I did this too - I am getting a few signups per week with fake emails?
Topic summary
Store owners are experiencing an influx of fake customer accounts with random names and seemingly legitimate email addresses across various domains (Gmail, Hotmail, corporate emails). The accounts appear even when customer registration is disabled and no signup forms are visible.
Common characteristics:
- Accounts show “Customer was created” in timeline with no specific source
- Occur despite password-protected stores
- Continue even with standard CAPTCHA enabled
Primary solution identified:
The main issue appears to be theme-related. One user resolved it by:
- Navigating to theme customization
- Selecting the customer registration page
- Removing the signup form from the template entirely
This worked because some premium themes don’t properly implement Shopify’s CAPTCHA settings.
Alternative approaches suggested:
- Increase CAPTCHA sensitivity (requires apps like Helium Customer Fields)
- Enable email verification before account creation
- Use IP blocking apps (e.g., Blockify)
- Secure admin accounts with 2FA and password resets
Key concerns:
- Fake accounts can trigger spam complaints when welcome emails are sent
- May increase ESP costs if accounts opt into marketing
- Deleting accounts is tedious (limited to 50 at a time)
- Bots can bypass frontend restrictions by hitting Shopify’s backend endpoints directly
Status: Issue remains unresolved for many users. Shopify reportedly “working on it” but no timeline provided. Standard CAPTCHA alone proves insufficient.
1 Like