AdSense Disabled Because Your Site Was Hacked

By · Updated · 4 min read

The revenue stopped overnight and the notice in your account talks about malicious or unwanted software, or a policy violation you do not recognize. If your site has been compromised, those two facts are connected, and the sequence for fixing it matters — trying to restore the account before the site is genuinely clean is the most common way people turn a two-week problem into a two-month one.

Why a hack triggers this

AdSense has to protect advertisers, and advertisers do not want their brands appearing on pages that redirect people to scams or serve malware. When Google's systems detect malicious behaviour on a site running ads, the response is to stop serving there, and depending on severity that can be a page-level restriction, a site-level one, or an account-level action.

The triggers after a compromise are the usual suspects: injected scripts redirecting visitors, fake update prompts, spam pages carrying your ad code, and links to malicious destinations. Note that spam pages are a particular problem here — injected pages inherit your site-wide ad code, which means your account is monetizing content that violates policy in several ways at once.

Read the notice precisely

The policy centre in your AdSense account tells you what was detected and at what scope, and those details determine everything you do next. A page-level enforcement affecting a handful of URLs is a very different situation from a site-level restriction, which is different again from account-level action.

Cross-reference with Search Console, because the same underlying problem usually appears there too, with better technical detail. The Security Issues report will often name the detection type and give you sample URLs, which is exactly what you need for the cleanup. My guide on Search Console security issues covers reading that report.

Clean the site first, completely

Do not request a review before the site is genuinely clean, for the same reason you would not with a reconsideration request: a failed review costs more time than being thorough would have. Work through the full cleanup — replace core, plugins and theme from clean sources; remove injected scripts from files and database; delete spam pages so they return proper 404s; remove rogue administrator accounts; find the persistence; rotate credentials; close the entry point.

Pay particular attention to removing spam pages, since those carry your ad code and are usually what the enforcement is actually about. And verify from outside with URL inspection rather than trusting what you see logged in, because conditional injections are invisible to administrators by design.

Requesting the review

Once you are confident, request a review from the policy centre. Some enforcements clear automatically when the violating content is gone and the site is re-crawled; others need the explicit request. Where there is a field for context, use it the way you would a reconsideration request — state what happened, what you removed, and what you changed so it will not recur.

Reviews typically take a few days to a couple of weeks. Do not submit repeatedly, and do not make large structural changes to the site while a review is pending, since that just makes it harder for everyone to evaluate what they are looking at.

About the money

Expect the revenue gap to persist through the review, and be realistic that clicks and impressions generated by traffic arriving at spam pages are unlikely to be paid out. That is uncomfortable but it is consistent — those impressions were not legitimate inventory, whoever created them.

If the action was account-level rather than site-level, the stakes are higher and the process is slower. The most useful thing you can do is make the first review count, which means a complete cleanup and a specific, factual account of it rather than an assurance that things look fine now.

Getting back to normal

Once serving resumes, watch for a few weeks. A repeat enforcement after reinstatement is much harder to recover from than the first one, and the usual cause is an incomplete cleanup that let the injection return — which is the subject of my guide on reinfection loops.

Your other Google properties are probably affected too, so work through them together: Google Ads disapprovals, Search Console security issues, and any manual action. If the revenue matters and you want the cleanup done right the first time, that is what my malware removal service is for.

Common questions

Why was my AdSense account restricted when I did nothing wrong?

Because enforcement is based on what the site is doing, not on who did it. Injected redirects, malware and spam pages violate policy regardless of whether you put them there. Being a victim explains the situation but does not change the enforcement — cleaning the site does.

Will I get paid for the period the spam pages were running?

Usually not for the impressions and clicks those pages generated, since that was not legitimate inventory. Earnings from your genuine content during the same period are normally unaffected. The details depend on the enforcement type and what your account shows.

How long does a review take?

Commonly a few days to a couple of weeks. Some page-level and site-level enforcements clear automatically once the violating content is gone and the site has been re-crawled, without any explicit request. Account-level actions take longer and deserve more care in the submission.

Should I remove my ad code while I clean up?

It is not required, and leaving it in place means serving can resume automatically once things clear. What matters far more is removing the spam pages that were carrying the code, since those are usually the actual subject of the enforcement.

Can this happen again after I am reinstated?

Yes, and a second enforcement is considerably harder to recover from. The overwhelming cause is an incomplete first cleanup that allowed the injection to return. Verifying the site is genuinely clean, and monitoring it for a few weeks afterwards, is what prevents the repeat.