Why you typed that, and what this page is going to do about it
I do not take that work, and this page is not a disclaimer. It is the argument I would make if you called, and it is made on facts rather than on how I feel about you.
Most people who arrive here looking for someone to hire are the same person: a small business owner convinced a competitor is cheating and getting away with it, who has watched a rival with worse work sit above them for two years and has lost real income over it. That is not a villainous position. It is what running out of legitimate options feels like.
So here is the honest version rather than a lecture. Almost everything sold under this heading is the one category of attack the evidence says has stopped working: the ordinary outcome of the purchase is that you pay and nothing happens. The part that does still work is criminal in ways that reach whoever commissioned it. And the seller ends up holding something worth considerably more than your fee.
One note for the other half of this traffic, because it is roughly half: people who were attacked and are searching with the attacker's vocabulary. On this site the phrase negative SEO services always means recovery - working out what happened to a site and undoing it. If that is why you are here, start with the triage sequence instead.
What is actually for sale is the one thing that stopped working
Strip the marketing away and the commodity product is link spam: a large number of low-quality inbound links aimed at a target. It is the only version of this that is cheap, automated and available at volume. Everything else - breaking into a server, forging copyright notices, hijacking a Business Profile - is a crime with a named victim and a paper trail.
Link spam is precisely the category the documented evidence says no longer does what a buyer wants. On 23 September 2016, when Penguin moved into its core ranking systems, Google set out the new behavior in a line worth reading twice: "Penguin now devalues spam by adjusting ranking based on spam signals, rather than affecting ranking of the whole site." Devalues, not demotes: the links are discounted rather than charged to the site they point at. On 14 December 2022 Google added that when its systems "nullify spammy links, the link credit that was previously generated is lost" - and a link that confers nothing also costs nothing. That is the mechanical reason the purchase fails, and it is not my opinion; it is Google describing its own architecture.
The public record agrees. The best-documented case of a link attack working is a 2012 agency experiment whose victim was the agency's own disposable test microsite. The best-documented case against a real business is Nick Ker's: a thousand spam links a day for months across 2012 and 2013, after which he reported rankings "nearly the same as they were back in February." The evidence, with dates, is on the spam link attack page.
And you will have no way to check whether you got anything
This is the part that should decide it, and it is a consumer argument rather than a moral one. A link campaign produces a highly visible artifact: thousands of new referring domains appearing in any backlink tool inside a week. That artifact looks exactly like delivery and proves nothing. You cannot establish that the links were built rather than harvested, that anything was aimed at your target on your behalf, or that any movement in a competitor's rankings had anything to do with what you paid for.
So the sequence is fixed. You see the proof. The rankings do not move. The seller explains that these things take another month. You have no contract you would ever enforce, no chargeback you would ever file, no complaint channel you could use, and a counterparty who suffers nothing from being reported. The unauditable purchase is not an accident of this trade. It is the business model.
The cheap thing does not work; the thing that works is a felony
This site documents 33 attack vectors, each reaching its own verdict from its own sources. Seven come out as largely neutralized - and every one of the seven is a link or click-signal attack: 302 hijacking, comment spam, click-through manipulation, forum profile spam, link farms, link velocity spikes, sitewide footer links. Ten come out as documented threats that still work against ordinary sites - and not one of the ten is a link-based ranking manipulation. They are security compromises, abuse of a platform's own complaint and review machinery, and one straightforward crime against the owner.
Put those two counts together and the buyer's position is worse than risky. The affordable product does not work, and the product that works is a felony with a victim, a timestamp and a jurisdiction. There is nothing in between. What is being sold as a middle option is the first thing with the second thing's marketing on it.
The people who did this and were identified by name
Nobody should tell you attackers always get caught. What can be shown is who has been caught, by whom, and what it cost them.
