August 2026

Recovery publishing active
Plan Authority · 50% intro discount
Monthly Report · April 2026

Foundation: tracking, indexing & Core Web Vitals

Month one built the measurement layer and technical baseline the whole campaign runs on.

Live
GA4 & Search Console
Live
Looker Studio dashboard
Full
Sitewide deep-crawl audit
63/52
PageSpeed — mobile / desktop
Workstreams this month
Analytics & indexing

Measurement & crawl foundation

  • GA4 + Search Console integrated for traffic, behaviour & index coverage
  • Audited robots.txt; clean XML sitemap generated & submitted
  • Full Googlebot-simulated deep-crawl across the site
  • 404s, redirect chains & warnings mapped for remediation
Competitive intelligence

Positioning & backlink gap

  • Top 5 competitors identified & organic footprint reverse-engineered
  • Backlink intersection analysis → high-authority target pool
  • Domains linking to competitors but not Reya isolated for outreach
Core Web Vitals — fixed

Stability & payload

  • CLS: custom CSS reserves space for heading animations — layout shift resolved
  • Payload: heavy images converted to modern compressed formats
CWV — engineering call

Render-blocking JS

  • !
    Deferring jQuery/builder JS spiked scores but broke Contact-form AJAX
  • Rolled back immediately — live lead-gen protected over a test metric
Why this matters

The change moved render-blocking scripts to the footer and loaded Elementor stylesheets asynchronously. Tool-reported scores jumped, but inquiry submissions failed. Protecting a working lead channel outweighed a synthetic score — documented here for transparency, not hidden.

Strategic foundation

Strategy & topic mapping

  • ICPs & user personas defined
  • High-value topic clusters mapped
  • Manual EEAT analysis on founder profile woven into strategy
Constraint identified

Elementor / builder ceiling

  • Surface bloat stripped; layout stabilised
  • 90+ scores need root-level builder work
  • Requires original dev team to avoid breaking the live site
Plan Authority · 50% intro discount
Monthly Report · May 2026

Keyword architecture, silos & the content engine

Month two built the production pipeline — research, silo structure, and the first article wave staged for early-June launch.

Mapped
Topic clusters & silo structure
Expanded
Intent & long-tail keyword set
Started
June content pipeline
Batch 1
Off-page outreach live
Workstreams this month
Keyword research

Intent mapping

  • Intent-led research across longevity, preventive care & clinic management
  • Long-tail expansion layered on top
  • Organised into prioritised clusters driving the roadmap
Content silos

Structure & linking

  • Silo architecture planned
  • Internal links improved across the site
  • Unlinked / underlinked pages identified & addressed
Content production

June pipeline drafted

  • First educational cluster researched & drafted
  • Queued for a sequenced early-June rollout
  • Staged, not dumped — clean cadence per URL
Tracking integrity

Consent-policy (Complianz) Resolved

  • Cookie-consent rollout required consent-mode re-verification
  • Consent configuration handled by Reya's development team
  • GA4 & GSC confirmed reporting cleanly before scaling publication
Groundwork carried into June
Off-page & on-page prep
  • First high-authority target list curated from the backlink-gap pool
  • Relationship-based outreach initiated (batch 1), entering webmaster response cycles
  • Page structures & silos audited; meta and structural tags prepared ahead of on-page optimisation
Plan Authority · 50% intro discount
Monthly Report · June 2026

Publishing launches — then a security incident forces a pause

Four articles went live in early-to-mid June. On ~22 June a casino PBN compromised the site; publishing was paused for containment.

4
Articles published (11–16 Jun)
~3d
Observed index time / article
22 Jun
PBN compromise begins
Paused
Publishing halted for safety
How the month unfolded
11–16 Jun
Pipeline live

4 articles published

  • First educational cluster went live on a sequenced cadence
  • Strong indexing behaviour — ~3 days to index per article
~22 Jun
Incident onset

Casino PBN compromise Contained

  • !
    Admin-level account compromised by a Private Blog Network
  • !
    Casino posts published, footer links injected, 12 spam posts indexed before detection
Full forensic detail

Entry vector, database persistence and remediation are documented under Additional Services → Casino Exploit Resolution.

