NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Documented incidents

Eleven documented negative SEO incidents, and what each one proves

Every incident here is public and attributed, because a case study you can check is worth more than one you cannot.

Why there is no client story on this page

A page called "case study" normally opens with an anonymized client: a manufacturer somewhere, a spike of toxic links, a heroic cleanup, a chart with the axis labels removed. I am not going to write that, and the reason is not modesty.

This site names no clients and publishes no testimonials, so a client story here would arrive stripped of every detail that would let you verify it - and an anecdote nobody can check is worth strictly less than an incident anyone can. Every case below is public: a published experiment with a disclosed method, a contemporaneous victim account, a federal complaint, or an incident covered by the trade press with dates and names attached. Where a victim is named, they named themselves. Where a number appears, it comes from the source attributed alongside it. If you want to check any of this, you can, and you should. That is also why this page looks different from every case-study page you have read.

2012: an experiment that worked, against a site with nothing underneath

What was done. The SEO agency TastyPlacement, in a write-up by Michael David published on 7 June 2012 - six weeks after Penguin 1.0 launched on 24 April 2012 - pointed roughly 56,000 links at one of its own internal test sites, an exact-match-domain microsite that ranked on the strength of its domain name. Most were blog comment and forum profile links carrying commercial anchor text.

Measured effect. The primary term first rose from third to second. Then, in the authors' words, by the next day the site was "off the front page and essentially invisible." Of 51 tracked secondary keywords, 26 fell significantly, by an average of about nine positions; 21 were unchanged and 5 improved slightly (TastyPlacement, 7 June 2012).

What fixed it. Nothing. The site was disposable and the experiment ended there.

What it proves and does not. That the mechanism existed in 2012: in the Penguin 1.0 era, inbound spam could demote a target. It does not show the mechanism exists now, and it is not a picture of an ordinary business site. The victim was a thin microsite whose whole ranking rested on its domain name and a small link profile - discredit that profile and nothing was left to score. It is the most-cited case in this field, almost always cited with that fact removed. Note the slant too: an alarming result served the agency publishing it.

2012-2013: the same attack, an established site, and nothing happened

What was done. Nick Ker of KerCommunications documented an attack on his own business site as it happened, from October 2012 to May 2013: escalating waves of comment spam, pingbacks, spun articles, scraped copies of his content, and bookmark and wiki links, aimed at his commercial terms. Volume rose from 30 to 40 links a day to 1,000 a day.

Measured effect. None. His recorded outcome, after thousands of spam links: "No 'unnatural links' warning in Webmaster Tools, rankings are nearly the same as they were back in February, traffic has also grown at around the same rate" (KerCommunications, 30 July 2013, updated 16 May 2019). He did not disavow into it and did not suffer for that.

What it proves. Read against the case above, the comparison is the finding, and it is the most useful pair of facts on this page. Same era, same class of attack, opposite outcomes - and the variable was not the attack, it was the target. This account carries the opposite slant to the last one: a reassuring result served an agency selling ordinary SEO. Two commercial interests pointing opposite ways, together saying something neither intended.

2012: a hijack that worked, and then Google penalized the attacker

What was done. Dan Petrovic of Dejan Marketing, publishing on 6 November 2012, copied the HTML of four live third-party pages - one of them Rand Fishkin's - onto subdomains of his own domain and pushed internal PageRank at the copies, testing whether a stronger host could displace an original.

Measured effect. It worked. For the query "Rand Fishkin," a days-old test page took the top result across Australia, the United States, the United Kingdom and Poland. Petrovic concluded that Google "takes rel=canonical as a hint and not an absolute directive." A canonical tag on the original "seemed to prevent it from hijacking the result fully but not in all cases" - partial protection, not immunity.

What fixed it, and this is the part usually cut when the experiment is cited. Google detected it and acted against the attacker: a manual search-quality notification for copied content was issued to the attacking domain and the hijacking pages were removed from the index. Documented at dejanmarketing.com and covered by Barry Schwartz at Search Engine Land.

What it proves. That the mechanism was real in 2012, that it required a marked authority advantage over the target, and that Google's enforcement both reversed it and punished the party running it. No comparably rigorous, method-disclosed replication succeeding against an established site has been published since - a meaningful absence after fourteen years. See plagiarism outranking.

2014: the one link attack that did produce a manual action

What was done. Writing on 17 November 2014, Eliav Lankri described roughly 600,000 spam links pointed at a jewelry e-commerce site across multiple content platforms, spread over a period rather than delivered in one spike. The site is not named, which is a real limitation of the account.

Measured effect and fix. A penalty confirmed in Webmaster Tools - a manual action, which is what the 2012 to 2014 threat model was actually about. It took link-removal outreach and disavow submissions in successive rounds before the action was revoked. Most visibility returned; some terms settled lower than before. That last detail is the honest one: recovery from this era was real but not always complete.

