How negative SEO works
The tactics fall into a few groups. Pointing large volumes of spam links at a target in the hope of triggering a link penalty. Copying a site’s content and republishing it, sometimes before the original is indexed, to confuse authorship. Filing false copyright or spam reports. Creating fake business listings or planting fake reviews. In rarer and more serious cases, exploiting a weakly secured site to inject pages, hidden links or redirects.
The first of those is what most people mean by the term, and it is also the one least likely to work. Google has said for years that it tries to ignore links it does not trust rather than punish the site they point at, precisely because the alternative would let anyone damage a competitor for the price of a spam package.
Why negative SEO matters
Less as a threat and more as a misdiagnosis. When traffic falls, sabotage is an appealing explanation because it puts the cause outside the business. Far more often the real cause is a core update, a technical change made during a redesign, a competitor doing better work, or ordinary seasonality. Investigating the wrong cause burns the recovery window.
Where the risk is real is the part that has nothing to do with links: an insecure site. Injected content and unauthorised redirects genuinely do damage rankings, and that is the version a small business is most likely to meet.
Where it goes wrong
People react before they diagnose. The usual sequence is a ranking drop, a backlink report full of red rows, a large disavow file submitted the same week, and then no improvement — because the links were never the cause, and the file may now be suppressing legitimate ones as well.
The other error is assuming an attack because spam links appeared. Junk links arrive at almost every site, unprompted, all the time. Their existence on its own is not evidence of anything.
What to do about it
Diagnose in order. Check Search Console for a manual action or a security issue. Check whether your indexed pages have changed. Check whether the drop lines up with a known algorithm update or with something you changed yourself. Compare your movement against competitors before concluding anything. Only when all of that is ruled out is an external cause worth considering.
Keep the basics tight: current software, strong administrator accounts, a small plugin surface, monitoring for content that appears without your knowledge, and an alert for copies of your pages. If an attack is confirmed and links are named in a manual action, a disavow file is the right tool, used narrowly. Otherwise the strongest defence is an unremarkable one: a site that earns its position honestly is hard to knock down and easy to explain to a reviewer.