Security

Your website could be linking to casinos right now (and you don't know it)

Why one in three hacked sites worldwide belongs to a small business like yours — and how to check yours in five minutes.

7 min read

Recently I reviewed the website of a business. A serious, well-established business that gets most of its clients through referrals. The site looked normal: clear services, tidy copy, a contact form. Nothing out of place.

Until I opened the code.

Hidden in the footer were hundreds of links to betting houses and online casinos. The owner had no idea. Their clients couldn't see them either. But Google could — and it had been seeing them for months.

If you run a business with a website, it's worth reading on. Because this is far more common than it seems, and the pattern that hit that business is exactly the one dominating today.

What SEO spam injection is

An attacker finds an open door into your site —often an outdated plugin— and instead of stealing your data or demanding a ransom, does something quieter: they insert links to their own betting sites, fake pharmacies or scams.

What for? To piggyback on the reputation your domain has built over the years. Every link from your site gives theirs authority in Google's eyes. You put in the effort; they harvest the result.

It's called parasite SEO, and it has one trait that makes it especially dangerous for a business owner: it's designed so you never see it.

Why it's invisible

Attackers don't put those links in plain sight. They use an old but effective trick: they place the block of links off-screen with huge negative coordinates, or hide it with style rules that make it invisible to a person but perfectly readable to a search engine.

The result: you visit your site, it looks spotless, and you assume everything is fine. Meanwhile, Google crawls the code —where the hidden content is plainly visible— and records that your professional domain is linking to a Turkish casino.

That disconnect between what a human sees and what a search engine sees is the attacker's entire business.

How common it is (the numbers are surprising)

This is not an isolated case or a technical curiosity. It's one of the most widespread forms of attack on the internet.

According to GoDaddy's annual cybersecurity report, in 2025 SEO spam affected more than 328,000 websites — 35.2% of all detected threats. It's the second-largest attack category in the world. Put another way: of every three compromised sites, more than one was hit by this exact technique.

And there's a detail that makes the story of the business from the opening fit perfectly: in 2025, for the first time in years, gambling spam became the most frequent type, displacing variants that had dominated for nearly a decade. That business wasn't the victim of something exotic. It was the victim of the year's most common pattern.

Why your business is the preferred target

There's a dangerous belief: "my business is too small for anyone to bother attacking it". The Australian numbers dismantle it completely.

The Australian Cyber Security Centre (ACSC) received more than 84,700 cybercrime reports in the latest period — one every six minutes. And Australian small businesses paid an average of $56,600 per incident, 14% more than the year before.

But the key is how victims are chosen. The ACSC itself puts it bluntly: attackers don't hand-pick targets. They launch automated scans that sweep the internet looking for the easiest doors to open —outdated software, weak passwords, unpatched plugins— and the size of the business rarely enters the equation.

To an automated program, your three-person business site and a corporation's are exactly the same: an address with a possible open door. You weren't chosen. You were found.

The way in: plugins

Most of these attacks come in through the same place: plugins.

In the WordPress ecosystem alone, more than 11,000 new vulnerabilities were discovered in 2025, a 42% increase over the previous year. 91% of them were in plugins, not in the core system. The same dynamic applies to other platforms such as Joomla.

The underlying problem is structural. A site built on these platforms depends on dozens of third-party software pieces, and every one of them needs constant updating. It only takes one falling behind —or worse, a pirated copy downloaded for free— for the door to be left open. Without active, permanent maintenance it's not a question of if it will happen, but when.

How to check your own site in five minutes

You don't need to be technical to do a first check. Try this:

  1. Open your website in the browser.
  2. Press Ctrl+U (or Cmd+Opt+U on Mac) to view the page source.
  3. Press Ctrl+F (or Cmd+F on Mac) to search within that code.
  4. Type terms like casino, bet, giriş (a Turkish word common in these campaigns) or the names of betting houses.
  5. Look at the results counter.

If dozens or hundreds of matches show up in the code of your cleaning, accounting or restaurant site, you have a problem.

A second, even simpler check: search Google for site:yourdomain.com.au and review which pages it has indexed. If you see results you never created, with copy you don't recognise, that's another clear signal.

And if you find nothing — excellent. But it's worth repeating the check every so often, because these attacks arrive unannounced.

The real fix isn't cleaning — it's not being vulnerable

When a site turns up like this, the natural reaction is "clean it". And yes, that has to happen. But removing the links without closing the door they came through only guarantees the problem returns within days.

The more useful question isn't how do I clean this, but why was my site vulnerable in the first place.

Most of these attacks exploit an enormous surface: exposed databases, code that runs on the server with every visit, and dozens of plugins to keep updated. A growing share of modern sites is built differently —generating static pages, with no database open to the public, without that swarm of third-party plugins— precisely so this class of vulnerability stops existing by design.

It's not magic and it's not more expensive. It's simply choosing an architecture where the door automated attackers look for isn't there.


In short

  • SEO spam affects more than a third of all hacked sites worldwide.
  • Small businesses are targets because the attacks are automated, not selective.
  • The damage is invisible to you but perfectly visible to Google, which can penalise your domain without you ever understanding why your rankings dropped.
  • Checking your site takes five minutes and requires no technical knowledge.
  • The real solution isn't cleaning over and over — it's building on a foundation that doesn't have the open door.

I build modern websites for businesses in Australia, with an architecture designed to be fast, secure and easy to maintain. If you'd like me to take a look at yours — no strings attached — drop me a line. A fifteen-minute look is usually enough to know whether there's anything to worry about.

— Javier · javiwarrior.com

© 2026 JaviWarrior Studio. All systems operational.
ABN: 34 656 367 780
WhatsApp