Decision
Containment

Publishing paused

  • Footer injection was sitewide — new pages would carry casino markup into the index
  • Pausing stopped the spam footprint growing on a YMYL health domain
  • Content production continued in the background — queue kept ready
Published this month · 4 articles
Plan Downgraded to Growth Plan
Monthly Report · July 2026

Remediation, verification & controlled resume

The incident window closed 25 July. Publishing resumed 27 July on a controlled cadence; event-page work began in parallel.

22 Jun–25 Jul
Incident & verification window
27 Jul
Publishing resumed
5
Articles published (27–31 Jul)
3
Event pages delivered
How the month unfolded
22 Jun–25 Jul
Blocked

Publishing blocked by the incident

  • !
    Remediation + one-week verification window ran through 25 July
  • Full technical account documented separately
Where the detail lives

File-system audit, database forensics, credential rotation and verification are under Additional Services → Casino Exploit Resolution.

In parallel
Behind the scenes

Work continued during the block

  • Off-page guest-post prospecting & data collection
  • Back-end content production — queue built & staged
  • Remediation coordinated with hosting through 25 July
27 Jul
Resumed

Controlled publishing resumes

  • Site verified clean; publishing resumed 27 July after the 25 July verification close
  • 5 articles shipped 27–31 July on a steady daily cadence
Published this month · 5 articles
Event pages · 3 delivered — each with SEO-optimised content
lm2026 Content update
Content & imagery refresh on existing Elementor design, with SEO-optimised copy.
24 Jul 2026
Longevity Roundtable Content update
Content & imagery refresh on existing design, with SEO-optimised copy.
28 Jul 2026
HLTH USA Built from scratch
New page designed & built ground-up on, with SEO-optimised content and structure.
28 Jul 2026
Plan Downgraded to Growth Plan
Monthly Report · August 2026 · through 12 Aug

Recovery publishing at pace, new event pages & off-page scale-up

Nine articles on a steady daily cadence, a second from-scratch event page, and the off-page programme scaled to 100 prospects.

9
Articles published (3–12 Aug)
18
Total articles live since launch
1
New event page shipped
100
Off-page prospects — batch 2
Published this month · 9 articles — through 12 August
Event pages · new page build & content
longevity fest 2026 Built from scratch
New event page on a fresh layout & components, with SEO-optimised content and structure baked into the build.
3 Aug 2026 · pairs with HLTH USA to form the new event-page
SEO-optimised content All 4 event pages
Every event page — the 2 updates and the 2 from-scratch builds — shipped with purpose-written, SEO-optimised copy and structure.
Jul 24 – Aug 3, 2026
On-page SEO · home-page content
reya-home.vercel.app Shared for review
On-page, SEO-optimised home-page content written for Reya’s pivoted scope, delivered as a live preview for sign-off before it goes onto reya.ai.
Shared Aug 2026 · preview live until 30 Sep 2026
Pivoted positioning Awaiting approval
Copy reflects the new scope, with a fresh website UI proposed alongside it. Awaiting client approval before it replaces the current home page.
Preview: reya-home.vercel.app
Off-page & recovery
Off-page SEO — batch 2

Refreshed prospect programme

  • Batch 1 secured no placements — target pool re-analysed
  • Rebuilt into 100 healthcare-relevant prospects, qualified for topical relevance
  • Outreach discontinued — programme wound down
Recovery context

Cadence rebuilds the topic signal

  • 14 articles across 27 Jul – 12 Aug on a controlled cadence
  • Each URL submitted for indexing → Google re-crawls a healthcare-focused site at pace
  • 3-month indexing velocity now works in the campaign's favour
Campaign Pipeline

What’s next

With the project winding down for a 31 August close, only on-page content optimisation and the LLM context file remain in play. The remaining off-page and ongoing-content workstreams are discontinued.

01 · On-page

Content optimisation

Submitted — waiting for corrections from team Reya
  • Homepage first, then core pages
  • Meta, structural tags, intent alignment
02 · Technical

LLM context file Waiting for homepage content

  • Deploy for accurate AI-crawler parsing
  • Extends readiness beyond classic search
03 · Technical

Sitemap update Discontinued

  • Refresh & resubmit full published set
  • Keeps discovery current as URLs ship
04 · Content

Continued production Discontinued

  • Hold the cadence through recovery
  • Expand cluster coverage & authority
05 · Off-page

SEO listings Discontinued

  • Directory & industry listings
  • Citation consistency
06 · Off-page

Guest posts & backlinks Discontinued

  • Advance batch-2 (100 prospects) to placements
  • Rebuild & grow domain authority

Where things stand: the home-page content optimisation for Reya as an intelligence layer was created and shared on 24 Aug 2026. On a follow-up call with Jomy we learned about Reya’s pivot, so we produced fresh home-page content for the new positioning and have already shared that too. Both directions also call for a fresh UI for the website, and we are currently awaiting approval on both.

