One person, and what that changes
This is a practice of one. No account manager, no junior running an audit tool overnight, no team behind the word I. Weigh that in both directions: the person who reads your Search Console is the person who writes the remediation plan and answers when it does not go to plan, and there is a hard ceiling on how many matters can be open at once. If you need a vendor who can put five people on a site next Monday, this is not that.
I sell negative SEO recovery work. I do not run attacks, broker them, or advise anyone on running them, and that is not a disclaimer at the bottom of a page - it is the reason this domain answers the search for hiring an attacker with a flat refusal rather than a quote. I have been working in search since 1996, which on this subject mostly means having watched inbound link attacks be genuinely dangerous, stop being dangerous, and go on being sold at the old price.
Every engagement starts with a diagnosis, and the diagnosis can end it
The first piece of work is always the same and deliberately small: determine whether a hostile act occurred, date it, and establish which surface it touched. It is bounded rather than an open-ended retainer, and it is the only part I will start without knowing the answer. It produces a finding, in one of four shapes:
- Nothing was done to you. The drop is algorithmic, technical or competitive. This is the commonest finding, and when it is the finding the engagement ends there with a written explanation of the evidence. There is no cleanup to sell, and selling one anyway is the defining behavior of this industry's worst end.
- Your site is compromised. Injected content, cloaked pages, redirects firing only for Googlebot, outbound spam links you did not put there.
- An index entry was taken. A copied or proxied page claiming your URL as its canonical, a redirect hijack, or URLs removed outright by a fraudulent legal notice.
- A platform record about your business was attacked. A profile edited, suspended or flagged closed; a wave of fabricated reviews; citation data corrupted across directories.
Those four lead to genuinely different work. Treating them as one service called "negative SEO cleanup" is why so much money in this field buys nothing: three of the four are not link problems, and the remedy for none of them is a disavow file.
A link engagement, and why it is usually the smallest one
Where the finding is genuinely about inbound links, the work is: a dated export of referring domains and anchor text preserved as evidence; an assessment of whether Google's own two-part test for the disavow tool is met; targeted removal requests only where a real publisher with a monitored inbox is on the other end; and, if warranted, a hand-built disavow file that is reviewable line by line with a reason recorded against each entry.
What that engagement will not include is a tool-generated list of a thousand domains disavowed on a proprietary toxicity score. Google's documentation calls the disavow tool "an advanced feature" that "can potentially harm your site's performance in Google Search results" if used incorrectly, says most sites will never need it, and heads the instructions "Step 0: Decide if this is necessary" (Google, Disavow links to your site). A file built to a vendor threshold fails Google's stated criteria on its face and throws away legitimate links in the process.
The consequence for my own revenue: link engagements are the shortest and cheapest work on this list, and a large share of the sites that arrive convinced they need one need none of it. The recovery page sets out that triage so you can run most of it before contacting anyone.
A compromise recovery is a different job entirely
This is the category where the damage is unambiguously real, and it shares nothing with a link cleanup - different evidence, different tools, different failure mode, different cost.
The work runs: find the entry point and close it before touching anything cosmetic; rotate credentials and remove unknown administrative accounts; identify every affected file and page rather than the sample that surfaced first; remove injected content and any cloaking or conditional redirect logic; verify from a crawler's perspective rather than a browser's, because the payload is usually served only to Googlebot; then request the review with evidence a reviewer can check quickly.
The reason this costs more is structural. A link file is one artifact; a compromise is an unknown number of files across an unknown number of installations, and the scope is not known until the examination is done. It also has an unforgiving failure mode: a review does not begin until the site is actually clean, and Google's guidance after a denial is to "reassess your site for malware or spam, or for any modifications or new files created by the hacker" (web.dev, Request a review). A partial clean produces a failed review, and a failed review costs the entire cycle again. Repeated failed reviews - not the hack - are the largest driver of long recoveries. Hardening afterward is covered in the guide to hardening WordPress against attacks.
Process and platform attacks, which are not SEO problems at all
The attacks that still reliably cause measured damage abuse a process rather than a ranking signal: a forged copyright complaint that removes URLs from search, a suggested edit that marks a trading business permanently closed, a coordinated wave of fabricated reviews, false spam reports against a listing.
The work here is documentary and procedural. It means capturing the notice or the change with timestamps before it is amended, filing the counter notification or the redressal complaint correctly the first time, escalating through the channel the platform actually reads, and keeping a record clean enough to hand to counsel if the same actor comes back. None of it involves a backlink tool, and an SEO retainer that includes "reputation monitoring" will not do any of it. See fake DMCA takedowns and Business Profile hijacking.
Expert witness and forensic work
Some of this work is not a recovery at all. I have served as an expert witness in matters involving search, links and online reputation, and have testified in United States Federal District Court and in the Grand Court of the Cayman Islands. That work is retained by counsel rather than by a site owner: examination of the record, reconstruction of what happened and when, written opinion in a form that survives cross-examination, and testimony.
The overlap matters to a business owner. Evidence here decays fast - backlink indexes rewrite themselves, spam pages come down, platform records are amended silently, and a screenshot with no timestamp is evidence of nothing. The habits that make a case defensible make a remediation defensible, which is why the first phase of every engagement is preservation rather than action. Method in the guide to preserving evidence.
