NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
EntityMap v1.0

NegativeSEO.ICU Entity Map

This is the machine-readable knowledge map for NegativeSEO.ICU, published to the EntityMap v1.0 specification. It describes the site's entities — every negative SEO attack vector and the concepts they turn on — with evidence passages drawn from the pages themselves.

View the EntityMap JSON → (41 entities · EntityMap v1.0)

Concept

Anchor Text Poisoning

Links built with commercial, adult or pharmaceutical anchor text. The documented outcome is a withdrawn anchor signal, not a site that ranks for the payload.

Same as: https://en.wikipedia.org/wiki/Anchor_text

Relations:

  • PART_OF → Link-Based Attack
  • RELATES_TO → Negative SEO

Anchor text is the clickable wording inside a link - the words a linking page chooses to describe the page it points at. Search engines have always used it as a description supplied by a third party, on the reasoning that what other people call your page is evidence about what your page is. Anchor text poisoning is a link attack with a payload. Rather than merely pointing junk at a target, the attacker controls the wording and fills it with terms chosen to misclassify the site being linked to.

Anchor Text Poisoning: What It Can Really Do — published by NegativeSEO.ICU
Concept

Forum Profile Spam

Automated profile and signature links at enormous volume, arriving pre-labeled with the one attribute that makes them count for nothing.

Relations:

  • PART_OF → Link-Based Attack
  • RELATES_TO → Negative SEO

Forum profile spam is the automated mass creation of accounts on discussion forums, wikis, guestbooks and any other site that lets a stranger register, where each account carries a link in its profile page (the "About me", "Website" or "Homepage" field) or in the signature block appended to every post the account makes. One run produces thousands to hundreds of thousands of inbound links from low-quality sites, very often with the same commercial anchor text repeated on all of them. Used as negative SEO, the run points at somebody else's site.

Forum Profile Spam: Does the Attack Still Work? — published by NegativeSEO.ICU
Concept

Blog Comment Spam Attack

Automated comments naming or linking a target across other people's blogs, where the enforcement risk falls on the blog and not on the site named.

Relations:

  • PART_OF → Link-Based Attack
  • RELATES_TO → Negative SEO

A blog comment spam attack is the automated posting of large volumes of comments across blogs, news sites and anything else with an open comment form, where each comment carries a link to — or simply names — a site the attacker wants to damage. It is ordinary comment spam turned inside out. Instead of promoting the spammer's own property, the run promotes somebody else's, so that the target appears to be running a crude and obvious link campaign. Two variants fail for different reasons and should be kept apart. The link variant.

Blog Comment Spam Attack: Does It Still Work? — published by NegativeSEO.ICU
Concept

Redirect Hijacking

Spam or penalized domains redirected wholesale at a target. Google says it ignores the links; the brand and crawl damage is what actually remains.

Relations:

  • PART_OF → Link-Based Attack
  • RELATES_TO → Negative SEO

Redirect hijacking is the pointing of a domain you do not control at a site you do own, so that everything the attacker's domain carries arrives at your address uninvited. A domain is the registered name a website answers to - example.com, and every page beneath it. The attacker aims theirs at yours with a 301 redirect : a Hypertext Transfer Protocol (HTTP) response whose status code, 301, means moved permanently and tells browsers and crawlers to treat the destination as the real address from now on.

Redirect Hijacking: Does a 301 Attack Work? — published by NegativeSEO.ICU
Concept

Weaponised Spam Reports

Filing spam reports and takedown notices against a rival. A report cannot invent a violation; a copyright notice removes URLs on assertion alone.

Relations:

  • PART_OF → Link-Based Attack
  • RELATES_TO → Negative SEO

Weaponized spam reporting is the use of a search engine's own abuse machinery against a competitor: filing spam reports, paid-link reports, copyright takedown notices, review flags and local-listing complaints in volume, in the hope that the paperwork itself produces a penalty. A spam report is a form submission telling Google that a site violates its spam policies. In Google Search the relevant channels are the spam report form, the paid links report, the legal removal request - which includes copyright notices under 17 U.S.C.