Action needed · article backlog

40 articles produced against quota — 22 held back by the pivot Decision needed

40
Articles produced (intelligence-layer scope)
18
Published & live
22
Unpublished — held by the pivot
26 Aug
Decision requested by EOD, 26 Aug 2026

Per the content quota, 40 articles have already been written for Reya as the intelligence layer. 18 are published and live. The remaining 22 are not yet published because of the pivot.

Action needed: approve publishing the 22 intelligence-layer articles as they are, or decide not to publish them.

We’d like this decision within a day (by 26 Aug 2026, EOD) so we have time to wrap the project by 31 Aug 2026. All SEO-related work will be discontinued after 31 August.

Wins · Keyword Rankings

Keywords we’re now ranking for on Google

Live Google SERP positions for target longevity keywords — several already in the top 3, with the intelligence-layer term at #1 and also cited by Google’s Gemini.

#1
Longevity Intelligence Layer · cited by Gemini
4
Keywords ranking in the top 5
6
Target keywords now ranking
Google
Positions per live SERP
Ranked keywords · Google SERP positions
# Keyword Position Notes
01 Longevity Intelligence Layer #1 Position 1 — also cited by Google’s Gemini
02 4Ps of Medicine #3 Top-3 result
03 Start a Longevity Clinic #3 Top-3 result
04 Longevity Clinic Operating System #4 First page, just outside the top 3
05 Longevity Concierge Medicine #7 First page
06 Longevity Clinic Patient Engagement #12 Page two — climbing

Positions are as per the live Google SERP. Rankings fluctuate with each crawl — these reflect the standings at the time of this report.

Billing · Invoice Summary

Invoices & payment summary

Summary of invoices issued to date. Two invoices remain outstanding — Invoice 0060 (July 2026) and Invoice 0062 (August 2026) for SEO Management Services.

6
Invoices issued
$4,061.50
Total paid
$2,050.00
Outstanding
$6,111.50
Total invoiced
All invoices
# Invoice No. Date Details Amount Status
1 0062 25 Aug 2026 SEO Management Services, August 2026 $1,025.00 Unpaid
2 0060 8 Aug 2026 SEO Management Services, July 2026 $1,025.00 Unpaid
3 0041 17 Jul 2026 Malware Removal Service, Casino Hack Fix $1,000.00 Paid
4 0036 1 Jul 2026 SEO Management Services, June 2026 $1,020.50 Paid
5 0032 25 Apr 2026 SEO Management Services, May 2026 $1,020.50 Paid
6 0030 25 Mar 2026 SEO Management Services, April 2026 $1,020.50 Paid
Outstanding · 2 invoices
Invoice 0060

$1,025.00 — SEO Management Services, Growth Plan Unpaid

Invoice date: 8 Aug 2026  ·  Service period: July 2026

Invoice 0062

$1,025.00 — SEO Management Services, Growth Plan Unpaid

Invoice date: 25 Aug 2026  ·  Service period: August 2026

Total outstanding: $2,050.00 — $1,025.00 (July 2026) + $1,025.00 (August 2026).

01 · Fix summary · 18 July 2026

The persistence mechanism was located and removed. The remediation is executed and now under monitoring.

WordPress admin access was received on 7 July 2026. Elementor hosting access followed on 16 July 2026. The remediation was executed on 18 July 2026. This section documents the work carried out at the file and database level.

07 Jul
WordPress admin access received
16 Jul
Elementor hosting access received
1
Malicious file found and removed
3
Unauthorized access keys revoked

Access and remediation Executed

Ace Wix received WordPress admin access on 7 July. We reviewed the site through the file manager and located the loader.

File and database level access followed with the Elementor hosting grant on 16 July.

The remediation was executed on 18 July. The removal work is done.

Status Executed · monitoring

The remediation is executed, not yet formally closed. A monitoring window of one week is now running.

The incident is closed only after the watch confirms nothing regenerates. If any component returns, we re-analyze and remediate at once.

Remediation approach

The work followed a fixed order. Map the infection, remove the source, clear the content, then rotate credentials.

