We wrote about negative SEO on the old Purple Imp site years ago. At the time the fear was simple: a competitor buys ten thousand rubbish links pointing at your site, Google decides you’re a spammer, and your rankings fall off a cliff.
That post still got a steady trickle of searches right up until we rebuilt the site, so people are clearly still worried about it. Fair enough. But the threat has moved, and most of the advice out there hasn’t moved with it.
Here’s where it stands in 2026, from the team that looks after 200+ websites on servers we manage, and spends a fair bit of its week reading server logs and Search Console reports.
What negative SEO actually is
Negative SEO is anything someone does to your site, from the outside, to push it down in search. The classic menu:
- Spam links: thousands of low-quality or dodgy-anchor links pointed at you.
- Scraping: copying your content onto other sites so yours looks like the duplicate.
- Hacking: breaking into your site to inject spam pages, links or redirects.
- Fake reviews and profile edits: one-star reviews and “suggested edits” on your Google Business Profile.
- Fake removal requests: bogus copyright complaints asking Google to drop your pages.
Some of these are mostly a thing of the past. Some are very much alive.
The link attack mostly doesn’t work any more
This is the one everybody fears, and it’s the one that matters least now.
For years Google has said its systems are built to ignore spammy links rather than punish the site they point at. If a thousand casino blogs link to your plumbing business, the overwhelming likelihood is that Google shrugs and counts them as nothing.
That changes how you should use the disavow tool. It exists for sites with a manual action for unnatural links, or that expect one because of links they (or an old agency) built. It isn’t a monthly hygiene task, and disavowing links out of panic can do more harm than the links ever would, because you can end up throwing away ones that were helping.
So if someone tells you your rankings dropped because of “toxic backlinks”, ask them to show you. Nine times out of ten there’s a duller explanation.
What can genuinely hurt you
1. Getting hacked
This is the real one. A compromised site can quietly grow hundreds of spam pages (pharmacy, casino, fake shops) that Google finds before you do. You get the “this site may be hacked” label, traffic falls off, and cleaning it up takes longer than preventing it would have.
The volume of attempts is not small. On one day in September 2026, across the WordPress sites on our own servers, we counted around 33,000 blocked attacks on 50 sites, from 1,516 different IP addresses. Blocking the top 20 offenders would have stopped about a third of it, and they rotate. You don’t win this by blocking IP addresses. You win it by closing doors.
One example: WordPress ships with xmlrpc.php switched on, and it lets an attacker try hundreds of passwords in a single request. Almost nobody needs it. We turned it off across every site we host and the attack traffic hitting it went from a fifth of a second of server time per request to practically nothing.
2. Your Google Business Profile
For a local business this is where the damage happens now. Fake one-star reviews, a competitor “suggesting” your business is permanently closed, or edits to your phone number or opening hours. These go straight to the thing people see before they ever reach your website.
Check the profile weekly, respond to reviews, and report fake ones through the profile itself. Google’s policies prohibit fake reviews, and a calm, documented report works better than an angry reply.
3. Scraped content
Mostly a nuisance. Google is generally good at working out who published first, especially if your site is fast, well linked and indexed quickly. It becomes a problem when the copy outranks you, which usually means your own page has a weakness worth fixing anyway.
4. Fake removal requests
Rare, but nasty when it happens. Someone files a copyright complaint claiming your page copied theirs, and Google removes it. If a page vanishes and Search Console mentions a legal removal, you can file a counter-notice.
The uncomfortable truth: most “negative SEO” is self-inflicted
When a site drops, the cause is far more often something the owner (or their agency) did than something a rival did. We’ve seen all of these, and done some of them.
Redirects that loop
We once watched a client’s home page redirect to itself for two days. The CDN in front of the site stored the “www goes to the main domain” redirect and then served it for the main domain too, so the home page sent visitors round in a circle. Nobody attacked anything. A caching setting did it. We fixed it at the CDN, then checked every other site we host for the same setup and fixed those too.
Migrations that lose the old URLs
We rebuilt purpleimp.com in September 2026. Afterwards our own Search Console showed dozens of 404s, old service URLs landing on the wrong pages, and Google still reading a sitemap that no longer existed. None of that was sabotage. It was us, and it’s exactly what happens after most rebuilds. Every old URL with traffic or links needs a single, direct redirect to its closest new page.
Junk you never published
Our Search Console also listed pages like /220338186.htm and /?play= links to casino spam. They were URLs we had never published. Whether they come from an old compromise or from spam sites linking to made-up addresses, the answer is the same: make sure they return a proper 410 Gone (or 404), never a redirect to your home page and never a friendly error page that returns “200 OK”.
Leftover files
Backup copies like functions.php.bak-20260914 are what people make before editing a live site. On a lot of servers they can be downloaded as plain text, source code and all. It’s a security problem first, but it’s also how sites end up with hacked content and warnings in search.
How to protect your site: the short list
- Look at Search Console every month. Security issues, manual actions, and the page indexing report. A sudden jump in indexed pages you don’t recognise is the earliest warning you’ll get of a hack.
- Keep everything updated, use strong unique passwords with two-factor login, and remove plugins you don’t use.
- Close the doors you don’t need: xmlrpc, public backup files, directory listings, old admin tools.
- Have backups you’ve actually tested restoring.
- Watch your Google Business Profile weekly.
- Plan every migration: a full redirect map, a clean sitemap, and a check of Search Console the week after.
- Don’t panic-disavow. Unless you have a manual action, you almost certainly don’t need to.
Think you’re under attack?
Before blaming a competitor, work through it in this order:
- Check Search Console for manual actions and security issues.
- Search
site:yourdomain.comand look for pages you didn’t make. - Look at what changed on your site recently: a plugin, a theme, a migration, a CDN setting.
- Compare the drop with known Google updates. A lot of “attacks” turn out to be algorithm updates.
- Only then look at the links, and only act on them if there’s a manual action.
If you’d rather someone else did the digging, that’s what we do. Our SEO work starts with exactly this kind of audit, and our hosting and support is where the doors get closed. Tell us what’s going on and we’ll tell you honestly whether it’s sabotage or something much more boring.
Got a problem like this? Good. We like those.
Tell us what you’re dealing with and we’ll tell you honestly what we’d do.


