Defacement/compromised-site signal
Websites that may be compromised
A compromised-site signal means the domain may be legitimate, but the specific page may have been altered, abused, or used to redirect visitors.
What it is
A compromised-site signal means the domain may be legitimate, but the specific page may have been altered, abused, or used to redirect visitors.
Why it matters
Attackers sometimes abuse real sites because people trust the domain. A compromised page can still steal information or redirect to malware.
Warning signs
- A normally trusted site shows strange ads, redirects, or unrelated pop-ups.
- The page content has unexpected political, scam, gambling, adult, or download material.
- The link path looks suspicious even though the main domain is familiar.
- The page asks for credentials in a place where that site normally would not.
What to do
- Do not enter credentials on pages that look defaced, injected, or out of place.
- Navigate to the site's main page directly and look for the content from there.
- Report suspicious pages to the site owner or your security contact.
- Avoid downloading files from compromised-looking pages.
Examples
Risky: A local club's website suddenly redirects visitors to a fake prize page.
Safer: Close the page and notify the site owner if you know them.
Risky: A trusted supplier site has a strange login form on an old blog post URL.
Safer: Use the supplier's main login page from a bookmark.
Common mistakes
- Assuming every page under a familiar domain is safe.
- Ignoring sudden redirects away from the trusted site.
- Entering credentials into a site section that looks newly broken or out of place.
Key takeaway: A familiar domain lowers some risk, but it does not make every page trustworthy.