Weaponized Spam Reports: Can a Rival Use Them? — published by NegativeSEO.ICU
Concept

Content Scraping

Wholesale copying of your pages onto other domains - a hosting and copyright problem far more often than a ranking one.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Content scraping is the automated, wholesale copying of a website's pages onto a domain somebody else controls. A script reads your URLs, frequently straight out of your own XML sitemap, fetches each page, and republishes the body text, the headings, often the images and sometimes the entire template somewhere else, usually with no attribution. It costs the copier nothing to do it to ten thousand pages rather than one, which is why it is almost never done to one.

Content Scraping: Does Being Copied Hurt You? — published by NegativeSEO.ICU
Concept

RSS and Autoblog Theft

A standing subscription to your feed that republishes every new post within minutes - the one copying attack with a genuine speed advantage.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

An automated pipeline subscribes to your site's RSS or Atom feed, polls it continuously, and republishes each new post on a domain somebody else owns - often within minutes of publication. RSS and Atom are the two standard machine-readable formats a publishing platform emits so that software can be told what you have just published; almost every content management system produces one by default, and by default it carries the entire body of each post rather than a summary. That default is what makes the copy costless to make.

RSS and Autoblog Theft: The Speed Problem — published by NegativeSEO.ICU
Concept

Plagiarism That Outranks You

The failure scraping is done for: a copy on a stronger domain heading the duplicate cluster, so your page is filtered out of results for its own text.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Plagiarism - the reproduction of somebody else's words as your own - becomes a search problem at exactly one point: when the copy appears above the original for a query the original was written to win. That is the failure everything else in this subject area is a preamble to, and it is the one that costs money. The mechanism is canonical selection . Google groups pages it judges to be duplicates or near-duplicates into a cluster, then picks one URL - the canonical - to represent that cluster in results.

When a Copy of Your Page Outranks You — published by NegativeSEO.ICU
Concept

Fraudulent DMCA Takedowns

A forged copyright complaint that pulls a page out of Google's index in hours, and a statutory process that takes at least two weeks to reverse.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

A fraudulent DMCA takedown is a forged or knowingly false copyright complaint, filed under the Digital Millennium Copyright Act, whose purpose is to have a competitor's page removed from search results rather than to protect anything the filer owns. A takedown is the removal an online intermediary performs on receipt of such a complaint. Under 17 U.S.C. 512 that intermediary keeps its own liability shield by acting on a facially complete notice first and adjudicating the merits afterward, if at all.

Fake DMCA Takedowns: The Attack That Works — published by NegativeSEO.ICU
Concept

Reverse-Proxy Hijacking

A domain that forwards every request to your live server, so their site is your site - no stored copy, and nothing to serve a takedown notice on.

Same as: https://en.wikipedia.org/wiki/Reverse_proxy

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

A reverse proxy is an intermediary server that takes an incoming request, fetches the page from another server, and returns it to the visitor as though it had served the page itself. The technology is ordinary and overwhelmingly legitimate - every content delivery network is a reverse proxy, and so is most load balancing and edge caching. What turns it into an attack is the origin being proxied: someone points a domain they control at your website and relays your pages under their own hostname, without your permission. The result is not a copy.

Reverse-Proxy Hijacking: A Live Clone of You — published by NegativeSEO.ICU
Concept

Canonical Hijacking

An attacker uses the rel=canonical element on a copy of your page to contest which URL Google treats as the original. It works under narrow conditions.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Canonical hijacking is an attack in which a copy of your page, hosted on a domain the attacker controls, uses the rel="canonical" element to contest which version of the content a search engine treats as the authoritative one. Hijacking , in the search sense, means taking over the identity of something you do not own - here, the identity of a page - without ever touching the server it lives on. The tag itself is ordinary infrastructure.

Canonical Hijacking: Does It Actually Work? — published by NegativeSEO.ICU
Concept

302 Hijacking

A 2000s attack in which a cross-domain temporary redirect made a search engine index the redirector's URL and show the destination's content. Fixed in 2006.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

302 hijacking - also called the 302 page hijack or the page hijack exploit - was an attack in which a page on the attacker's domain returned an HTTP 302 response pointing at a page on your site, and the search engine responded by indexing the attacker's URL while displaying your content under it. Your own listing was then suppressed as a duplicate. A visitor clicking the result landed on your page; the address in the search result belonged to somebody else.