What it proves and does not. It is the clearest available picture of the 2014 threat model from inside. It is a practitioner blog post rather than a controlled test, and it predates Penguin 4.0 by nearly two years - the mechanism it describes, site-level demotion for inbound links, is exactly what Google said in September 2016 it had stopped doing. Anyone citing this case to sell you a link cleanup today is citing a machine that was retired. What remains current is the process, in the guide to manual actions and reconsideration requests.

From 2016 on, the damage moved to processes: forged copyright notices

Everything above is historical. Everything below is not, and the pattern changes: from 2016 onward, every incident with real measured damage worked by abusing a process rather than a ranking signal.

Google went to federal court over it. In Google LLC v. Nguyen, No. 5:23-cv-05824 (N.D. Cal., filed November 2023), Google alleged that two individuals created at least 65 accounts to file fraudulent copyright takedown notices against more than 117,000 third-party URLs, to remove competing sellers from Search. The complaint alleged they "have weaponized copyright law's notice-and-takedown process and used it not for its intended purpose of expeditiously removing infringing content, but instead to have the legitimate content of their competitors removed based on false allegations." Techdirt and Bloomberg Law reported it as resolved in Google's favor in 2024. Note what the attack did not involve: no links, no ranking manipulation, no algorithm. It abused a legal process, which has no algorithmic immune system in front of it.

And it is current. In March 2026 a Search Engine Land article was removed from Google Search globally after a copyright complaint filed on 27 March alleging it "copied our entire content word for word" and used "proprietary images." The article contained no images at all and no duplication was found; it was reinstated on 31 March (Danny Goodwin, Search Engine Land, 30 March 2026). Three months later Press Gazette reported one of its own articles on the same subject delisted on a notice whose cited original was a month-old Reddit post about online casinos; it was reinstated on 2 July 2026 (Dominic Ponsford, Press Gazette, 30 June 2026).

That pair is the most probative thing here for an ordinary business, precisely because the victims were not ordinary. Two publications with named contacts inside Google were still delisted, and still took days to get back; a small business with no such contacts should assume longer. Google's documentation concedes the two facts that make it viable: it cannot always notify a site owner before content is removed, and it is not always able to verify a request's accuracy. See fake DMCA takedowns.

Listings and reviews: the attacks that need no technical skill

A trading restaurant marked permanently closed. The Register reported on 3 March 2017 that Arrosto, a rotisserie chicken restaurant whose owner Kaie Wellman went on the record, was marked permanently closed on Google Maps and in mobile search while trading normally. The trigger was an ordinary suggested edit, the mechanism open to any signed-in stranger. Google's reported position at the time was that "this feature is working as intended and we [do] not foresee it being removed." The listing was corrected by publication; the report does not establish what prompted the fix, or who submitted the suggestion.

What has changed, and the page has to say it. Google states that from April 2026 verified business owners receive proactive email alerts about suggested edits before those edits go live. If that works as described, exposure for a claimed, verified, monitored profile is far lower than in 2017, and essentially all remaining risk sits with the unclaimed profile - which makes claiming and verifying the listing the highest-value action this page can send a reader away with. See fake business closure.

The industrial version, and both edges of it. Google has sued named operators over listing fraud twice on the public record: a June 2023 action concerning roughly 350 fraudulent Business Profiles and more than 14,000 fake reviews, and a March 2025 action over more than 10,000 alleged illegitimate listings concentrated in locksmith and towing categories, covered by CBS News. Google also reports removing 292 million policy-violating reviews in 2025. Those figures cut both ways and both edges belong here: the behavior is industrial, and Google catches an enormous amount of it automatically, which is why an established profile usually survives a burst of fabricated one-star reviews with its rating intact. All of those numbers are Google's own, self-reported and unaudited.

What actually reversed one. The agency 39 Celsius published an account from September 2019 of a business whose eight-year-old profile was suspended for over 30 days after repeated false spam reports and unauthorized edits, with a reported loss of about 84 percent of impressions and clicks. What ended it was a Doe lawsuit and a subpoena to Google, not a support ticket. That account is single-source with no case name or docket and the 84 percent figure is unverified: cite it for the mechanism, which is ordinary and effective, not for the number.

Extortion: prosecuted, sentenced, and then retaliation

The most serious case here involved no ranking manipulation at all. In United States v. William Laurence Stanley (N.D. Tex.), the Justice Department's release describes the defendant as a self-described "black hat search engine optimizer." A federal grand jury indicted him and his sister on extortion and interstate-threat counts on 27 March 2014; he had extorted victims by threatening to publish fraudulent negative comments and build damaging websites about them. Court records show the principal victim firm had paid $80,000 to end the relationship before sending four further payments totaling $29,556 abroad. He pleaded guilty to one extortion count on 22 December 2015, with a government estimate of 40 to 45 victims and losses over $230,000, and was sentenced on 5 January 2016 to 37 months in federal prison and $174,888 in restitution.

Then the part that matters most to anyone deciding whether to report an attack. While on home confinement in late 2016 he retaliated against the company that had reported him to the FBI, posting derogatory content across multiple platforms and complaint boards and encouraging others to duplicate it. He was indicted for witness retaliation on 7 December 2016 and convicted by a federal jury on 19 April 2017. All of it is documented in successive Justice Department press releases.