One thing stated plainly, because it appears on consultants' pages in forms that do not survive checking: I have judged the US Search Awards and the Global Search Awards. Judging is not winning, and nobody should hire me on the strength of either.
What determines cost
No figures appear on this site, and that is a decision rather than an omission: a published rate for work whose scope is unknown until the examination is finished is either a floor nobody honors or a ceiling nobody can hold to. What drives cost is structural, and you can place a matter on each of these before speaking to anyone.
- Which of the four findings it is. A link matter is bounded. A compromise is not bounded until the examination is done. That single distinction accounts for most of the range.
- How much of the property is involved. One site on one stack, or a dozen properties, several installations, multiple hosts and a content delivery layer in front of them.
- Whether the evidence still exists. A matter brought in week one is cheaper than the same matter in month eight, because by then the record has to be reconstructed from whatever survived, and some of it has not.
- Whether the fix requires access you control. Where the damage lives on somebody else's server or inside a platform's records, the work is filings and escalation on someone else's timetable rather than changes I can make and verify.
- How many review cycles the remediation needs. A manual action or a security flag adds a wait with a real chance of rejection, and a rejection means the cycle repeats.
- Whether the output must withstand challenge. Work that may end up in front of counsel, an insurer or a court is documented to a different standard, and that standard costs time.
- Whether anyone must be coordinated. A host, a registrar, a developer, a platform's support path or opposing counsel each add elapsed time that is not analysis time.
What is not offered, in plain terms
The absent items are as informative as the present ones.
- No attacks, ever. Not against a competitor, not as retaliation, not as a test. This domain answers roughly the same search terms an attacker-for-hire would, and it answers them with a refusal.
- No guaranteed rankings, traffic or revenue. Recovery cannot be guaranteed by anyone. A revoked manual action restores eligibility, not position, and Google publishes no timeline for rankings returning and no statement that they will. A proposal that promises otherwise is describing something that does not exist.
- No open-ended monitoring retainer. Where monitoring is genuinely useful - dated evidence collected before you need it - it is small and defined, and I will say when it has stopped earning its keep. A monthly invoice for a list of links Google already discards is retainer padding.
- No toxicity scores. No search engine publishes such a metric and no vendor's is calibrated against Google's behavior, so a report built on one is an opinion formatted as evidence.
- No expedited review channel. There is no queue-jumping arrangement with Google, and anybody describing one is describing a fiction.
- No named clients, logos or testimonials. A recovery engagement is usually the worst month of a business's year, and I do not publish who has had one. It is also why the case-study page is built entirely from publicly documented incidents you can check rather than anonymized stories you cannot.
What an engagement produces
Every engagement produces files rather than a dashboard login, because files are what remains useful after it ends and what an attorney or a successor can read without me.
- A dated evidence set: exports, captures and reports preserved in the state they were in when the matter opened.
- A written finding: what happened, when, what it touched, and what remains uncertain, with the uncertainty labeled rather than smoothed over.
- A remediation plan in the order the work must be done, marking what only you can do and what needs a third party.
- Where reviews or filings are involved, the drafted request or notice, plus the supporting record a reviewer can verify quickly.
- A short recurrence section: the entry point that was closed, the monitoring worth keeping, and the monitoring that is not.
Where to start depends on where you are. If the drop is recent and undiagnosed, read how a recovery proceeds. If you are not yet sure anything happened, read telling an attack from an algorithm update. Both are written so you can reach the answer without hiring anyone, and a fair number of readers do.
Every engagement starts the same way: you describe what changed and when, I tell you whether the evidence points at an attack, and we decide from there whether there is work worth doing. That first exchange costs nothing and it ends with a straight answer, which is sometimes that nothing was done to you and you should keep your money. If that is the conversation you want, get in touch.
Frequently asked questions
Will you take the work if you find nothing was done to my site?
No. If the diagnosis says the movement was algorithmic, technical or competitive, that is the deliverable and the engagement ends there with the evidence written up. Selling a cleanup against a problem that does not exist is the single most common thing that happens to businesses in this situation, and I would rather lose the work than be the one doing it.
Why are there no prices on this site?
Because scope is not knowable before the examination in the categories that matter. A compromise recovery is bounded by how much of the site is affected, which nobody knows on day one. A published rate would be a number I would have to walk back on half of matters and that would quietly go stale on the rest.
Can you guarantee my rankings come back?
No, and neither can anyone else. Google publishes review windows for manual actions and security issues; it publishes nothing about whether or when rankings return, and a revoked action restores eligibility rather than position. Treat any promise to the contrary as the clearest available signal about the person making it.
Would you work against a competitor's site?
No, under any framing, including as a test, a demonstration or a retaliation. Where a competitor's own conduct violates a platform's policies, the documented route is reporting it through the platform's own channels with evidence, which is covered in the guide to reporting negative SEO to Google.
What do you need from me to start?
Verified Search Console access or, failing that, exports from it: the Manual actions and Security Issues reports, and a Performance export at day granularity spanning the drop. Where links are suspected, a referring-domain export with first-seen dates. Almost everything in the first phase comes from those, and they are also what an attorney would want if the matter goes that way.