NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Abstract square grid illustration representing PBN Link Attack
Link-Based AttackYour backlink profile

PBN Link Attack

Situational Works only under specific conditions, and rarely otherwise.

Private blog network links pointed at a competitor: the most sophisticated link attack, and the one with no documented case behind it.

What a PBN link attack is

A private blog network, almost always abbreviated to PBN, is a set of websites controlled by one operator and maintained for a single purpose: passing link value to a site that operator wants to rank, known in the trade as the money site. The network sites are usually built on expired domains that retain inherited authority, and they are dressed to look independent - separate registrations, separate hosting, plausible content - because their whole value depends on not appearing related.

A PBN link attack is the use of such a network against a site the operator does not own: pointing network links at a competitor in the hope that Google identifies the network, concludes the target built it, and demotes the target for it.

This is the most sophisticated form of link attack and the one that worries defenders most, for a reason worth saying plainly. PBN links do not look like spam. They arrive from aged domains with real content and clean-looking profiles. The standard reassurance - that Google ignores obvious junk - is at its weakest here, because these links are engineered specifically not to be obvious junk.

That is the case for taking it seriously, and it is a fair one. The case against it is stronger, and it is economic before it is technical.

The paradox at the center of the attack

A network exists to pass value. Every design decision in one - the aged domain, the written content, the clean outbound profile, the separate hosting - is made so that the links will count. Which means that if the network goes undetected, its links to the target help the target. The attacker has spent real money and months of domain acquisition handing a competitor free authority.

The attack only pays if the network is detected. And when Google detects a network, its documented response is to neutralize the links rather than charge them to whoever received them. Announcing the December 2022 link spam update on 14 December 2022, Google stated that SpamBrain, its machine-learning spam system, "can now detect both sites buying links, and sites used for the purpose of passing outgoing links," and that when "our systems nullify spammy links, the link credit that was previously generated is lost."

"Sites used for the purpose of passing outgoing links" is Google's own description of a PBN, published and dated, and the stated consequence is that the credit is lost - which, for a target that never had the credit, is no consequence at all.

So the attacker has two outcomes. Undetected, and the target gains. Detected, and the target is returned to where it started. Neither is a win. The only path to harm runs through Google mistakenly attributing the network to the target, and every architectural change since 2016 has moved away from that kind of attribution.

Why 2014 is the source of the fear, and why it is misread

In autumn 2014 Google ran conspicuous action against private blog networks, combining de-indexing of the network sites with thin-content penalties on the money sites receiving links from them, as reported by Eric Enge at Search Engine Watch on 7 October 2014. That episode is the origin of the modern fear, and it is routinely misread.

The money sites penalized were sites whose operators had built or rented the networks themselves - the beneficiaries and orchestrators, identifiable as such because the relationship between network and money site was one of common control and consistent benefit over time. It is not evidence that an arbitrary third party can hand a competitor a penalty by pointing a network at them.

It is, however, fair evidence that in 2014 Google was willing to act against link recipients. That is exactly the posture Google abandoned two years later, which makes the date the whole point: the 2014 answer and the answer from 2016 onward are different facts about different systems, and quoting the first in the present tense is quoting a wrong fact.

What Google changed in 2016

On 23 September 2016, announcing that Penguin had become part of the core ranking algorithm, Google wrote the sentence this subject turns on: "Penguin now devalues spam by adjusting ranking based on spam signals, rather than affecting ranking of the whole site." It added that Penguin's data now refreshes in real time, "so changes will be visible much faster, typically taking effect shortly after we recrawl and reindex a page." Both quotations come from independent same-day transcriptions of the post, which does not render its body to a plain fetch.

That is Google's own statement of the shift from demotion to devaluation, and it removes the mechanism a PBN attack depends on. Google's disavow documentation states the third-party point even more directly: "Google works very hard to make sure that actions on third-party sites do not negatively affect a website."