302 Hijacking: An Attack That Died in 2006 — published by NegativeSEO.ICU
Concept

Hacked Site Injection

Spam pages and hidden links written into a site someone else can write to, served to crawlers and hidden from the owner.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Hacked site injection is what happens when someone who is not you gains write access to your website and uses it to publish. Not to deface it - defacement is loud, and this is deliberately quiet. The intruder adds spam pages (URLs on your domain that you never created, usually in directories you have never opened), hidden links inside templates you did create, or code that decides what to serve based on who is asking: your ordinary page for you, a wall of pharmaceutical or gambling keywords for a search engine crawler.

Hacked Site Injection: Spam From Your Server — published by NegativeSEO.ICU
Concept

Malware and Blacklisting

Malicious code that triggers a Google Safe Browsing warning, so a site keeps its rankings and loses effectively all of its traffic.

Same as: https://en.wikipedia.org/wiki/Google_Safe_Browsing

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Malware and blacklisting is the case where an attacker puts hostile code on your site and Google Safe Browsing flags the domain as dangerous. The consequence is not a ranking change. It is a full-page warning shown inside the browser before your page loads , a warning label beside your listing in Google's results, and - if the site is verified - a notice in the Security Issues report in Search Console. Three terms, because they land in the same report and mean different things.

Malware and Blacklisting: A Total Traffic Stop — published by NegativeSEO.ICU
Concept

Spoofed Googlebot

Traffic wearing Googlebot's name to bypass access controls or hide a flood - where the usual damage is done by the defense, not the attack.

Same as: https://en.wikipedia.org/wiki/Web_crawler

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Spoofed Googlebot traffic is requests arriving at your server - the machine that answers when a browser or a bot asks for one of your pages - carrying a Googlebot user-agent string, from IP addresses that do not belong to Google. The user-agent header is a plain text field set by whoever makes the request. Anyone can put "Googlebot" in it. Nothing about it is authenticated, and nothing ever has been. Googlebot is Google's web crawler : the automated program that fetches pages from sites across the web so they can be indexed and ranked.

Spoofed Googlebot: Verify Before You Block — published by NegativeSEO.ICU
Concept

Crawler Overload and DDoS

Sustained request floods that push a site into errors and timeouts, until Google slows its crawling and starts dropping URLs from the index.

Same as: https://en.wikipedia.org/wiki/Denial-of-service_attack

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Crawler overload is what happens when sustained request volume pushes a site into slow responses or errors, and search engine crawling reacts to that unavailability. The volume can be an application-layer denial-of-service attack - a flood of ordinary-looking HTTP requests, as opposed to a network-layer bandwidth flood - or an abusive scraper, or a botnet hammering the most expensive URLs on the site. The target is not a ranking algorithm.

Crawler Overload: When Downtime Deindexes You — published by NegativeSEO.ICU
Concept

Injected Keyword Stuffing

Hidden keyword blocks written into a site's existing pages - a weak payload that proves somebody can write far worse ones.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Injected keyword stuffing is a narrow variant of site compromise in which an intruder writes a block of keyword text into pages your site already owns and already ranks - rather than adding whole spam pages or a malware payload. An invisible container of repeated phrases in the footer. White text on a white background behind a hero image. A zero-height list of city names. Keyword-loaded image descriptions. A paragraph of keyword-dense nonsense appended to the bottom of a legitimate article.

Injected Keyword Stuffing: Symptom, Not Cause — published by NegativeSEO.ICU
Concept

Fake Negative Reviews

Coordinated one-star reviews on Google and other platforms: immediate damage to conversion, unproven damage to ranking, and a removal queue aimed elsewhere.

Same as: https://en.wikipedia.org/wiki/Review_bomb

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

A review bomb is a burst of reviews posted not to describe an experience but to move a number. In the local-business version, a third party posts — or pays other people to post — one-star reviews of a business they never bought anything from, in enough volume to visibly drag the star average down. Three terms are worth separating before anything else, because owners use them interchangeably and they behave differently. A review is a single public rating, usually with text, attached to a business listing.