This sequence is deliberate. A wrong order lets this class of infection rebuild itself during cleanup.

Remediation timeline
  • 7 July
    WordPress admin access received
    Site reviewed through the file manager inside WordPress.
  • 7–10 July
    File system audit
    Full file system downloaded. The Easy Post loader was found in mu-plugins and removed manually. The downloaded copy was verified with ClamAV by 10 July.
  • 16 July
    Elementor hosting access received
    Database access granted for the deeper review.
  • 16–18 July
    Database forensics
    Footer injection and unauthorized access keys located and removed.
  • 18 July
    Remediation executed
    Access keys revoked. Security keys regenerated. Sessions invalidated.
  • 18–25 July
    Verification window
    One week of activity log and file change monitoring.
Scope of the remediation

The audit covered both layers of the site. The file system was examined first, then the database.

The file system held one malicious file, the Easy Post loader. It was removed. The stored injection and the persistence mechanism lived in the database.

The following sections document each layer, the findings and the action taken for each.

02 · File system audit

A full offline scan of every file on the site

We pulled a complete copy of the file system and scanned it away from the server. An offline scan is stronger. Malware cannot hide from a scanner the way it can on a live server.

Step 1

Offline copy and scan

Through the file manager we downloaded a full copy of the WordPress file system. We scanned it locally with ClamAV by 10 July and ran a manual signature review.

Step 2

Coverage

The scan covered the theme, all plugins and the uploads directory. It also covered wp-admin, wp-includes, the root files and wp-config.

Step 3

Core integrity

We compared the WordPress core files against the official release. No modified core file was found. No added core file was found.

Result

One malicious file found and removed Verified

One malicious file was identified, the Easy Post loader in the mu-plugins directory. It was removed by manual check before the scan completed.

The rest of the file system was clean. We found no injected code, no web shell and no other rogue script.

Signal

Direction set

File editing was already disabled through DISALLOW_FILE_EDIT. This confirmed the stored injection had to sit in the database.

03 · Entry vector and loader

The Easy Post loader was the entry vector

The audit traced the injection to a must-use loader. This component ran on every request and stayed hidden from the plugin list. The steps below cover how it was found, checked and removed.

Loader investigation
  • Entry vector
    Easy Post loader
    A must-use loader named Easy Post was found in the mu-plugins directory. It executed on every page load and hid itself from the admin plugin list. The loader was removed.
  • Replication check
    Self-healing copies
    This class of loader often keeps a second copy that rebuilds the first. Every plugin directory was checked for duplicate copies. A Duplicator check was run for any packaged re-installer left behind.
  • Sweep
    Plugin and folder audit
    Every plugin folder and the uploads directory were reviewed. We looked for unauthorized PHP files and unfamiliar plugin names.
  • Result
    Loader layer clean
    After removal, the plugin and file layers were clean. No further loader or replicator remained. The stored content and the persistence mechanism still lived in the database, so the audit moved there.
04 · Database forensics

The database held the injection and the persistence mechanism

The file system was clean, so the source had to be in the database. A full database audit confirmed this. It also revealed the persistence mechanism behind the recurring spam.

Finding 1

Footer injection

The casino footer was stored in an options record named easypost_homepage_placements.

It held cloaked anchors set with absolute off-screen positioning. Visitors never saw them. Search engines still read them.

The record was deleted.

Finding 2

Spam content

The 12 spam posts were removed from the site. The URLs now return 410 Gone for permanent deindexing.

The same URLs were already cleared from Google through the Search Console Removals tool.

Finding 3

Scheduled tasks

We audited WordPress cron and the Action Scheduler queue. No malicious scheduled task was present. Every entry was a known plugin task.

Finding 4

Code snippets

We audited the snippets table. Every snippet was legitimate and owned by the site. None created posts or output footer content.

Finding 5 · Root cause

Unauthorized application credentials

The audit found three unauthorized application access keys. These are API credentials that authenticate against the site without a standard login.

They were created between 21 and 22 June. One key was last used on 2 July, which matches the recurring spam.

They were called from two unrecognized external addresses, 207.228.202.152 and 86.54.24.51.

This was the persistence mechanism. It let the operators re-inject content through the API after each earlier cleanup, without any dashboard login.

All three keys were revoked. The WordPress security keys were then regenerated to invalidate every active session and token.

05 · Verification and monitoring

The site is verified clean and now under a monitoring window

After removal, we verified the result from outside the site and locked down the access layer. A monitoring window now confirms nothing regenerates before the incident is formally closed.

