Skip to main content
Categories
@ Follow Us
Newsletter Sign Up
Newsletter Sign Up

Google’s September 2026 spam update: is your website hosting spam without knowing?

6th October 2026


Google’s September 2026 spam update began rolling out on 24 September and, at the time of writing, is still in progress. It is expected to complete by around 8 October. Spam updates sound like a problem for shady link schemes, but an honest small business can end up on the wrong side of one simply because its website gets used to host someone else’s spam. Here is what Google has confirmed, what we caught on a site we look after in late September, and a practical checklist to keep your site clean.


What has Google confirmed about the September 2026 spam update?

Google says the September 2026 spam update started on 24 September 2026 at 09:15 Pacific time, applies globally and to all languages, and “may take up to two weeks to complete”. It has not said what the update targets.

The announcement on the Google Search Status Dashboard is short: “Released the September 2026 spam update, which applies globally and to all languages. The rollout may take up to two weeks to complete.” This is the fourth spam update of 2026, following updates in March, June and August. As Search Engine Journal points out, those earlier ones finished quickly (19 hours 30 minutes in March, just over two days in June, and two days 16 hours in August), so a window of up to two weeks is unusually long.

Google has given no detail on targeting, so anyone claiming to know exactly what this update is after is guessing.

Why can a spam update hit a business that has done nothing wrong?

Spam updates improve Google’s automated systems for detecting content that breaks its spam policies, and those policies judge what is on your site, not who put it there. If spam is being published on your domain, the site can be treated as a site with spam on it.

Google’s spam policies are clear that “sites that violate our policies may rank lower in results or not appear in results at all”. Several of the policy areas describe things that usually happen to a site rather than things a site owner chooses to do:

  • Hacked content. Google defines this as “any content placed on a site without permission, due to vulnerabilities in a site’s security”. That includes injected pages, injected scripts and hidden links slipped into existing pages.
  • User-generated spam. Spam added “through a channel intended for user content”, such as comment spam and, notably, “spammy files uploaded to file hosting platforms”.
  • Site reputation abuse. Third-party content published on an established site mainly to borrow that site’s standing in search.

The common thread is trust. A long-standing business domain is valuable to spammers precisely because it looks respectable.

What did we see on a WordPress site we look after?

In late September our monitoring flagged an automated campaign against the file-upload fields on a WordPress site we look after. Bots were submitting PDFs with business-lure names, such as fake HR handbooks and purchase orders, in an attempt to get a trusted domain to host phishing documents.

The pattern was methodical: submit a PDF through a form, then try to fetch it back to see whether it was now publicly available. The file names looked like ordinary office paperwork, the kind of attachment someone opens without thinking if it comes from a familiar company’s web address.

The form plugin briefly kept the uploads as temporary files before its own scheduled clean-up removed them, and the bots’ attempts to fetch them back did not succeed. We picked the whole thing up in the server’s access logs, which is why we read them every day rather than only when something breaks.

We are not suggesting this campaign is connected to Google’s update. But it is a clear example of how a legitimate site can be recruited to host someone else’s scam, the kind of thing that, left unchecked, leads to security warnings and ranking problems.

Why is a website upload field a publishing channel?

Any feature that lets a stranger put a file on your server and get a web address back is, in effect, a way to publish on your domain. If uploads become public before anyone has checked them, your contact or careers form becomes free file hosting with your name on it.

Most businesses see an upload field as a way to receive CVs or photos. Spammers see a way to borrow your reputation. The same applies to comments, reviews and anything else visitors can write to.

A practical spam hygiene checklist for small business websites

Limit what visitors can upload, keep it private until a real submission is complete, watch your logs, and use the free warnings Google already gives you.

  • Restrict upload types and sizes. Only accept the file types you genuinely need, and set sensible size limits.
  • Keep files private until the form is submitted. A file should not be publicly reachable just because someone started filling in a form.
  • Keep uploads out of search indexes. Private upload folders should not be crawlable or indexable.
  • Put a firewall in front of the site. Web application firewall rules can rate-limit or block the repetitive upload-then-fetch behaviour that automated campaigns rely on.
  • Monitor your logs, not just your uptime. A site can be up and fast while being abused. Website monitoring that looks at access logs spots patterns like repeated uploads, odd file names and new URLs nobody on your team created.
  • Check the Security Issues report in Search Console. Google’s Security Issues report covers hacked content, malware and social engineering such as phishing. If Google has found something, this is where it tells you.
  • Keep WordPress, plugins and themes patched. Most hacks exploit known, already-fixed vulnerabilities.
  • Look for pages and links you do not recognise. Search site:yourdomain.co.uk for pages you never published, and check for outbound links to casinos, pharmacies or loan sites you never added.

Keeping on top of all that is a job in itself, which is what our WordPress webmaster service exists for: updates, security checks and someone actually reading the logs.

What should you do if your site has been used to host spam?

Clean the site completely first, close the hole that let the spam in, and only then ask Google to review it.

  • Find and remove everything. Injected pages, files, links and scripts, across the whole site.
  • Fix the cause. Update or replace the vulnerable plugin or theme, change passwords, and review who has admin access.
  • Request a review. Google advises that when all issues in the Security Issues report are fixed on all pages, you select Request Review and explain the problem, what you did and the outcome. Reviews can take several days or weeks, and Google warns against resubmitting before you get a decision.
  • Be patient with rankings. For spam updates generally, Google says changes “may help a site improve if our automated systems learn over a period of months that the site complies with our spam policies” (Google Search Central).

If you see a sharp drop mid-rollout, do not rush to rewrite your site. Check for injected content first and judge the change once the rollout ends. Our SEO team always rules out spam on the site before blaming the algorithm.

Frequently asked questions

When will the September 2026 spam update finish?

Google started it on 24 September 2026 and said it may take up to two weeks, so it is expected to complete by around 8 October.

What is the September 2026 spam update targeting?

Google has not said. It has only confirmed that it is a spam update, applies globally and covers all languages.

Can a hacked website be affected by a spam update?

It can. Google’s spam policies include hacked content and user-generated spam, which are usually put there by someone other than the site owner.

Is it safe to have a file upload field on my website?

Yes, if it is set up carefully. Limit file types and sizes, keep uploads private and out of search, protect the form with a firewall and watch your logs for abuse.

Worried your website could be hosting something it should not, or want someone to keep an eye on it for you? Book a call with our team and we will talk you through a health check.


Has something in this article peaked your interest? We’re never more than a few clicks or a quick call away so please don’t hesitate to get in touch!

6th October 2026
Google’s September 2026 spam update: is your website hosting spam without knowing? - Avatar
Related Article
Free Consultation

Book a Call