We Found 14 Hacked Local Business Websites. Here's What Was Hidden on Them
While reviewing Ontario business websites, we came across 14 that had been quietly filled with hidden gambling links and pages. What was added, why owners rarely notice, and how to check your own site in a few minutes.
Over the past couple of weeks, while reviewing local business websites across southern Ontario, we came across 14 that had been changed by someone other than the people who run them. They belong to a law firm, a medical clinic, an optometrist, two golf clubs, a banquet hall, a wedding venue, a bed and breakfast, a pub, a jeweller, an antiques market, a contractor, a truck repair shop and a computer repair shop.
At a glance, none of them looked hacked. The pages loaded normally and the menus worked. Most of the changes were made to be read by search engines, not by people. We're getting in touch with each business privately, so we won't name anyone here. The patterns are worth knowing, though, because they're common and easy to miss.
What had been added
Hidden links. The most common change was a block of links to gambling websites tucked into a page where visitors can't see it: pushed thousands of pixels off the side of the screen, squeezed down to one pixel tall, or set to invisible. One home page carried more than 1,400 hidden links.
Pages nobody can find. On several sites, someone had added pages that aren't linked from any menu but are listed for search engines. Two sites had more than 2,000 gambling pages each, added through an extra sitemap file. A contractor's site had about 200 gambling articles posted over 20 months, a bed and breakfast had 60 posted in three months, and a jeweller's site had 80 pages.
Rewritten text. On both golf club sites, the spam was worked into the real content. One course description now calls the club a casino facility. The other club's history page says its history is tied to a casino website, with a link to it.
Hijacked link previews. On two sites, the text that appears when someone shares a page in a message or on social media had been replaced with gambling copy.
Other languages. The spam was written in French, German, Polish, Russian, Japanese, Hungarian, Turkish and several other languages, more than a dozen in all. None of it is aimed at local customers.
Why anyone would do this
Links still play a part in how search engines rank pages, and a link from an established local business website carries weight. Gambling sites, essay-writing services and similar operators pay for links, and some of the people who supply them get them by breaking into websites and adding them quietly. Your site's years of good standing are what's being sold.
The cost lands on the business. Google can label a site "This site may be hacked" in its search results, push its pages down, or stop showing them, and a customer who lands on a spam page loses trust quickly. A site that has been broken into also usually means someone still has a way back in.
Why owners don't notice
Staying hidden is the whole point. The spam doesn't show on the pages an owner visits, the extra pages aren't in any menu, and nothing breaks. On one site, new spam articles were still being added more than a year and a half after the first ones appeared. Most owners find out from a customer, from Google, or from someone like us.
How to check your own website
You don't need any software for this, and it takes about five minutes.
- Search Google for your own site. Type site:yourdomain.ca casino into Google, using your own address, then try the same with slots, betting and essay. Pages you never made are a strong sign something is wrong.
- Look at your home page's source code. In most desktop browsers, right-click the page and choose View Page Source, then search it (Ctrl+F, or Cmd+F on a Mac) for casino, slot and bet.
- Check your robots.txt file. Go to yourdomain.ca/robots.txt. A "Sitemap:" line pointing to a file you don't recognize deserves a closer look.
- Skim your sitemap. Most sites have one at yourdomain.ca/sitemap.xml, and WordPress sites often use wp-sitemap.xml. Look for page or post titles you didn't write.
- On WordPress, check Users and Posts. Look for accounts you don't recognize and posts you didn't publish.
- Use Google Search Console. If your site is set up there, the Security Issues report shows whether Google has found a problem.
If you find something
Deleting the spam pages is rarely enough on its own. Whoever added them usually left a way back in, and the pages tend to reappear. Treat it as a break-in: have whoever looks after your website find out how they got in, close that door, and change every password involved. We cover the most likely ways in, and what prevents them, in How Small Business Websites Get Hacked.
Keep reading
All articlesHow Small Business Websites Get Hacked, and What Actually Prevents It
We looked at how 14 hacked local business websites were set up. An out-of-date WordPress was rarely the common thread. Here are the likelier ways in, and the habits that close them.
Read articleThe Network Security Gaps Most Small Businesses Don't Realise They Have
Most small business networks share the same firewall and segmentation gaps. Here are the ones we find most often, and how to close them before they cost you.
Read articleWhat a NIST Cybersecurity Risk Assessment Actually Involves
A plain-language walk through what a NIST cybersecurity risk assessment looks at, what you receive at the end, and why any small business benefits.
Read articleLet's build something great.
On-site assessments are free for new business projects. We'll come to you, evaluate your needs, and provide a clear, no-obligation quote.