Perfection Cosmetic Clinic
A medical aesthetic clinic in North York, Toronto, led by registered healthcare professionals. The site was hit by a DDoS attack that overloaded the server and left pages unreachable. The blanket blocking put in place to stop it also blocked search-engine crawlers, so the site could no longer be crawled or indexed and organic traffic fell. We took over, replaced blanket blocking with precise rules, and restored crawling and indexing.

What we inherited
The site was hit by a DDoS attack, with malicious requests overwhelming the server. To stop the bleeding, blanket blocking was applied through Cloudflare. It did stop the attack — and the same rules shut Googlebot out with it. The site still loaded for visitors; it simply could no longer be crawled, so the index drained away and organic traffic fell with it.
What the diagnosis found
- The protection rules were drawn too broadly and treated search-engine crawlers as anomalous traffic
- Pages served normally to visitors but returned a blocked response to crawlers — a failure that is invisible in a browser
- With crawling stopped, the existing index decayed and rankings went with it
- The attack was in fact concentrated on specific pages and specific sources; blanket blocking was far wider than the problem required
How we worked
- 01
Establish the attack's real footprint first
We analysed the sources and the pages actually being targeted before touching a rule. How narrow the protection can safely be depends on how concentrated the threat is — do this properly and you never need blanket blocking to feel safe.
- 02
Replace blanket blocking with precise rules
Limits were applied to the affected pages and the malicious traffic itself instead of to everything unusual, with search-engine crawlers explicitly allowed. Protection and crawlability are not in conflict; they just have to be handled separately.
- 03
Verify as a crawler, not in a browser
A full-site crawl confirmed crawlability and indexability, checking the response search engines actually receive. This is the crucial step: the incident persisted precisely because everything looked fine in a browser.
- 04
Monitor the index coming back
Restored crawling is not restored indexing — re-indexing takes time and the search engine sets the pace. We kept monitoring until pages returned to the index, rather than treating the fix as the finish line.
Where it stands
The blocking is resolved, search engines can reach the site again, and the index has been recovering. As with the other rescue on this list, we publish no traffic figures — we do not hold Search Console access to this property. What is worth remembering here isn't a number: a protection rule drawn too widely can remove a site from search results with no error message anywhere, while the site looks perfectly healthy to everyone who visits it.
What we did
- Analysed the attack sources and the pages being targeted
- Replaced blanket traffic blocking with targeted rules
- Reopened access for search-engine crawlers
- Full-site crawl to confirm crawlability and indexability
- Monitored index recovery and the return of organic traffic