Google's internal Content Warehouse API documentation, published to a public code host in March 2024, is consistent with both. It documents penguinPenalty as a "Page-level penguin penalty," matching the 2016 wording about not affecting the whole site, and it carries penguinEarlyAnchorProtected - "Doc is protected by goodness of early anchors." The companion module bounds the damage in time, with demotedStart and demotedEnd documented as the start and end of a demotion period, and leans on trusted-source comparison through trustedTotal, "Total number of trusted sources for this URL." None of that is proof: leaked documentation establishes that a field was written, not that it decides a live ranking, and parts of the corpus are marked deprecated. Taken at face value, though, the fields name the asymmetry practitioners observe. A site with a long, good early link history carries documented protection. An established business is a poor PBN target. A six-month-old site is not.

The opening that keeps this off the myth verdict

There is one, and it is worth stating exactly rather than dismissing. John Mueller, whose job at Google is answering site owners' questions publicly and on the record, described the first-line behavior in a Search Central video reported on 1 November 2021 as trying to ignore links it recognizes as spammy - and then added the qualification: "if we see a very strong pattern there, then it can happen that our algorithms say well we really have kind of lost trust with this website."

That is the theoretical opening for a PBN attack, and the only one. A network sophisticated enough to be inseparable from a target's legitimate profile could in principle produce a site-level trust failure. Executing it requires a network good enough to be indistinguishable from real editorial links - which is a network worth far more pointed at the attacker's own property than spent on a competitor.

The narrow places where the opening is genuinely reachable:

  • New sites and new pages, where early-anchor protection cannot apply and the network's links are a large share of a small profile.
  • Sites already using networks themselves. This is the most realistic scenario on the page. If a site's own profile already contains network links, an attacker's network merges indistinguishably with the target's real violations, and the "cannot isolate" condition is satisfied - by the target's own conduct rather than the attacker's skill. Buying links is what makes a site attackable with links.
  • Sites already carrying a manual action, where the attack compounds an existing finding.
  • Sites filing a reconsideration request, where a human reviewer examining the profile will see the network links along with everything else.
  • Bing and smaller search engines, which do not necessarily share Google's devaluation posture and are worth checking separately.

There is no documented case, and that matters

No disclosed PBN attack exists in the public record that I could locate - no case study, no experiment, no account by a victim or an attacker. The three well-known documented link attacks all involve cheap bulk spam rather than networks: the TastyPlacement experiment against its own test site on 7 June 2012, Nick Ker's contemporaneous account of a failed attack on his established site published 30 July 2013, and Eliav Lankri's account of a 600,000-link attack that did draw a penalty, published 17 November 2014.

That absence is consistent with the economics. Nobody spends network money on an attack, and so nobody has documented doing it. Given the cost of building a network and the legal exposure in admitting to one being used offensively, it is unlikely such a case will ever be published.

Which means the entire practitioner literature on this vector rests on inference. That is the most important thing on this page, and I would rather say it than let the page imply otherwise: the link attack readers fear most is the one with the least evidence behind it. Everything above is reasoning from Google's documented behavior and from the economics of building a network, not from a case anybody can point to.

How a network is recognized

PBN links are recognized by network characteristics, not by looking spammy. That is the entire difficulty, and it is why toxicity scores fail here.

  • Search Console, Links, External links, Top linking sites, exported, with the "Latest links" sample. Establish what arrived and when.
  • Search Console, Security and Manual Actions. Check this first. "No issues detected" means no human at Google has penalized the site, and most of the remediation literature does not apply to you.
  • Top linking text. A network built to attack usually carries deliberately chosen commercial anchors, which makes it an anchor attack as well.
  • The network shape across the new referring domains: sites that went live or changed hands within a narrow window; near-identical templates; content that is thin, spun, or on topics with no relation to one another; outbound links to unrelated commercial sites; boilerplate or absent contact pages; domains whose archived history shows a completely different former business.
  • Registration and hosting overlap - with the caveat that competent networks deliberately avoid it, so its absence proves nothing while its presence is strong evidence.
  • Search Console Performance against the update calendar, before sabotage is assumed at all.

What this is commonly mistaken for: a core or spam update; a partner's legitimate niche-blog outreach; a syndication network; a scraper network; expired domains in your niche that happen to have been rebuilt; and, frequently, the site's own historic link buying resurfacing years later. A meaningful share of PBN attacks turn out to be old invoices, and that possibility deserves checking before an attacker is assumed.

