Getting hit by an influx of bots from China & Singapore, now more bots are coming from Latin America

Hey all, posting this both to see if others are experiencing the same thing and to get more visibility than I got from support, in case there’s a fix nobody’s mentioned yet.

Since October 2025, we’ve had recurring waves of bot traffic hitting our storefront directly (no referrer, shows as “(none)” in GA4). Each wave rotates through a different set of countries:

Oct 2025: Singapore, China, India
Jan 2026: same profile
Mar 2026: same pattern, reduced volume
Jun 2026: quiet
Aug 2026: new wave, Seychelles, Netherlands, Bangladesh, Lithuania, Chile

At peak, this has inflated our session count by 20 to 30x our normal baseline (about 13K/month legitimate visitors vs 380K+ bot sessions in a recent period). GA4 confirms it: these sessions show about 1 to 2 second engagement time and under 15% engagement rate, versus 70 to 90%+ for our real channels (organic, paid, email, affiliate).

We checked, no checkout attempts beyond one bot, zero fraudulent orders, and no affiliate/referral link connection. It’s pure top of funnel crawling (homepage/product/collection pages), not fraud or cart abuse.

We use the Blocky Fraud Blocker app and have it set to block by country. But blocking at that level still lets the request count as a session before it’s blocked, the bot can still load/interact with the site enough to register a visit, it just can’t complete certain actions. So our session and analytics data stays inflated even with country blocking active. & yes, I do know I can filter them out on analytics, but it’s still very frustrating also we have zero marketing camapigns outside of the US. Everything is set to US only

Shopify told us this is happening to other merchants, the bots are “sophisticated,” and there’s nothing to be done beyond filtering analytics with the built-in bot exclusion.

What I’m trying to figure out:

  1. Has anyone found a blocking method that actually prevents the session from counting at all, rather than just blocking the interaction after the fact?
  2. Has anyone had better luck with a different app or Cloudflare level blocking for this kind of rotating country pattern? (Heard mixed results from other merchants on Cloudflare specifically.)
  3. Is anyone else seeing app billing impacted by bot inflated session/user counts (apps that price by MTU or session volume)?
  4. Any luck escalating past tier 1 support to get a real technical response, given a documented year long pattern?

Those numbers are large enough to separate two questions: storefront blocking and reporting/billing.

Shopify’s current docs say every online-store request already passes through Shopify’s Cloudflare layer, and its domain troubleshooting page says putting your own Cloudflare proxy/O2O in front is unsupported and can actually reduce Shopify bot-detection accuracy. Cloudflare published an O2O Shopify guide on Aug 25, so the vendor docs currently conflict; I would not change DNS until Plus Support confirms in writing that your exact setup is supported.

Also, Shopify Plus bot protection is a checkout-event control, so it won’t solve homepage, product, or collection crawling. For the next seven days I would freeze one daily evidence table with:

  • Shopify Analytics: Human or bot session dimension
  • GA4: country, landing page, hostname, and engagement time
  • each MTU/session-priced app: billed users/sessions and billing window
  • checkout and order impact

Then ask Plus Support two specific questions: whether these requests are being classified as bots at Shopify’s edge, and whether they can provide a case/escalation ID for the recurring fingerprints or ASNs. For each app vendor, ask whether known bots are excluded from billing and request a day-level export.

Which apps are showing the possible billing increase, and can any of them export the counted users or sessions by day? That determines whether this is only analytics cleanup or a real billing-reconciliation problem.

Shopify references:
https://help.shopify.com/en/manual/intro-to-shopify/bots/dealing-with-bots
https://help.shopify.com/en/manual/intro-to-shopify/bots/bot-filtering
https://help.shopify.com/en/manual/domains/troubleshoot-issues-with-domains

Update: Checked our paid app subscriptions, all flat-rate monthly fees, no MTU or session-based pricing exposure. Ruling that question out, this looks to be purely an analytics/reporting issue, not a billing one. Ignore that question

Generally speaking, bot traffic is pretty normal, and for the most part unavoidable. Country blocking apps are mainly for blocking individuals, really not a good approach for mass bot traffic. Bots can use rotating IPs and completely go around it. A scraper bot can go through data center IPs, proxies, VPNs, etc.

And it’s not really unique to Shopify either… It happens on every e-commerce platform. WooCommerce, Magento, Wix, they all get hit pretty bad. But I think you’re spot on about filtering. Shopify could/should do a better job at analytics filtering. BTW, @kai_xing is just pasting ChatGPT/Sidekick, so would that count as a bot? lol