Hacked and cloaked links: how to recognise them and why to avoid them

A hacked link is placed on a website without the owner's permission, which is a crime against that owner. A cloaked link is shown to one audience and hidden from another, often to cheat the buyer. Both are sold as ordinary placements. A few checks before you pay will catch most of them.

In short

  • Hacked links are injected into compromised websites and are sometimes resold to unsuspecting buyers as cheap niche edits or as links from education and government sites.
  • Medianama reported in June 2026 that 223 Indian government websites had been hacked to carry gambling content.
  • Unauthorised access to a computer system is a criminal offence in practically every jurisdiction, and a buyer can be exposed to legal claims.
  • A cloaked link can mean the buyer sees a live link while Googlebot is served a page without it, or a page set to noindex.
  • Fetching the page as Googlebot and checking the rendered page, the robots rules and the canonical catches most cloaking.

A hacked link is one placed on a website by someone who broke into it. A cloaked link is one that different audiences see differently: visible to Google and hidden from visitors, or shown to the buyer and hidden from Google. The first is a crime against the site owner. The second is usually a fraud against you.

Both are sold as normal placements, so you need to recognise them. This lesson describes what they look like and what to check. It gives no instructions for creating either.

Attackers get into websites through weaknesses in content management systems, stolen passwords, or pirated themes and plugins that carry a backdoor. Once inside, they add links or whole pages that point to the sites they want to rank.

Google’s spam policies, last updated in August 2026, define hacked content as content placed on a site without permission because of a security weakness. The examples it gives include injected pages and hidden links or text added to existing pages.

Access to these compromised sites is sold in underground markets. From there, links are sometimes resold to buyers who do not know the origin, described as niche edits or as links from education and government domains.

How large the problem is

This is not rare, and gambling is the sector where it has been documented most.

  • Medianama reported in June 2026 that 223 Indian government websites had been hacked to host gambling content.
  • Casino.org reported in 2026 that an illegal gambling group hijacked about 20 African government websites in 16 countries to improve its Google rankings.
  • Anticoruptie.md reported that the website of Moldova’s Chamber of Commerce hosted illegal casino spam for 49 days from 16 April 2026.

These cases show the pattern: trusted domains, hidden pages, and content the owner did not know about for weeks. Our high-risk markets hub sets them in context.

Why to stay away

It is a crime. Unauthorised access to a computer system is an offence in practically every jurisdiction. A buyer who knew, or should have known, can be exposed as an accomplice and to civil claims from the site owner. This is general information, not legal advice.

The link does not last. It vanishes when the owner cleans the site. In the Moldova case that took 49 days.

It breaks Google’s policy. Hacked content is a named spam category, and Google’s October 2023 spam update is reported to have targeted it along with cloaking.

A real organisation is harmed. The site owner faces clean-up costs, security warnings in search results and loss of trust.

There is no version of this that is acceptable for any site. A written link policy should ban it outright, as link buying policy and governance recommends.

Google’s spam policies define cloaking as presenting different content to users and search engines with the intent to manipulate rankings and mislead users. For links, it appears in two directions.

Hidden from visitors, shown to Google. This is how most injected links work. The link sits in the page code but is hidden with styling, placed off screen, or served only to search engine crawlers. The site owner browsing their own pages sees nothing.

Shown to the buyer, hidden from Google. This is the seller’s trick. You are sent a URL with your link on it. Meanwhile, one of the following is true:

  • Googlebot is served a version of the page without the link, or with a nofollow attribute.
  • The page carries a noindex tag, or an X-Robots-Tag header that does the same.
  • The page’s canonical tag points to a different URL.
  • The article folder is blocked in robots.txt.
  • The link is added by a script that crawlers do not run.
  • The article is an orphan: live at its URL but linked from nowhere on the site.

In each case you paid for a link that passes nothing.

How to recognise them

Sign Hacked link Cloaked by the seller
Casino, pharmacy or loan anchors on a school, church or municipal site Strong sign
Link present in the source but invisible on the page Strong sign
Very cheap links on education or government domains Strong sign
Seller cannot change the text around the link Strong sign Possible
Seller will not name an editorial contact or show ownership Strong sign Possible
Page looks different when fetched as Googlebot Possible Strong sign
Page is noindex, blocked or canonicalised elsewhere Strong sign
Article cannot be reached from the site’s navigation Possible Strong sign
Link disappears suddenly with no notice Strong sign Possible

The two warnings about the seller matter most. A real publisher can edit a sentence and can put you in touch with an editor. A seller who can only “drop a link” into a page, and cannot alter anything around it, may not have legitimate access.

Checks before you pay

These are the standard post-publication checks used in link quality control. Run them on every paid placement, not only on suspicious ones.

  1. View the rendered page. Confirm the link is visible to a normal visitor, in context.
  2. View the source. Confirm the link is there, with the agreed attribute.
  3. Fetch with a Googlebot user agent and compare. The page should match what you see in a browser.
  4. Check indexing controls: no noindex tag, no X-Robots-Tag, a canonical pointing to the page itself, and no robots.txt block.
  5. Check internal links. Find the article from the homepage, a category or the sitemap.
  6. Confirm it gets indexed. Check at day 7, 14 and 30.
  7. Ask who the editor is. Send a short email to the site’s public contact address if in doubt.

Marketplaces with escrow reduce one part of this risk, because payment is released after the link is checked. They do not replace your own checks. The link marketplaces comparison records what each platform states about monitoring. For ongoing checks, see how to track backlinks.

If you find one in your profile

A hacked link you or a vendor bought. Stop using that vendor. Review every link the vendor placed. Get legal advice. Do not try to keep the link. If a manual action follows, the links belong in your removal and disavow work.

A cloaked placement. Treat it as non-delivery. Hold or reclaim payment, ask for a correct placement, and record a strike against the seller.

Hacked links you did not buy. Competitors sometimes point junk at a site, and attackers’ pages link widely. Google says it mostly ignores such links. Negative SEO and link attacks explains when to act.

If your own site is the victim

Site owners should watch for outbound links they did not add and for pages they did not create. Search Console reports security issues, and a site: search for your domain with terms such as casino will often show injected pages. Keep the content management system, themes and plugins updated, and never install pirated copies.

Where to go next

Cheap niche edits are the product most often used to resell injected links, so read that page before buying any. Terms such as cloaking, hacked content and orphan page are defined in the glossary.

Common questions

What is a hacked link?

It is a link or page placed on a website by someone who broke into it, without the owner's knowledge. Google classes it as hacked content spam, and the break-in is a crime.

What is a cloaked link?

It is a link shown to search engines but not to visitors, or the reverse. In link selling, it often means the buyer is shown a link that Google never sees.

How can I tell if a link I bought is on a hacked site?

Warning signs are a link hidden from normal visitors, a commercial anchor on a school, church or municipal site, a seller who cannot change the surrounding text, and no editorial contact at the site.

Is it illegal to buy hacked links?

The hacking is a criminal offence almost everywhere. Buying the result can expose you to claims as an accomplice and to civil action by the site owner. Take legal advice if you find you have bought one.

Do hacked links work?

They can lift rankings for a short time, which is why criminals use them. They disappear when the site is cleaned, in one documented case after 49 days, and they fall under Google's hacked content policy.

Vendors to look at

  • BazoomEditor's pick

    Sponsored content and link marketplace, managed service

  • MotherlinkEditor's pick

    Backlink services, guest posts, niche edits, full SEO