External verification

Live crawl

We crawled the live homepage and blog from outside the site. The footer injection is gone from both.

Only genuine Reya content remains indexed. No cloaked markup was found in the page source.

Access layer

Credential rotation

All user passwords were reset. The unauthorized access keys were revoked.

The WordPress security keys were regenerated. This ended any session the operators may still have held.

Watch

Monitoring window

We monitor the activity log and file changes for one week. This confirms no component regenerates.

If anything returns, we re-analyze and remediate at once.

Hardening

Controls in place

Wordfence is active for firewall and malware monitoring. The custom login URL is live.

Two factor authentication is pending rollout for all administrator and editor accounts.

Conclusion

Remediation executed · monitoring in progress 1 week watch

The casino operation is removed from the file system and the database. The entry vector and the persistence mechanism are both closed.

The removal is executed and verified. The one week watch is the final step before the incident is formally closed. Once posting is confirmed stopped, the SEO recovery clock begins.

06 · SEO impact & recovery

Publishing was paused for safety. It resumes on 27 July with a stacked pipeline.

The footer injection sat on every page. Publishing during that period would have spread the injected markup and fed Google more polluted pages. So content publishing was paused as a containment step.

During the incident

Why publishing paused

The injection was sitewide. Every new page would carry the same casino markup into Google's index.

Pausing was the safe call. It stopped the spam footprint from growing while the source was still live.

Behind the scenes

Work never stopped

The pause was on publishing, not on production. We kept writing and preparing articles throughout.

A queue of ready articles was built up during this window. It is prepared and waiting to publish.

From 27 July

Publishing resumes

The footer is now removed and the site is verified clean. It is safe for Google to crawl again.

Publishing resumes on 27 July 2026, after the one-week verification window closed on 25 July. We push the prepared queue and let Google crawl clean pages.

The method

Stacked publishing

The prepared queue lets us publish on a steady, continuous cadence rather than in one burst.

Consistent publishing rebuilds topical authority and trust signals. It is the fastest safe way back.

How this ties to recovery

The pipeline drives the recovery timeline

The recovery timeline in the Casino Hack Report depends on fresh, clean content reaching Google at pace.

The stacked queue is exactly what feeds that. Steady publishing from 27 July restores the healthcare topic signal and rebuilds the authority lost during the incident.

The site's strong indexing velocity, built over the first three months, now works in our favour again. Clean articles get picked up fast and compound over the recovery window.

01 · Executive summary

The site was hacked by a casino spam network. It is contained, but not fully cleaned yet.

Around 22 June 2026, reya.ai was compromised through a user account with administrator access. The attackers run a PBN (Private Blog Network) — an operation that hacks trusted sites to publish casino content and links. Everything reachable from WordPress admin has been cleaned; the remaining infection sits deeper and needs hosting-level access to remove.

12
Spam posts indexed by Google — now temporarily removed
2
Pages still showing spam in search (home + 1 post)
0
Manual actions or security issues in Search Console
6→9
Revised months to reach the ranking target
Incident timeline
  • ~22 June
    Attack begins
    First malicious activity through a compromised account, per the activity log.
  • 22–29 June
    Spam published & indexed
    Casino posts go live; footer links injected; Google indexes 12 spam posts within days.
  • ~29 June
    Detection & first response
    Entry point traced; malicious plugins and rogue users removed; all passwords reset.
  • Early July
    Search cleanup begins
    All 12 spam URLs hidden via Search Console Removals. No manual action confirmed.
  • Today
    Infection still active below the surface
    Spam keeps reappearing; footer injection still live. Points to a file/database-level backdoor.
  • Next
    Deep clean with hosting access
    Full file and database audit with the hosting provider.

The good news Verified

Search Console shows no manual action and no security warning. Google has not penalised the site — the damage is to trust signals, not a formal penalty. Acting within the first week likely prevented browser warnings that would have hit every visitor.

The open risk Urgent

The casino footer links are still live on the site today. Every day they stay, Google re-reads a healthcare domain endorsing gambling sites. The SEO recovery clock cannot start until the backdoor is found and removed — which needs hosting-level access.

This month In progress

Aggressive SEO measures underway: deleted spam URLs are being moved from 404 to 410 Gone to force faster permanent deindexing, while hosting access is arranged for the deep clean.

