This is one of the most frequent reports — and one of the most confusing, because the merchant often cannot reproduce it. From their own computer the site behaves normally. From a customer’s phone it sends visitors to a dubious advertising page.
Why you see nothing
Today’s malicious redirects are conditional: they only fire in certain circumstances. Depending on device type, on where the visitor came from, sometimes only once per person — and almost never for someone logged into the site’s administration.
This targeting is not accidental. It exists to monetise your traffic for as long as possible without raising your suspicion. It is also why the problem is nearly always reported to you by a customer, a partner or a search engine before you notice it yourself.
Confirm before concluding
Before deciding your site is compromised, make sure the behaviour reproduces from several devices and several different connections. Identical symptoms can come from a malicious browser extension on one person’s machine, or from compromised network equipment at their end. In that case your site is not at fault.
If the behaviour reproduces everywhere, however, the problem really is on your site — or on the layer sitting in front of it.
What it reveals
A redirect is never an isolated incident: it is the visible part of access obtained by someone else. So the real question is not “how do I remove this redirect” but “how was that access obtained, and what else did it allow”. A site that can redirect your visitors is also, potentially, a site where other modifications were possible.
That is why deleting what you can see almost never suffices. In most cases the mechanism reinstates itself within hours.
Consequences to handle in parallel
A malicious redirect quickly leads to flagging in browsers and search engines, often followed by suspension of your advertising campaigns. These effects do not clear automatically once the site is clean: separate procedures must be started, each with its own timelines and evidence requirements.
And if your visitors were sent to phishing pages, the question of protecting your customers arises — with, depending on the case, information obligations to meet.