What it proves. Three things a victim needs: that this conduct is prosecuted and the sentences are real; that retaliation against a reporting victim is a documented risk and is itself a separate federal felony, which is what someone weighing a call to the FBI needs to know in both directions; and that the harm had nothing to do with rankings - it was money extracted under duress and defamatory content published about a named firm.

The contrast, from the same year. In 2014 near-identical extortion emails circulated in volume, demanding payment by wire transfer, threatening tens of thousands of forum-profile backlinks and claiming permanent removal from Google within 24 to 48 hours. Google's response, reported by Search Engine Land, was that its "algorithms are designed to prevent these kinds of activities from causing problems for webmasters" and that it was "unclear how credible this threat really is." No public case has since shown that a target who refused to pay suffered a ranking loss attributable to the threatened links - the cleanest illustration here of the gap between the threat sold and the threat delivered. See negative SEO extortion.

One case I am party to, and it is unresolved

The eleventh case is my own published work, and it belongs here because the disagreement is the value.

On 20 April 2018, investigating a sudden ranking loss, I found that a spam site had copied a victim page's entire head section, canonical tag included, so that the spam page declared the victim's URL as its canonical; it was traceable only because the spam site linked out to other domains. Google's John Mueller replied publicly within days: "the rel canonical has been around for over a decade, people have tried lots of things with it," and "the premise that rel canonical combines pages is wrong. That's not how it works, it's either one or the other" - reported by Roger Montti at Search Engine Journal on 20 April 2018, which also noted the exploit "has been documented but never tested or verified experimentally." Barry Schwartz at Search Engine Roundtable covered it skeptically, writing that the tactic "is not actually novel."

What it proves: nothing, on its own, and that is why it is on the page. I observed a correlation; Google's spokesperson denied the mechanism; neither side ran a controlled test, and the disagreement was never resolved. Mueller's "either one or the other" is a real rebuttal - in Google's account canonicalization selects a URL from a cluster rather than merging two pages' properties, so there is no channel for a spam page's characteristics to reach the victim's URL. Google did not confirm the finding and no source says Google fixed anything; I would rather print that than let a stronger claim circulate under my name. A reference that prints only the cases agreeing with it is a brochure. What is operationally useful from that work is the Search Console string a defender should look for - "Duplicate, submitted URL not selected as canonical" - covered on canonical hijacking.

What the eleven show when read together

Six observations, each supported above rather than asserted.

  1. Every documented link attack that moved rankings is from 2012 to 2014, before Penguin 4.0 on 23 September 2016 moved Google from demotion to devaluation.
  2. The one well-documented link attack on an established site failed completely - a thousand links a day for months, no warning, no loss.
  3. Where a link attack did produce a penalty, the penalty was a manual action, and remediation took successive rounds of removal and disavow. That is the 2014 threat model, not the current one.
  4. Every incident from 2016 onward with real measured damage abused a process, not an algorithm: forged copyright notices, suggested edits and closure flags, fabricated profiles and reviews, extortion.
  5. Google acts against the attacker about as often as it acts at all - a manual action against the hijacker in 2012, federal complaints in 2023 and 2025.
  6. The remedies that worked were platform and legal remedies, not SEO remedies: a counter notification, a Doe suit and a subpoena, a federal complaint, claiming and monitoring a listing. In none of the eleven did a disavow file resolve a post-2016 incident.

That is the same conclusion the cornerstone page reaches from the documentation rather than the incident record, arrived at independently. If you came here to learn whether the thing you are afraid of is real, the record's answer is that the version sold to you mostly is not, and the version nobody sells you protection against mostly is. What to do about it is on the recovery page.

Frequently asked questions

Why are there no client case studies on this page?

Because this site names no clients, an engagement story here would arrive with every verifiable detail removed, and an unverifiable anecdote is worth less than a documented incident. Every case above has a named party, a date and a source you can go and read.

Has anyone ever proved negative SEO works?

Against a thin site in 2012, yes, with a disclosed method. Against an established site with an ordinary link profile, no post-2016 case with a measured ranking loss attributable to inbound spam links has been located across this and prior research passes. That is an absence of evidence found rather than proof none exists - but the absence has now lasted a decade.

Does a lawsuit prove an attack worked?

No. A complaint is a set of allegations, and the litigation here establishes that attackers get identified, named on a public docket and sued - not that any attack moved anyone's rankings. The cases where damage was actually measured are the process-abuse ones: delisted URLs, a suspended listing, a closure flag.

Should any of this make me file a disavow file?

No. Not one of the post-2016 incidents here was resolved by a disavow file, and the 2012 to 2014 cases where links did damage describe a demotion mechanism Google said it stopped applying in September 2016. Google's own criteria for the tool require a manual action or the realistic prospect of one.

How current is this page?

The most recent incidents are from 2026 - two delistings of trade-press articles on forged copyright complaints, and Google's stated April 2026 change giving verified owners advance notice of suggested edits. The oldest are from 2012 and are labeled historical, because on this subject a fact stated in the present tense without its date is usually a wrong fact.

Top