Google unmasks operators and sues them in federal court. In November 2023 it filed Google LLC v. Nguyen (N.D. Cal.) against two individuals alleged to have created at least 65 Google accounts to file fraudulent copyright takedown notices against more than 117,000 competing URLs in one retail niche, with investigators tracing notices touching around 500,000 URLs. Google's complaint says they "have weaponized copyright law's notice-and-takedown process and used it not for its intended purpose of expeditiously removing infringing content, but instead to have the legitimate content of their competitors removed based on false allegations." Secondary coverage reports the matter ending in Google's favor during 2024, though the docket itself is not cited here. Google sued separately in June 2023 over roughly 350 fraudulent business listings and more than 14,000 fake reviews, and again in March 2025 over more than 10,000 illegitimate listings. The first of those is the closest published analogue to what a buyer here is contemplating: competitors using a platform process against their rivals, unmasked by the platform that runs it.
And an SEO practitioner has gone to federal prison for it. United States v. William Laurence Stanley (N.D. Tex.), described in the Justice Department's own release as a self-described black hat search engine optimizer, ran on threats to damage a company's online reputation unless it paid. He was indicted on 27 March 2014, pleaded guilty to one Hobbs Act extortion count on 22 December 2015, and on 5 January 2016 was sentenced to 37 months in federal prison and $174,888 in restitution, with the government estimating 40 to 45 victims.
Victims also unmask attackers without Google's help. One published account describes a Business Profile suspended for over a month after repeated false spam reports, restored only after the owner sued an unknown defendant and subpoenaed Google for the identity behind them - a routine and affordable step that courts grant regularly.
Hiring somebody is not a firewall, and the statute says so
The most common assumption a buyer makes is that the exposure sits with whoever does the work. It does not. 18 U.S.C. section 2(a) reads, in full:
Whoever commits an offense against the United States or aids, abets, counsels, commands, induces or procures its commission, is punishable as a principal.
Commands, induces or procures is a description of hiring, and section 371 covers conspiracy separately. The exposure is set by the act commissioned rather than by the size of the invoice: a small purchase of a serious act is a serious act.
Two further hooks catch the specific things people ask for. Paying for negative reviews about a competitor is a named violation of the FTC's rule on consumer reviews and testimonials, 16 CFR Part 465, effective 21 October 2024, which bars buying reviews expressing a particular sentiment "whether positive or negative" and gives the Commission civil-penalty authority. And the Lanham Act, 15 U.S.C. section 1125(a) - the federal false-advertising and unfair-competition statute a competitor's lawyer reaches for first - turns on a false statement made in commercial promotion, its materiality, and the injury. None of its elements requires proving that a search engine demoted anything. "The links did nothing" is no answer, because the claim is about what was published against the target's name. The theories are set out in full elsewhere on this site, including the honest admission that no decided case is cited under several of them. This page is general information about consequences, not legal advice.
The seller ends up holding your payment trail
Look at what changes hands. You have supplied an identity or a payment instrument, an email address, the name of a target, and a written record of commissioning an attack on a competitor - to a person whose business is attacking companies for money.
Now consider what that business already is. Link removal extortion has two documented shapes: point spam at a target and then email the owner demanding payment to remove it, or skip the links entirely and threaten a campaign for a fee. Either way the trade is selling relief from a threat.
The buyer is a better mark than the target ever was. The target can call the police with clean hands; the buyer cannot. The buyer has demonstrated willingness to pay, supplied a working payment channel, and handed over the evidence that turns a demand into a certainty. I have no figure for how often this happens and will not invent one, because nobody measures it. The structure is the argument: you have introduced yourself to an extortionist as somebody who pays.
That these operators retaliate is documented rather than speculative. While on home confinement in late 2016, after pleading guilty, Stanley went after the company that had reported him to the FBI, posting derogatory material across social networks and complaint sites and encouraging others to copy it. A witness retaliation indictment followed on 7 December 2016, and a federal jury convicted him of it on 19 April 2017 - a second conviction, earned while already sentenced for the first, against a victim whose only act had been to report him.
What surfaces if it ever reaches litigation
The purchase is written down somewhere: email, a chat log, an invoice, a payment record with identity verification on one end. Business records are what discovery exists to produce, and a civil claim of the kind above does not require proving the attack worked - so "it had no effect" will not stop a case opening discovery on payments, communications and everyone involved.
Several of these attacks also self-document. Copyright takedown notices are published with the submitter attached, in Google's transparency reporting and in the Lumen database - which is how the defendants above ended up in a federal complaint with 65 accounts and 117,000 URLs counted against their names. Reviews and profile edits are logged by the platform and produced under subpoena.
