Someone is attacking your site. Probably not.
Most suspected negative SEO turns out to be a core update, a botched migration, or a tracking change. Some of it is real, and a few of the real ones are serious. This is the reference that tells you which is which — 33 attack vectors, each with a verdict on whether it actually works, how it is detected, and how it is undone.
Three verdicts, 33 vectors
Every attack page on this site opens with one of three verdicts, before a word of prose. 10 are documented threats that work against ordinary sites today. 7 are largely neutralized, and saying so is the point — anyone selling you protection from those is selling you something you do not need.
The attacks people ask about most
What is being attacked
Attacks divide cleanly by what they aim at — and the division predicts which ones work. The ones that try to fool a link algorithm have mostly stopped working. The ones that compromise your own site, your listing or your reputation still work exactly as well as they ever did.
Link-based attacks
Spam link blasts, poisoned anchors, forged endorsements. This is the family the phrase “negative SEO” usually means, and it is the family where most of the fear is now out of date.
Content & platform attacks
Theft, forged ownership claims, injections, malware, fake reviews, listing hijacking. Less discussed, and where nearly every attack that genuinely works now lives.
Detect, recover, prevent, and the law
Negative SEO recovery
I work on negative SEO recovery: establishing whether an attack actually happened, what it touched, and what will undo it — and saying so plainly when the answer is that nothing was done to you.