02 · What happened

A casino spam network took control and published through the site

Spam posts 12 indexed

The attackers published casino-related blog posts on reya.ai. Google crawled and indexed 12 of them before they could be caught.

Footer link injection Still live

Casino links were injected into the site footer — anchor text in Russian, French, Polish, Turkish, Hungarian and Danish, all pointing to gambling websites. This injection is still visible on the site today.

Why they do it: the PBN model

A Private Blog Network hacks legitimate, trusted websites and uses them as link farms. Reya.ai's domain trust — built through real content and real authority — is exactly what makes it valuable to them: every casino link on the site passes some of that trust to their gambling pages. They target sites like this deliberately, and they build in ways to stay.

The uncomfortable irony: our own indexing velocity

Over the past three months, our SEO work raised the site's crawl frequency and indexing velocity to the point where a new article could be indexed in about 3 days — content was even being picked up by Google's Gemini. That same speed worked against us during the attack: Google indexed the spam before it could be caught. On a slower site, most of those 12 posts would never have reached the index.

That velocity is not the problem — it's an asset. Once the site is clean, the same speed accelerates the recovery.

03 · How it happened

Possible entry through a compromised plugin or account with administrator access

Entry point

Compromised plugin / administrator account

The initial scan identified the likely entry point as either a compromised plugin or a user account with administrator privileges. The available evidence does not conclusively identify the initial entry point.

Tools installed

Two malicious plugins

Using that access, the attackers installed modified plugins disguised as normal utilities — "Easy Post" and "Speed Optimiser". These did the actual damage: publishing spam and planting deeper hooks into the site.

Persistence

Extra accounts & a bot

They created multiple extra user accounts and a bot account, so losing one door would not lock them out. Standard practice for PBN operations — they plan to stay.

Scope of access

What Ace Wix could reach

Ace Wix held WordPress admin access only — the level an SEO agency normally works at. Everything visible and fixable from that level has been handled. The remaining infection lives below it, at the hosting level. Currently Ace Wix holds only Wordpress Editor access.

04 · What we did so far

Immediate containment and search cleanup

Inside WordPress Done

· Traced the entry point through the WP Activity Log

· Deleted the two malicious plugins

· Removed every rogue user account, including the bot

· Reset the password of every user on the site

· Deleted all casino spam posts

In Google Search Done

Submitted all 12 indexed spam URLs through Search Console's Removals tool — they are now hidden from results. The hold lasts about 6 months, covering us while permanent removal completes.

Verified in Search Console: no manual action, no security issue. That keeps the recovery path clean.

This month's aggressive SEO measures In progress

Moving the deleted spam URLs from 404 (Not Found) to 410 (Gone). A 404 tells Google "missing, maybe temporary"; a 410 says "removed on purpose, permanently". Google drops 410 pages from the index noticeably faster — this is one of the levers we're pulling to shorten the recovery.

05 · Open items at time of report

The infection sits below WordPress — and every day it stays live matters

The symptom

After the cleanup, spam posts kept reappearing at regular intervals — and the casino footer links are still live on the site today, weeks after the plugins, users and passwords were dealt with.

The conclusion

The attackers left a backdoor at the file or database level — hidden code that recreates their access and content even after the visible pieces are removed. This layer is not reachable from the WordPress dashboard; it needs hosting-level access to the site's files and database.

Why this is serious Priority 1

Reya.ai is a healthcare platform. Every day the footer keeps linking to gambling sites, Google re-reads a health domain endorsing casinos — the exact opposite of the trust profile the site needs. And the SEO recovery clock cannot start until the infection is fully removed: cleaning search results while the site re-infects itself is pouring water into a leaking bucket. Closing the backdoor is the single most urgent item in this report — which is why the next phase, done with the hosting provider, matters more than anything else here.

06 · How this affects SEO

A health site linked to casinos: the worst mismatch under Google's trust rules

Google treats health websites as YMYL ("Your Money or Your Life") — topics where bad information can hurt people. For YMYL sites, Google leans heavily on E-E-A-T: Experience, Expertise, Authoritativeness, Trustworthiness. Reya.ai's rankings depend on Google trusting it as a serious healthcare platform — and the hack attacks exactly that trust.

Damage

Topic dilution

Search Console now shows casino terms and anchor texts connected to reya.ai. Google's picture of what the site is "about" has been polluted with gambling topics — a drag on every healthcare keyword until it fades.

