but contain hidden links to dubious content.

Google expected the problem to increase further. In fact, the company suggested malicious actors will continue to capitalize on the internet by infecting more online properties as sites become outdated.

Staying Ahead of Attackers

Webmasters who fix problems via manual notification from Google can apply for a site review through a reconsideration request. Google reported as many as 84 percent of webmasters who apply for reconsideration successfully clean their sites.

However, webmasters will only receive a notification of infection if their sites are verified in Search Console, a free service that allows site owners to check site performance. Almost two-thirds (61 percent) of webmasters did not receive a notification from Google that their site was infected because they were not verified in Search Console.

Google encouraged site managers to register for Search Console, since the service remains the firm’s main communication channel for site health alerts.

How to Avoid Becoming a Hacked Site

IT managers and webmasters must be aware of the risk a hacked site poses. They should take preventative and proactive measures to keep errant individuals at bay.

The web has become the platform of choice for many attackers, and websites are not the only target. Experts have reminded developers to program defensively to prevent security bugs from cropping up in their online software. Security professionals should also be aware of vulnerabilities posted by connected Internet of Things (IoT) devices — ForeScout stated that some products can be compromised in as little as three minutes.

Google reminded webmasters that it is always best to take a preventative approach rather than having to deal with the aftermath of an attack. Site leaders should stay on top of updates from content management system providers as well as software and hardware vendors.

More from

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today