TEMPLATES Brackets are filled per site. Sites outside Poland get these in English, Polish sites get the Polish version.
HackedIndex / notices and messages
See pricing
What we send

Every warning is free. No warning sells anything.

Cold notices carry no offer, no price and no link to click. Offers go only to verified owners who asked for them. Public institutions and non-profits get Monitoring free.

DAY 0 · FREEBreak-in noticeEvidence and a code for the private report
DAY 7 · FREEReminderFree re-check and a free cleanup guide
CLEAN · OPT-IN ONLYCase closedMonitoring offered only if you asked for offers
ANY DAY · FREEEmergency noticeA hole exploited now likely hits your version
DAILY · PAID OR NON-PROFITMonitoring alertsBreak-ins and new holes in your plugins
FREE Day 0 · our scan finds a break-in
FromHackedIndex <[notice address]>
To[contact listed on the site]
RefHI-7Q4K-2M9P

example.com is showing casino spam to Google

Hello,

Our scanner found pages on example.com that you most likely didn't write: [n] casino and betting pages listed in your sitemap, and a block of links on the home page that only Google sees.

These pages were almost certainly added by someone else. Visitors don't see them, which is why they often stay for months. If you added them on purpose, reply and we will close the case.

Confirm it without clicking anything in this email: search Google for site:example.com casino, or open example.com/sitemap.xml yourself.

No links in this email. For the evidence and a step-by-step fix, type hackedindex.com into your browser and enter this code.HI-7Q4K-2M9P
This notice and the report are free. We will never ask you for a password, a payment or a plugin install.
One notice per case, re-check in 7 days. To stop scanning: TXT record hackedindex-optout. Sent by Mateusz Haber, HackedIndex, [address]. We found this address on example.com/[page] and use it only to tell you about this security problem (GDPR Art. 6(1)(f), network security). Reply STOP and we never write to this address again. Privacy notice: hackedindex.com/privacy
FREE Day 7 · still infected on re-check
FromHackedIndex <[notice address]>
To[same contact]
RefHI-7Q4K-2M9P

Still infected: example.com. The re-check is free.

A week ago we told you about spam on example.com. Today's re-check still finds it: [n] spam pages, [n] of them visible in Google search.

Cleaned it already? Ask for a re-check and we close the case the moment it comes back clean.

Cleaning Google takes longer than cleaning the site, so spam can stay in search results for weeks after the fix.

Still no links. To re-check, type hackedindex.com into your browser and enter the same code.HI-7Q4K-2M9P
Fixing it yourself? The private report includes a free cleanup guide: the injected code, the backdoor, then Google.
Last reminder. After this we write only if something changes. Sent by Mateusz Haber, HackedIndex, [address]. We found this address on example.com/[page] and use it only to tell you about this security problem (GDPR Art. 6(1)(f), network security). Reply STOP and we never write to this address again. Privacy notice: hackedindex.com/privacy
OPT-IN ONLY · FIRST OFFER Clean, to an owner who asked for offers
FromHackedIndex <[notice address]>
To[verified owner]

example.com is clean. Google isn't yet.

Good news: our re-check finds no spam on example.com. The case is closed and the site is off our count of infected sites.

Google still shows [n] of the spam pages. They drop out as Google re-crawls, which can take weeks. We'll look once more in 30 days, free.

Want us to watch every day instead? Monitoring scans daily, tells you within 24 h if anything comes back, and follows Google until the last spam page is gone.

Watch daily from €5 / month
Public institution or non-profit? Monitoring is free for you for as long as HackedIndex runs. How to get it
You get offers because you ticked “send me offers” when you verified example.com. Reply STOP to turn them off. Do nothing and you won't hear from us about this case again.
FREE Any day · likely affected (version-based)
FromHackedIndex <[notice address]>
To[contact listed on the site]
RefHI-3LX8-5T2C

Urgent: the WordPress hole attackers are using now may affect example.com

On 25.09.2026 CISA added CVE-2026-87902 to its list of vulnerabilities attackers are actively using. It lets anyone run code on a WordPress site without logging in.

example.com shows WordPress [version] publicly, which is in the affected range. Judging by the version alone, it is likely affected.

Today: update WordPress to [fixed version] or newer. Then check for free that nobody got in first.

No links in this email. For the free check, type hackedindex.com into your browser and enter this code.HI-3LX8-5T2C
We send this only for holes attackers are using right now, once per hole. It's free and there is nothing to buy.
Based on the version your site shows publicly. Some hosts patch without changing it. If yours did, ignore this. Sent by Mateusz Haber, HackedIndex, [address]. We found this address on example.com/[page] and use it only to tell you about this security problem (GDPR Art. 6(1)(f), network security). Reply STOP and we never write to this address again. Privacy notice: hackedindex.com/privacy
PAID · MONITORING Daily match finds a new hole · email or Slack
HackedIndex alert · shop.example.com

New vulnerability in a module your shop runs

ModuleAdvanced Popup Creator ProblemSQL injection · CVE-2025-69633 Your version[version] Fixed in[version] SourceFriends of Presta advisory

What to do: update the module, or switch it off until you can. We check again tomorrow and tell you when it's closed.

Open report
You get this because shop.example.com is on Monitoring. Alerts go to [email] and [Slack channel].
FREE · NON-PROFIT Status verified
FromHackedIndex <[notice address]>
To[verified owner]

Monitoring for [organisation] is free for as long as HackedIndex runs

We've verified [organisation] (KRS [number]) and example.org. Everything in Monitoring is now on at no cost: daily scans, vulnerability alerts and Google tracking.

No card and no trial. Once a year we'll ask you to confirm your status. Nothing else.

Alerts go to [email]. You can add a colleague or a Slack channel in settings.

Open your dashboard
Know a school, parish or foundation that could use this? Forward this email.
On the site

Lines we repeat everywhere

CHECK PAGEPrivate check · free · no account
PRIVATE REPORTThis report is free and stays free.
EVERY NOTICENo links, and we never ask for a password, a payment or a plugin install.
PRICINGKnowing you've been hacked costs nothing.
INDEX AND FAQNo site is ever named. We publish counts and report cases to CERT Polska.
NON-PROFIT BADGEFree for public institutions and non-profits. No card needed.