A healthcare practice came to us after finding hundreds of junk URLs appearing under their domain in Google. A spam-injection hack had been generating pages of unrelated content, and even after the infection was removed, those URLs were still in search results and damaging the practice’s reputation.
Removing the malicious code was only half the job. The other half was getting Google to drop the spam pages quickly. Instead of waiting for each one to fall out of the index on its own, I added a single .htaccess rule with a regex that matched the spam URL pattern and returned a 410 “Gone” status for all of them at once. A 410 tells search engines the page was removed on purpose and isn’t coming back.
In my experience, most people think a hack is over once the malware is gone. It isn’t. The search results are what your customers actually see, and they can keep hurting your business for months. I now treat deindexing as part of every hack cleanup.