If you think you are looking at one

  1. Confirm whether a manual action exists. If Search Console shows none, there is no penalty, and the correct next step is almost always to stop.
  2. Check the update calendar against the date the traffic moved.
  3. Establish whether the links are your own history. Ask whoever handled marketing before you, and ask specifically.
  4. Document the network now - dates, screenshots, exports. Network domains are disposable and vanish, and this evidence decays faster than any other kind on this site. A site owner who waits six months has nothing left to document.
  5. Do nothing further, in most cases. Devaluation is automatic and asks nothing of you.
  6. Disavow only where Google's two-part test is met: a considerable number of spammy, artificial or low-quality links and a manual action they have caused or likely will cause. Even then, only where you have positively identified a cluster and can articulate why each domain belongs to it - and disavow at domain level rather than URL level, since a network's individual URLs are trivially replaced.
  7. Build the trusted baseline. Because the documented mechanism compares against trusted sources, the durable defense is a legitimate profile large enough to make any network statistically marginal.

What does not help: contacting network owners, who are anonymous by design; reconsideration requests with no manual action outstanding; disavowing every domain a toxicity score dislikes; and publicly accusing a competitor.

Why a good network is hard to sue

Google offers no complaint route for hostile links. The disavow tool is a request to ignore rather than a report, and Google's spam report form addresses the spamming site's conduct, not harm to a target. Google's own disavow documentation warns that the tool "can potentially harm your site's performance in Google Search results" if used incorrectly and that "most sites will not need to use this tool."

Where a network can be traced - and it usually cannot without discovery - the US theories are tortious interference with prospective business relations; defamation, where the network publishes false statements of fact about the target; the Lanham Act, 15 U.S.C. section 1125(a), for false advertising or unfair competition between competitors; and state unfair competition and business disparagement statutes. The Computer Fraud and Abuse Act, 18 U.S.C. section 1030, is not engaged by link building alone, because no unauthorized access to the target's systems occurs. Realistically, attribution is the barrier rather than the legal theory: networks are built anonymously, and without a subpoena to a registrar or host there is generally no defendant to name.

There is a second barrier specific to this vector, and it is the paradox repeating itself. Every theory above depends on something the links say - a false statement, a misused mark, a disparaging claim. A well-built network does the opposite of shouting: its anchors are clean, plausible and on-topic, because that is what makes the links look natural. Strip out the false statement and nothing is left to plead except "my rankings fell," which requires proving what Google's systems did with the links - evidence inside Google that a private plaintiff cannot obtain. The more sophisticated the network, the weaker both the attack and the victim's remedy. No decided case establishing liability for a PBN attack is cited here, and none should be assumed. Where an extortion demand accompanies the links, that is a law enforcement matter and a far stronger one.

Frequently asked questions

How do I tell whether a backlink is from a PBN?

You look at the network rather than the link. One aged domain with thin content proves nothing. A cluster of domains that changed hands in the same window, share templates or content patterns, carry unrelated outbound commercial links, and have boilerplate or missing contact pages is the shape worth recording. Registration and hosting overlap is strong evidence when present, and no evidence at all when absent - competent networks avoid it deliberately.

Should I disavow every PBN link I find?

No, and PBN attacks generate more unnecessary disavow files than any other vector, because the domains look plausible enough to alarm and spammy enough to seem to justify acting. Google's criteria require a manual action as well as the links. Absent one, you would be permanently discarding equity to counter links Google's documented behavior is already to nullify.

Could a competitor really buy a network just to attack me?

They could, and it would be a poor investment. An undetected network passing links to you helps you; a detected one has its links nullified rather than charged to you. The money buys nothing in either branch. That is the main reason no disclosed case of this attack exists, and it is why the verdict is Situational rather than a documented threat.

These links look like something my old agency did. Does that change anything?

It changes everything. Links your own site commissioned are your own conduct, they merge with any hostile links so that neither can be isolated, and they are the single condition that makes a site genuinely vulnerable here. Find out what was bought and when before treating any of it as an attack, and never describe historic buying in a reconsideration request without advice.

Is PBN detection software worth buying?

Detection tooling that shows you registration, hosting, template and timing patterns is doing real work, and it is what network identification actually requires. A single toxicity score is not. It compresses the only useful evidence - the pattern across domains - into a number Google has no counterpart for, and then recommends the one action most likely to hurt a site that was never affected.

Top