Fake Negative Reviews: Why Removal Is Slow — published by NegativeSEO.ICU
Concept

Google Business Profile Hijacking

Malicious edits to a listing's name, category, address, hours, phone or website — now largely a problem of unclaimed and unmonitored profiles.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

A Google Business Profile is the record Google holds for a physical or service-area business — its name, address, phone number, website, primary and secondary categories, hours and photographs. It is the thing that renders as a listing in the local pack, as a pin card on Google Maps , and as the knowledge panel beside a search for the business name. Owners call all of it "my Google listing", and when it goes wrong they call all of it hijacking.

Business Profile Hijacking: You Have 3 Days — published by NegativeSEO.ICU
Concept

Fraudulent Closure Reports

Reporting an open business as permanently closed. One accepted edit kills the listing overnight — and one owner-side setting usually reverses it.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

A third party tells Google that an open, trading business has shut down, and Google believes them. The listing — the record that renders in the local pack, on Google Maps , and in the knowledge panel — then carries a Permanently closed or Temporarily closed label. Customers who look the business up are told, by Google, not to bother. Start with the remedy, because it is the most useful sentence on this page and it is the one nobody is told.

Fraudulent Closure Reports on Google — published by NegativeSEO.ICU
Concept

Citation Poisoning

Corrupted name, address and phone data seeded across directories: a real risk to your phone line, and the weakest-evidenced ranking claim in local search.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

A citation , in local search, is any mention of a business's NAP — its Name, Address and Phone number — on a third-party site: a directory, a chamber of commerce page, an industry association listing, a review site, a data aggregator. Citation poisoning is the deliberate seeding of wrong NAP data across those sources: a transposed suite number, a phone number belonging to somebody else, a variant business name, an address the business moved out of three years ago, a closed flag on a directory listing.

Citation Poisoning: The Most Oversold Fix — published by NegativeSEO.ICU
Concept

Brand Mention Spam

A brand name published in bulk beside pharmacy, adult or fraud vocabulary, with no link. The ranking fear is misplaced; the occupancy risk is not.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Brand mention spam is your company name, your product name or your own name published at scale on low-quality pages that also carry pharmaceutical, adult, gambling, cryptocurrency or fraud vocabulary. In its pure form there is no link to your site at all , which is why the attack is also called linkless negative SEO. The pages exist so that the string "YourBrand" and the string "no prescription" or "escort" or "ponzi" appear together, thousands of times, across many domains. An unlinked mention is your brand name in text with no hyperlink attached.

Brand Mention Spam: Does an Unlinked Mention Hurt? — published by NegativeSEO.ICU
Concept

SERP Defamation Campaigns

Grievance pages and complaint posts built to rank for a brand's own name. Legally the hardest attack to remove, and the easiest one to make worse.

Same as: https://en.wikipedia.org/wiki/Defamation

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

Defamation is a false statement of fact, published to a third party, made with the requisite level of fault, that causes reputational harm. A SERP defamation campaign is defamation aimed at a search result: web pages built or amplified so that they rank in Google for your brand name , accusing you of fraud, scams, non-payment, harassment or crime. Written defamation is libel; spoken is slander. What makes the search version distinctive is not the accusation but the placement. The target is not a competitive keyword.

SERP Defamation: When a Smear Ranks for Your Name — published by NegativeSEO.ICU
Concept

CTR and User Signal Manipulation

Engineered search traffic aimed at making a page look unsatisfying. Click data is real; third-party control of it has never been demonstrated.

Same as: https://en.wikipedia.org/wiki/Click-through_rate

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

CTR manipulation is the claim that a stranger can send engineered traffic to your listing in Google's results, make that traffic behave like a disappointed user, and get your page demoted for it. Click-through rate is clicks divided by impressions for one query and one URL, as reported in the Google Search Console Performance report. An impression is a single appearance of your link on a results page; a click , in Google's own definition, is a click that sends the user to a page outside Google Search, Discover or News. Two versions circulate.

CTR Manipulation: Can Bot Clicks Sink Your Site? — published by NegativeSEO.ICU
Concept

Trademark and Platform Complaints

False intellectual property complaints filed with platforms rather than courts. The listing comes down first and the merits are reached weeks later.

Relations:

  • PART_OF → Content & Platform Attack
  • RELATES_TO → Negative SEO

The attacker never touches your website. They file paperwork — with a platform , not a court — asserting that you are infringing an intellectual property right, and the platform's compliance machinery does the damage. No technical skill is required, no budget, and no relationship with the target. It requires a form. Every large platform that hosts commercial content operates a rights-holder complaint channel , and every one of them is built to act on the notice first and adjudicate afterwards.

