Malware and hacked stores: what Merchant Center policy says
Malware on your store is a Merchant Center problem as well as a security one: the Abuse of the network policy covers malicious software and compromised sites. Clean the whole site, check Search Console’s Security issues report, and only then ask for a review. A half-cleaned store is still a hacked store, and the checkout is the first place to look.
Why this matters
Google's “Abuse of the network” policy for Shopping ads lists “Malicious content” first among the things it does not allow, and splits it in two. Deliberate malware is the rare case: Google calls it egregious, says the account is suspended on detection without prior warning, and the advertiser is not allowed back. The common case is the store that got hacked. The policy calls that a compromised site: “A compromised site refers to a site or destination whose code has been manipulated to act in ways that benefit a third party without the knowledge of the site or destination’s owner or operator, and often in a way that harms the site’s users.” Its examples include a credit card skimmer and “Operating a website using a content management system with known security vulnerabilities, where it has been exploited.” For that case the page promises notice first: “A warning will be issued, at least 7 days, prior to any suspension of your account.” Use those days.
The verdict that counts comes from Google's own tools. Search Console's “Security issues report” help says “you should rely on the Security Issues report as the source of truth to verify whether any security issues exist for your site, or if they have been fixed.” It also says why your own browser can look fine: warnings depend on the browsing context, so you may not reproduce them. And it is strict about the clean-up: “Fix the issue throughout your site. Fixing the issue on just some pages will not earn you a partial return to search results.” The Safe Browsing site status page is the other public check, and its own summary is sobering: “Every day, we discover thousands of new unsafe sites, many of which are legitimate websites that have been compromised.” Plenty of hacked stores belong to people who did nothing worse than skip an update.
Every StoreVerifier scan asks Google Safe Browsing about your store and shows you the answer; a flag there is the most serious thing a scan can return. A clean answer covers that one lookup, not every page on your site, and it is not a Merchant Center decision. For the full picture, check the two Google pages above.
Know the symptoms. Google's spam policies describe injected code, injected pages and redirects, and warn that “The kind of redirect sometimes depends on the referrer, user agent, or device.” A store that behaves only for visitors who type its address is covered in cloaking and sneaky redirects. Once the store is clean, run the free scan for the rest of what shoppers see: policies, contact details, prices and checkout, all listed on the misrepresentation checker.
Typical evidence
A security warning outranks the catalogue
A storefront that serves malware or mines crypto in the browser has a problem more urgent than catalogue hygiene. Treat a Safe Browsing warning as critical, remove the compromise, and verify the clean site before requesting another review.
The public signals this check looks for:
A shopper, your payment provider or your own phone shows a browser warning such as “Decept…
A shopper, your payment provider or your own phone shows a browser warning such as “Deceptive site ahead” on your store.
Search Console's Security issues report lists hacked content, malware or social engineerin…
Search Console's Security issues report lists hacked content, malware or social engineering.
Visitors arriving from Google Search are redirected to spam, pharmacy or gambling pages, w…
Visitors arriving from Google Search are redirected to spam, pharmacy or gambling pages, while typing the address directly looks normal.
An unknown script appears on the checkout or payment page, which is where card skimmers si…
An unknown script appears on the checkout or payment page, which is where card skimmers sit.
New admin users, pages you never created, or strange URLs in your sitemap
New admin users, pages you never created, or strange URLs in your sitemap.
An out-of-date plugin, theme or CMS with a published security hole, or an admin password s…
An out-of-date plugin, theme or CMS with a published security hole, or an admin password shared by email.
A downloadable file on the site, such as a catalogue or an “installer”, that browsers warn…
A downloadable file on the site, such as a catalogue or an “installer”, that browsers warn about.
What it looks like once it is right
The owner opens the Security issues report, finds the sample URLs, updates the CMS, deletes the old plugin and the injected redirect, resets every admin password, confirms from a phone that Google Search now lands on the product, and requests a review listing each change.
Common mistakes
Common mistake
Fix checklist
Clean first, then request review
After a security finding, remove the code, close the entry point, then use the relevant provider’s review process and confirm the result. StoreVerifier cannot predict timing or a platform decision.
Questions merchants ask
Can a hacked website get my Merchant Center account suspended?
It can. Google's Abuse of the network policy treats a hacked store as a compromised site, which leads to disapproval, and says a warning is issued at least 7 days before any suspension. Deliberately distributing malware is handled far more harshly: suspension on detection, without prior warning.
My browser shows no warning. Does that mean my site is clean?
Not necessarily. Google's Security issues report help says Safe Browsing shows warnings based on the browsing context, so you may not be able to reproduce them. It tells you to rely on the Security Issues report in Search Console as the source of truth.
What should I say when I request a review after a hack?
What Google's Security issues help asks for: explain the exact issue, describe the steps you took to fix it, and document the outcome. Request it only when every listed issue is fixed on every page, and do not resubmit while a review is still open.
Remediation
Risk signal
Similar cases
Sources
Last reviewed 23 Sep 2026.
That is one issue. The library documents 134.
The free scan lists what it finds on your store. The paid report adds the affected pages, captured evidence and step-by-step fixes. Start free, with no account needed.