Thousands of dummy customers - how to stop

I’m getting hundreds of dummy customer accounts created every day. It’s obviously bots and many of them place something in the cart leaving an abandoned checkout. It’s really messing with my stats. Is there anything I can do about this? I’ve tried geoblocking China (where the visits seem to be coming from) using an app but it doesn’t seem to be working. Help!

Hi! I have not encountered this problem before, but I can see how problematic this would be. Which app did you try?

Hey @Nicky_Hemming! That sounds really frustrating. If geoblocking by country alone isn’t helping, I’d suggest going a step further and blocking by a specific URL/path as well, especially if the bot traffic is hitting the same pages repeatedly (for example account creation, login, or other suspicious entry points).

It’s also worth enabling bot blocking , not just country blocking. Bots can rotate IPs or use VPNs/proxies, so blocking one country alone often won’t stop them for long.

If you haven’t already, you may want to look into MIDA Fraud as well. A fraud/bot-focused solution is usually more effective for this kind of issue than simple geoblocking, especially when fake accounts and abandoned checkouts are involved.

Hope you get it under control soon.

@Nicky_Hemming

This is a frustrating but unfortunately common bot attack.

hCaptcha and geoblocking don’t fully stop it because Shopify’s hCaptcha only protects login and contact forms, not the checkout. Bots can directly access cart or checkout pages and create abandoned checkouts without triggering CAPTCHA. Also, many bots use VPNs or proxies, so blocking a country like China doesn’t always work effectively.

You should first make sure hCaptcha is enabled in Online Store > Preferences, and avoid using any conflicting third-party CAPTCHA apps. It’s also a good idea to enable double opt-in for emails so fake addresses don’t affect your marketing list.

You can temporarily pause abandoned checkout emails to avoid sending messages to bot-generated emails, and use Shopify reports with the “Human or bot session” filter to get cleaner analytics.

For cleanup, abandoned checkouts will auto-delete after 3 months, but fake customer profiles can be exported and removed in bulk using tools like Matrixify.

For stronger protection, full checkout-level bot blocking is only available on Shopify Plus, otherwise you’ll need a third-party bot protection or WAF app. You can use below app

https://apps.shopify.com/mida-fraud-ip-blocker

I have a solution: require guests to log in before they can proceed to the checkout page.


The results can be seen instantly and clearly.

Yes, that could work.

Yes, I think that the problem is VPNs. All the “customers” are located in USA but all the traffic is from China!

Thanks @mastroke . I’ve paused abandoned checkout emails and I’ll check out the human/bot session filter. Didn’t know I could do that!

The “Human or bot session” filter mastroke mentioned is useful, but it only affects Shopify’s own reports… your google analytics, meta pixel, and ESP metrics (klaviyo/mailchimp/etc.) don’t know about that filter and will still show the bot traffic as real customers. So even with hCaptcha and login-required in place, if any bots slip through (and with VPN-based traffic some always will), your ROAS, conversion rate, and sender reputation stay corrupted in the places you actually make decisions from.

Two things worth adding on top of what’s already been suggested:

  • In your ESP, add a suppression filter on profiles matching the VPN-USA signature you’ve identified (USA address with the traffic actually coming from China). Keeps them out of your abandoned cart flows and out of your active list, so you’re not burning sends or inflating your subscriber count. Matrixify is useful for cleanup, but this stops the bleeding
    upstream.
  • For google analytics, either mark those sessions as internal traffic or exclude the specific IP ranges you can identify. Won’t catch everything but takes a decent chunk out.

The VPN-USA pattern is pretty well known by now and the signature is usually clean enough to automate the filter once you have 2-3 days of samples.

Hi @Nicky_Hemming

As a Shopify partner, this is usually bot traffic hitting signup and checkout endpoints, not just site-based visits. Geo blocking won’t help with it alone. Add Shopify’s CAPTCHA for creating accounts, require email verification, and limit guest checkout spam by using checkout rules. Additionally, many merchants utilize Cloudflare bot protection, or apps similar to BotBlock that filter spam more effectively.

@Nicky_Hemming Hundreds of dummy customer accounts per day can create a different operational burden from ordinary bot traffic, especially when abandoned checkouts also distort store reporting.

Since geoblocking did not appear to resolve it, could you share three non-sensitive details?

  1. Is the activity still occurring, and approximately how many fake accounts are created per day?
  2. How much staff time is spent identifying, deleting, or separating them from real customers?
  3. Apart from analytics, has the activity affected email automations, payment processing, support work, or legitimate customer access?

Please do not share customer details, checkout data, or store credentials. I’m researching the workflow and trying to understand which consequence is costly enough to require a focused solution.