My store has recently suffered a malicious registration attack and has registered 60,000customers (which is scary), I have tried the following options and none of them have solved the problem, what can I do to fix this problem?
- hide the registration form
- use new customer account
- tried several public apps
Hi Kyle @Kyle_liu so sorry about the inconvenience you’re currently facing. What public apps in particular did you use? Did you try the high ranking location and bot blocking apps?
Hi @Bundler-Manuel
I used ‘Negate Bot Protection’ , ‘Blockify: Fraud Filter’, "Blocky Fraud blocker’ and ‘Browsify: Fraud Filter Blocker’
You can contact Shopify’s Trust & Safety team directly, not general support. A 60,000-account attack is the kind of thing their platform security team can investigate at the infrastructure level. You can reach them through your Partner Dashboard or escalate via a support ticket specifically flagging it as a bot/fraud attack on your store.
Or if you’re already on new customer accounts and still seeing this, double-check whether the registrations are completing the email OTP step or whether they’re just creating pending/unverified accounts. Shopify’s new accounts require email verification to actually log in, so if the 60k accounts are unverified shells, they may be less harmful operationally - but it’s still worth understanding whether the bots are getting through the OTP step or not.
Cloudflare is also worth considering even on the free tier. Since it sits at the DNS level, it intercepts requests before they reach Shopify. Enabling ““Bot Fight Mode”” or even just the basic DDoS/bot detection can cut off a lot of automated registration traffic that app-layer solutions can’t catch.
If the registrations are concentrated from specific countries or ASNs, geo-blocking or ASN blocking through Cloudflare is more surgical than anything you can do inside Shopify directly.
The combination of Cloudflare at the edge + escalating to Shopify Trust & Safety is probably your best path forward at this point, since you’ve already exhausted the app options.
At that volume, I’d honestly be less worried about the fake accounts themselves and more worried about what the traffic is trying to test.
We’ve seen situations where waves of fake registrations were followed later by things like card testing, fake checkouts, coupon abuse, or support spam.
Sometimes the registrations are just the first visible sign that automated traffic is probing the store from different angles.
Hey @Kyle_liu try try this one Enable captcha go to online store >preferences and enable Google reCaptcha on the registration from
if it is help full to you then don’t forget to LIKE & MARK AS SOLUTION on it