Skip to main content

Malware and hacked stores: what Merchant Center policy says

Malware on your store is a Merchant Center problem as well as a security one: the Abuse of the network policy covers malicious software and compromised sites. Clean the whole site, check Search Console’s Security issues report, and only then ask for a review. A half-cleaned store is still a hacked store, and the checkout is the first place to look.

Critical5 min read

Why this matters

Google's “Abuse of the network” policy for Shopping ads lists “Malicious content” first among the things it does not allow, and splits it in two. Deliberate malware is the rare case: Google calls it egregious, says the account is suspended on detection without prior warning, and the advertiser is not allowed back. The common case is the store that got hacked. The policy calls that a compromised site: “A compromised site refers to a site or destination whose code has been manipulated to act in ways that benefit a third party without the knowledge of the site or destination’s owner or operator, and often in a way that harms the site’s users.” Its examples include a credit card skimmer and “Operating a website using a content management system with known security vulnerabilities, where it has been exploited.” For that case the page promises notice first: “A warning will be issued, at least 7 days, prior to any suspension of your account.” Use those days.

The verdict that counts comes from Google's own tools. Search Console's “Security issues report” help says “you should rely on the Security Issues report as the source of truth to verify whether any security issues exist for your site, or if they have been fixed.” It also says why your own browser can look fine: warnings depend on the browsing context, so you may not reproduce them. And it is strict about the clean-up: “Fix the issue throughout your site. Fixing the issue on just some pages will not earn you a partial return to search results.” The Safe Browsing site status page is the other public check, and its own summary is sobering: “Every day, we discover thousands of new unsafe sites, many of which are legitimate websites that have been compromised.” Plenty of hacked stores belong to people who did nothing worse than skip an update.

Every StoreVerifier scan asks Google Safe Browsing about your store and shows you the answer; a flag there is the most serious thing a scan can return. A clean answer covers that one lookup, not every page on your site, and it is not a Merchant Center decision. For the full picture, check the two Google pages above.

Know the symptoms. Google's spam policies describe injected code, injected pages and redirects, and warn that “The kind of redirect sometimes depends on the referrer, user agent, or device.” A store that behaves only for visitors who type its address is covered in cloaking and sneaky redirects. Once the store is clean, run the free scan for the rest of what shoppers see: policies, contact details, prices and checkout, all listed on the misrepresentation checker.

Typical evidence

A security warning outranks the catalogue

A storefront that serves malware or mines crypto in the browser has a problem more urgent than catalogue hygiene. Treat a Safe Browsing warning as critical, remove the compromise, and verify the clean site before requesting another review.

Dangerous site
Attackers on yourstore.com might trick you into installing software or revealing information.
Domain reputation
Google Safe Browsingflagged · malware
Rendered-page scancrypto-miner found
Plugin / theme versionsoutdated · CVE
Remove the malicious code, close the entry point (patch plugins, rotate credentials), then request a Safe Browsing review and confirm the status in that tool. Monitor routinely so a compromise is found promptly.

The public signals this check looks for:

  1. A shopper, your payment provider or your own phone shows a browser warning such as “Decept…

    A shopper, your payment provider or your own phone shows a browser warning such as “Deceptive site ahead” on your store.

  2. Search Console's Security issues report lists hacked content, malware or social engineerin…

    Search Console's Security issues report lists hacked content, malware or social engineering.

  3. Visitors arriving from Google Search are redirected to spam, pharmacy or gambling pages, w…

    Visitors arriving from Google Search are redirected to spam, pharmacy or gambling pages, while typing the address directly looks normal.

  4. An unknown script appears on the checkout or payment page, which is where card skimmers si…

    An unknown script appears on the checkout or payment page, which is where card skimmers sit.

  5. New admin users, pages you never created, or strange URLs in your sitemap

    New admin users, pages you never created, or strange URLs in your sitemap.

  6. An out-of-date plugin, theme or CMS with a published security hole, or an admin password s…

    An out-of-date plugin, theme or CMS with a published security hole, or an admin password shared by email.

  7. A downloadable file on the site, such as a catalogue or an “installer”, that browsers warn…

    A downloadable file on the site, such as a catalogue or an “installer”, that browsers warn about.

What it looks like once it is right

The owner opens the Security issues report, finds the sample URLs, updates the CMS, deletes the old plugin and the injected redirect, resets every admin password, confirms from a phone that Google Search now lands on the product, and requests a review listing each change.

Common mistakes

Common mistake

A store owner sees “Deceptive site ahead” on their own product page, clears the browser cache, sees the page load normally and carries on. An old slider plugin had been redirecting phones from Google Search to a gambling site for three weeks.

Fix checklist

Clean first, then request review

After a security finding, remove the code, close the entry point, then use the relevant provider’s review process and confirm the result. StoreVerifier cannot predict timing or a platform decision.

✓Find & remove the injected scripts / redirects
✓Patch or replace the vulnerable plugin / theme
✓Rotate every admin credential; patch the host
4Request a Safe Browsing review & de-listing
5Confirm the flag has actually cleared
Check the domain on Safe Browsing’s site-status tool routinely so a monitor, rather than a customer report, surfaces a compromise.

Questions merchants ask

Can a hacked website get my Merchant Center account suspended?

It can. Google's Abuse of the network policy treats a hacked store as a compromised site, which leads to disapproval, and says a warning is issued at least 7 days before any suspension. Deliberately distributing malware is handled far more harshly: suspension on detection, without prior warning.

My browser shows no warning. Does that mean my site is clean?

Not necessarily. Google's Security issues report help says Safe Browsing shows warnings based on the browsing context, so you may not be able to reproduce them. It tells you to rely on the Security Issues report in Search Console as the source of truth.

What should I say when I request a review after a hack?

What Google's Security issues help asks for: explain the exact issue, describe the steps you took to fix it, and document the outcome. Request it only when every listed issue is fixed on every page, and do not resubmit while a review is still open.

Remediation

Risk signal

A hacked store harms your customers first and your listings second. Clean the whole site, trust Google's Security issues report over your own browser, and once it is clear, run the free scan to check everything else a shopper sees.
PriorityTreat this and any other highest-severity findings as first-priority work, then document each fix.
EvidenceRecord the current state before each change, apply the fix, then capture the corrected state so every change is evidenced.

Similar cases

Sources

  1. Abuse of the network (Shopping ads policy)Google Merchant Center Help — support.google.com
  2. Search Console Help: Security issues report (hacked content and malware)Google Search Console Help — support.google.com
  3. Safe Browsing site status — check a domainGoogle — transparencyreport.google.com

Last reviewed 23 Sep 2026.

That is one issue. The library documents 134.

The free scan lists what it finds on your store. The paid report adds the affected pages, captured evidence and step-by-step fixes. Start free, with no account needed.