The fine is rarely the worst outcome. A filed complaint is public, indexed and permanent, and for a small business the discoverable fact that the owner commissioned an attack on a competitor is the kind of thing that ends an acquisition, a franchise agreement or a lending relationship. It is permanent in exactly the way the attack was supposed to be and is not.
What to do instead, given the grievance is usually real
The underlying complaint is often legitimate: a competitor really is violating Google's policies and really is outranking you. Four things address that, and each has a stated limit.
- Report the actual spam through the actual channel. Google's guidance on reporting quality issues says reports help improve its spam detection and that it may also use one to take manual action. Two caveats decide whether this is worth your time. Google says the text you submit has to be passed on to the site owner where a manual action is issued, so that the owner understands why - which means a report is not anonymous in practice - write it as something you would be content for the competitor's lawyer to read. And a report cannot manufacture a violation: if the competitor is clean, a hundred reports produce a hundred reviewers finding nothing. What a report buys is attention, correctly aimed.
- Use the specific form for the specific problem. Fraudulent listing names, addresses and phone numbers go through the Business Redressal Complaint Form; policy-violating reviews on your own profile go through the reviews management tool; fake reviews are also an FTC matter. Citing the exact policy category is materially more effective than calling something unfair, and every channel Google operates is listed here, including the ones that achieve nothing.
- Document it as it happens - dated screenshots, archived copies, exported link data, the results page as it looked. Contemporaneous records are what a claim runs on later and what makes a report credible now.
- Compete, which is the unglamorous answer and also the arithmetic one. If spam aimed at an established site is nullified rather than charged, a substantial legitimate profile is at once the best available defense and the one thing a competitor's spam cannot buy. The sites that survive attacks are the sites that did not need to be attacked.
Then secure what is actually exposed. Nearly all the residual risk in this subject sits on an unclaimed Business Profile, an unpatched content management system and an unwatched inbox. If you arrived intending to attack somebody and leave having closed your own three openings, that is the only outcome of this page worth anything to either of you.
And if you came here angry because a competitor really is doing something to you — that is a different problem with a real answer. Work out what is actually happening before you spend anything on it, and if you want a second opinion on the evidence you can get in touch.
Frequently asked questions
Can you buy negative SEO, and does it work?
Services claiming to sell it exist. What they mostly deliver is link spam, which is the category Google says it devalues rather than charging to the target, so the ordinary outcome is that money changes hands and the competitor's rankings do not move. The attacks that do still work - compromising a server, forging copyright notices, hijacking a business listing - are criminal acts with identifiable victims, and they are not what is being sold cheaply at volume.
Would I get in trouble if I hired someone rather than doing it myself?
Hiring is not a shield. 18 U.S.C. section 2(a) makes whoever "commands, induces or procures" an offense punishable as a principal, and section 371 covers conspiracy separately. Civil exposure works the same way: a Lanham Act or tortious interference claim turns on what was published against the target and the injury it caused, not on who typed it. Nothing here is legal advice, and anyone genuinely weighing this needs a lawyer rather than a web page.
How would anyone ever find out it was me?
Through the ordinary machinery. Copyright takedown notices are published with the submitter attached; reviews and profile edits are logged by the platform and produced under subpoena; a suit against an unknown defendant plus a subpoena to Google is a routine step that victims take and courts grant. Google has traced operators across dozens of accounts and sued them by name. And the person you paid holds your payment trail and has no reason to protect you.
My competitor really is using spam tactics. What can I actually do?
Report it through Google's spam reporting channel with specific evidence and the exact policy category, knowing that Google says it may pass your submission text to the site owner and that a report cannot create a violation that is not there. Use the Business Redressal form for fraudulent listing data and the reviews tool for policy-violating reviews. Document everything with dates. If the harm is real and attributable, that is a conversation with a lawyer about what was published, not about your rankings.
Do you offer any negative SEO services?
Recovery only. On this site the phrase always means working out whether an attack happened, what it touched, and how it is undone - and a fair share of that work ends with me telling someone that nothing was done to them and no cleanup is warranted. No attacks, no work aimed at a third party's site, no exceptions.