Trademark Complaint Abuse: Suspend First, Ask Later — published by NegativeSEO.ICU
Concept

Negative SEO

Third-party action intended to reduce another website's visibility in search results, as distinct from an algorithmic update, a manual action, or ordinary technical decay.

Third-party action intended to reduce another website's visibility in search results, as distinct from an algorithmic update, a manual action, or ordinary technical decay.

What Negative SEO Is | NegativeSEO.ICU — published by NegativeSEO.ICU
Concept

Disavow tool

The Google Search Console tool that asks Google to ignore specified inbound links. Google's own documentation states that most sites should not use it.

The Google Search Console tool that asks Google to ignore specified inbound links. Google's own documentation states that most sites should not use it.

The Disavow File | NegativeSEO.ICU — published by NegativeSEO.ICU
Concept

Manual action

A penalty applied to a site by a human reviewer at Google, visible to the site owner in the Search Console manual actions report and removable only by reconsideration.

A penalty applied to a site by a human reviewer at Google, visible to the site owner in the Search Console manual actions report and removable only by reconsideration.

Manual Actions and Reconsideration | NegativeSEO.ICU — published by NegativeSEO.ICU
Concept

DMCA takedown

The notice-and-takedown process created by 17 U.S.C. 512, including the counter-notice procedure and the liability under 512(f) for knowing material misrepresentation.

Same as: https://en.wikipedia.org/wiki/Online_Copyright_Infringement_Liability_Limitation_Act

The notice-and-takedown process created by 17 U.S.C. 512, including the counter-notice procedure and the liability under 512(f) for knowing material misrepresentation.

Fraudulent DMCA Takedowns | NegativeSEO.ICU — published by NegativeSEO.ICU
Concept

Google Safe Browsing

Google's service for identifying unsafe websites, which triggers the browser interstitial that removes effectively all of a flagged site's traffic.

Same as: https://en.wikipedia.org/wiki/Google_Safe_Browsing

Google's service for identifying unsafe websites, which triggers the browser interstitial that removes effectively all of a flagged site's traffic.

Malware and Blacklisting | NegativeSEO.ICU — published by NegativeSEO.ICU
Concept

Google Business Profile

The business listing that feeds Google's local results and map pack, editable through suggested edits and ownership claims — which is what makes it a target.

The business listing that feeds Google's local results and map pack, editable through suggested edits and ownership claims — which is what makes it a target.

Google Business Profile Hijacking | NegativeSEO.ICU — published by NegativeSEO.ICU
Taxonomy

Content and Platform Attacks

Negative SEO attacks aimed at a site's content, infrastructure, listings and reputation — scraping, forged ownership claims, injections, malware, review fraud and listing abuse.

Relations:

  • INCLUDES → Content Scraping
  • INCLUDES → RSS and Autoblog Theft
  • INCLUDES → Plagiarism That Outranks You
  • INCLUDES → Fraudulent DMCA Takedowns
  • INCLUDES → Reverse-Proxy Hijacking
  • INCLUDES → Canonical Hijacking
  • INCLUDES → 302 Hijacking
  • INCLUDES → Hacked Site Injection
  • INCLUDES → Malware and Blacklisting
  • INCLUDES → Spoofed Googlebot
  • INCLUDES → Crawler Overload and DDoS
  • INCLUDES → Injected Keyword Stuffing
  • INCLUDES → Fake Negative Reviews
  • INCLUDES → Google Business Profile Hijacking
  • INCLUDES → Fraudulent Closure Reports
  • INCLUDES → Citation Poisoning
  • INCLUDES → Brand Mention Spam
  • INCLUDES → SERP Defamation Campaigns
  • INCLUDES → CTR and User Signal Manipulation
  • INCLUDES → Trademark and Platform Complaints

Negative SEO attacks aimed at a site's content, infrastructure, listings and reputation — scraping, forged ownership claims, injections, malware, review fraud and listing abuse.

Content and Platform Attacks | NegativeSEO.ICU — published by NegativeSEO.ICU
Top