Damage

Trust signals

Outbound casino links from a health domain, spam pages in the index, and spam anchor text all lower the trust side of E-E-A-T. These fade only after the source is gone and Google re-crawls the clean site.

Avoided

No penalty

No manual action, no security warning. A "hacked site" flag could have put warnings in Chrome for every visitor — far worse for a healthcare company. Acting within the first week likely prevented it.

Timeline cost: the target moves from month 6 to month 9

Deindexing the spam, letting the casino terms fade, and rebuilding trust signals adds roughly one quarter. The keyword set originally projected to reach top positions around month 6 is now projected for month 9.

M1
M2
M3
M4
M5
M6
M7
M8
M9
Growth work done — crawl frequency & indexing velocity built Cleanup & signal recovery Push to ranking target

Ranking projections always depend on Google — these are informed estimates, not guarantees.

07 · Proposed technical fix

A complete audit of the WordPress files and database, with the hosting provider

With hosting access granted, we run a systematic sweep of every layer the attackers could have touched. The goal is simple: find and remove every backdoor, then prove the site stays clean.

This plan was executed on 18 July 2026. The completed work is documented in Casino Exploit Resolution.

Step 1

Core integrity

Verify the WordPress core files against the official clean versions, so any modified or added file stands out immediately.

Step 2

Theme & plugin audit

Review the theme and all plugin code for injected code — including the footer injection that is still live. Reinstall from clean official sources where needed.

Step 3

Malware scan

Scan the full file system for hidden scripts and webshells — attackers commonly plant these where the WordPress dashboard never shows them.

Step 4

Database audit

Check the database content for injected entries, hidden users and stored spam — including anything that regenerates the spam posts.

Step 5

Scheduled tasks

Review all scheduled tasks, WordPress and server level. Spam recurring at regular intervals often means a malicious scheduled job is doing the publishing.

Step 6

Full credential rotation

Rotate every credential the attackers could have copied — hosting, database and FTP passwords, plus WordPress's internal security keys, which force-logs-out every session they might still hold.

Step 7

Verification window

After the clean, monitor the activity log and file changes for a set period to confirm nothing regenerates. Only then do we call the incident closed — and start the SEO recovery clock.

Note

This work is coordinated with the hosting provider's support team. Specific findings — file locations, affected records — are documented privately during the audit and shared in the closure report.

08 · Making sure it never happens again

Prevention and hardening plan

Custom login URL Live

The default WordPress login URL has been changed to a custom one, cutting off the automated bots that hammer the standard login page.

Two-factor authentication Rolling out

Enforce 2FA for every account, mandatory for administrator and editor roles. Each person enrols their own authenticator app — a stolen password alone will never be enough again. This directly closes the door the attackers used.

Security plugin (Wordfence) Active

Wordfence is already installed by the development team. It provides login rate limiting, lockouts, firewall rules, file change detection and continuous monitoring.

Ongoing watch Continuous

Keep the WP Activity Log running with regular reviews, plus scheduled malware scans and file integrity checks — so any future attempt is caught in hours, not days.

09 · Recovery timeline & what to expect

How the search damage unwinds — step by step

Google does not forget instantly, but it does forget. Here is the realistic sequence once the deep clean is complete. The key dependency: every clock below starts only after the infection is fully removed.

Now

Aggressive cleanup measures In progress

Spam URLs hidden via the Removals tool (done) and moved from 404 to 410 Gone this month, telling Google the pages are permanently removed. Hosting access requested for the deep clean.

Weeks 2–6

Permanent deindexing

As Google re-crawls the 410 pages, the 12 spam URLs drop out of the index permanently — not just hidden, gone. The homepage and remaining blog post re-crawl clean once the footer injection is removed.

Weeks 4–10

Casino terms fade from Search Console

With the spam pages and footer links gone, the casino queries and anchor texts lose their source and fade over several weeks of re-crawling.

Months 1–3 after clean

Trust and topic signals recover

Google's picture of reya.ai re-centres on healthcare. Fresh, high-quality content published in this window speeds it up — the site's strong indexing velocity now works for us again.

Months 7–9

Push to the ranking target

With clean signals restored, the original growth plan resumes at full force. The target keyword set is projected to reach top positions around month 9.

Summary: the hack costs roughly one quarter. The foundation built in the first three months — crawl frequency, indexing velocity, content quality — is intact, and it is exactly what makes the recovery this fast.