My website is being raped by BOTS from SINGAPORE

In the last few days (to be precise on April 17, 2026) I noticed a spike on visits from Singapore.

Here is the visits:
4/17 1,357
4/18 1,964
4/19 5,860
4/20 9,475
4/21 13,611
And today, as I am writing this, the report says it’s 115% higher than yesterday the same time.

It’s not getting any better.
I 've read Shopify has Cloudflare but I don’t think it’s being used to protect people who is not on PLUS, is this correct?
I see on my Shopify Analytics that people are trying to checkout but it looks like my website is clogged.
FYI the bots are not trying to do checkout or add to cart (not yet!)
They land in random product, collection pages (like 300 sessions at once on the same page) and 100% bounce.

I really need help. I contacted Shopify chat but they said what I already did: turn on Enable hCaptcha. Duh? Who didn’t? That’s it? So I just sit here and watch my store sink?

He said: “I completely understand your situation right now, and you’re not alone. Many merchants are seeing the same thing, and it’s a real concern, especially when it affects your analytics and ad performance.

He said to go to Google Analytics and flag the bots as “internal traffic” so they don’t count as traffic. WHAT T F??? What kind of advice is that???

Can someone out there help me?

Thanks!

@ChelseySoper they are correct, you have blocked the traffic from Google analytics,

You can try this

1- block the traffic from Singapore for some days, if your target country is not Singapore

2- you can also try the shopify app like Blockify Fraud Filter, available on App Store.

have tried using cloudflare? they have a bot protection system especially for this

We cannot have Clouflare since Shopify already has it. Thanks for taking the time to help.

Blockify didn’t help since the bot hit the website before the app can delete them from the analytics. Thanks for taking the time to help.

then serverside configuration is the solution and connect with Shopify support.

We recommend to use Blocky to begin with if you’re store is ONLY seeing a spike in traffic bots, not fraudulent orders, it wont fix your reporting data, but will allow you to block country or IP bot traffic.

Alternatively, go into your domain register settings and see the options to block the IP at the DNS level.

Lastly, if fraudulent order volume is a problem, get Cloudflare, you can control the aggressive approach in the settings to avoid losing sales. Forget about Captcha on Shopify Settings, not a good option.

This definitely looks like a coordinated bot attack. It is a common problem for stores that are not on Shopify Plus because they lack advanced firewall controls to block specific countries or IP ranges. The advice you received to filter your analytics only masks the reporting errors and does not solve the underlying performance issues. You should look for a dedicated security app in the Shopify store that can block traffic by country if you do not do business in Singapore. To ensure that this surge of bot traffic does not damage your site speed or search engine rankings, you can use SearchPie. It helps monitor your technical health and optimizes your store performance during these challenging spikes.

bot traffic spikes from a single country are super common and unfortunately Shopify’s built-in protection doesn’t catch everything. the good news is this is inflating your analytics but probably not costing you money unless you’re running retargeting ads that include these fake sessions.

quickest fix: go to Settings > Markets and either remove Singapore as a market or set it to inactive if you don’t ship there. that won’t fully block bots but it removes the storefront for that region. for a more robust solution, add a Cloudflare layer in front of your store (you can do this even on Shopify by changing your DNS). Cloudflare’s free tier has bot protection that catches most of this. also exclude Singapore from any ad retargeting audiences immediately so you’re not paying to retarget bots.

A spike like that going from ~1.3k to 13k+ visits in five days, all from one country, reads like scraper/bot traffic rather than buyers, so the first move is to stop trusting the session numbers and look at whether any of it converts. It almost never does in these cases.

On the Cloudflare question: Shopify does sit behind Cloudflare, but you don’t get to configure those rules yourself on standard plans, so you can’t just switch on a country challenge the way you could on your own server. That’s the limitation people keep running into.

What you can do without Plus:

Block or redirect the country at the storefront with a country/IP blocker app. That won’t help if the bot is hammering the checkout URL directly, but for storefront visit spikes from one region it works and it cleans up your analytics fast.

Filter the noise out of your reporting by leaning on GA4 with bot filtering plus a segment that excludes the offending region, so your real CVR becomes visible again.

If the goal is mainly to keep that Singapore traffic off the store and out of your stats, an app such as Blockify can block by country/IP and catch VPN/proxy traffic, and it logs what it blocks so you can confirm it’s actually junk and not real visitors. If you later see the same bot skipping your product pages and going straight to checkout, that’s a different problem and would need a WAF in front of the domain instead.

For my Shopify clients getting hit with Singapore traffic I added them to Cloudflare on top of the native Shopify Cloudflare. Shopify support stated they won’t allow merchants to block entire countries for some reason. This gets around that with a completely customizable Cloudflare account layer. You can setup a rule to block Singapore and you’ll be set. Your conversion rates and traffic will be back to normal in about 48hours. This is the only thing that worked for my clients.

Hi @CD .
Your Shopify support advice was useless. Do this instead.
Sign up at cloudfare.com.
Point your domain’s DNS to Cloudflare.
Turn on Bot fight mode.
Geo block Singapore until it stops.
That’s it, Cloudflare freetierr handles exactly what you are describing.
Mass bot traffic is hitting random pages.

This doesn’t work, the bots are getting past cloudflare with security set to block and to give them the manual human test.

I wouldn’t treat this as an analytics problem just because the traffic is showing up there. Filtering it out in GA only makes the report cleaner; it doesn’t stop the requests from reaching your storefront. If you’re actually seeing the site slow down, you need to deal with the traffic at the request/security layer rather than just excluding it from reporting.