PROTOTYPE Poland pilot. Figures come from the full scan of 08–09.09.2026, CVE counts from NVD read on 28.09.2026. Fields in [brackets] are not filled yet.
HackedIndex Check your site
Poland pilot · full scan of 08–09.09.2026

923 hacked websites quietly serving spam to Google, mostly casino and betting

More software holes are published every year, and AI makes them faster to find and to exploit. We scan every site, match it to the holes attackers use today and warn the owner first. Free.

Check privately
No account. The result goes only to the verified owner. We never publish any site by name.
1 in 138 sites with Polish traffic is serving hidden spam
2.25× new published vulnerabilities in three years, January to April
9,3052023
15,9802025
20,9622026
NVD, rejected CVEs excluded, 28.09.2026 Vulnerability radar →
208,884spam pages injected into 255 of the sites
9,849spam pages on the worst single site
85%show the spam in their Google results (866 checked)
127,804 domains with Polish traffic, scanned 08–09.09.2026. The scanner flagged 1,113. We count only the 923 with a hard signal or a second proof. Left out: 120 whose only trace was sitemap addresses that may be ordinary content, 46 with bot-only content and no trace in Google, 13 where the flagged content is their own business and 11 other unclear cases. Treat 923 as a floor: a mass scan misses some infections a single-site check finds.

Infected sites over time

Sites with injected spam, Poland, one point per scan.
Measured The line starts with the second full pass
1,200 800 400 0 30.06 31.07 31.08 27.09 No earlier passes. Daily change appears from the second one. 923 · 09.09.2026 · first full pass
ACTIVE OUTBREAK since 27.08.2026
WPMU DEV Dashboard below 5.0.2
CVE-2026-76581 · CVSS 9.8
SSO authentication bypass
24.08Patch 5.0.2 released
27.08First exploit attempts
29.08First infected site observed
04.09Hidden casino block on a site we monitor
Infected index sites with a WPMU DEV Pro plugin 3
Read the outbreak report
Anatomy of 923 confirmed hacks

How the spam hides, what it sells, who it hits

A site can show several techniques and spam types, so the bars do not add up to 100%.

Technique

How the injected content stays hidden
Hidden block in the page HTML637 69%
Links out to gambling domains217 24%
Spam pages in the sitemap193 21%
Cloaking: another page for Googlebot129 14%
Links to a known spam network21 2%
Content shown only to bots12 1%

What it sells

Keyword match in the evidence we saved
Online casino782 85%
Sports betting, Turkish “bahis”118 13%
Indonesian “slot gacor”50 5%
Pharma: opioids, ED pills22 2%
Loans and crypto18 2%
No keyword matched79 9%

Who it hits

923 confirmed sites
Companies and shops783 85%
Public institutions, parishes, schools88 9%
News portals and media52 6%
877of the 923 confirmed are on a .pl domain
46confirmed foreign sites with Polish visitors
The second infection

Cleaning the site doesn't clean Google

19 days after we first saw them, at least 68% of the confirmed sites were still infected. Removing the code is only half the job: Google keeps injected URLs in its results until it crawls them again.

01Remove the injected code and the backdoor that put it there.
02Update or remove the plugin that let the attacker in.
03Make Google forget it: resubmit the sitemap and remove the spam URLs in Search Console.
Site still infected after 19 days≥68%
Lower bound. Re-scan of all 923 on 28.09.2026. 9 did not answer and count as clean.
Public institutions still infected after 19 days≥62%
55 of the 88 confirmed schools, offices and parishes.
We track both axes for every site, and a site leaves the index only when both are clean.
What infected WordPress sites run

WordPress on 747 of 923 confirmed sites

Of the 581 that show a version, 52% already ran WordPress 7.x. An up-to-date core does not help when a plugin has the hole.

Plugin present on infected site Sites Share of 747
contact-form-7273
37%
elementor205
27%
woocommerce155
21%
elementor-pro116
16%
revslider95
13%
js_composer74
10%
Presence is not cause: these plugins are popular everywhere. Next step is matching plugin versions against clean sites. PrestaShop, Joomla and Magento fingerprints are in development, so 176 sites have no CMS named yet.
Link targets

Where the injected links point

ultraiz.co25 sites
vavadapoland.pl10 sites
energy-casino.hu9 sites
lotto-kasyno.pl7 sites
monopoly-live-casino.de7 sites
betzoid.com6 sites
A link target is not proof of who did the hacking. Lower bound: we keep up to three links per site as evidence.
Spam networks we fingerprint
betzoid casizoid betzella kasinique kasinord winstwijzer scommezoid
Responsible disclosure
88
sites of public institutions, schools and parishes are infected.

We never publish which sites are hacked: not companies, not public bodies, not people. Every case goes privately to the site, CERT Polska and the host. What we publish is how many.

Day 0Private notice to the site, CERT Polska and the host
Day 7Reminder with a free re-check
Day 30Still infected: we update CERT Polska and the host. Nothing is published.
Any dayClean on re-check: case closed within 24 h
Public counters · updated after each full pass
[n]cases reported to CERT Polska
[n]sites cleaned after our notice
[n]cases still open after 30 days
Methodology

How the index is built

5 requests

What we ask each site for

The home page twice: with Google’s crawler user-agent plus our name and contact, and as a normal browser. Then the sitemap and two site-search probes. Plain GET requests only: no logins, no exploits, no forms.

Full pass weekly · known infections daily · opt out any time
0 of 90

How we avoid false alarms

No false alarm on 90 sites we know are clean. Each flagged site counts only with a hard signal (hidden spam block, cloaking, a known spam network) or a second source such as Google results. 190 without one are not counted. On search probes only hard evidence counts.

Found wrongly? Report a false positive
Feeds & API

For hosts, CERTs and researchers

Hosts see the infected sites on their own network, CERTs get the full feed, researchers get aggregated data only. So you can help your customers first. Free for CERTs and non-profits.

Request data access
Who runs HackedIndex

Mateusz Haber, as a side project

HackedIndex is my side project, built after hours for a good cause. I want the owner of a hacked site to hear it from someone friendly before their customers see it. HackedIndex watches and warns. It does not clean sites, sell cleanup or take referral fees. Monitoring fees cover the cost of daily scanning, and money never changes what we count or report.

Data controller: Mateusz Haber · [address] · [email]