• Resolved gluecklichezwerge

    (@gluecklichezwerge)


    Hello everyone,

    since a couple of days a client of mine is receiving automated mail error reports saying mail delivery failed, the email account she tried to reach does not exist.
    Because the amount of error mails made her suspicious, she pleased me to take a look at it.
    Now here is what I found out:
    – all the mail accounts are registered at gmail.com
    – all the mail accounts are registered to senseless, cryptic names, like [email protected] (just an example, to avoid leaking userdata I changed a few letters!)
    – the error report has been sent after the mail account registered in the Woocommerce shop of my client
    – all of the suspicious mail accounts belong to newly registered customers with the exact same name, without filling in First and Last name

    Taking a look at all of this gives me the feeling some bots registered in her shop. The fact that they aren’t able to send data by email, makes me think the collected data might be picked up from outside, through an existing API or security breach.
    Maybe I am just too paranoid, maybe it is ‘just’ Google or another advertiser trying to get more product related data.

    What should I do? What would you do?

    Looking forward for your answers and hints on this. Highly appreciated, best regards,
    -Bj?rn

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support Hannah S.L.

    (@fernashes)

    Automattic Happiness Engineer

    Hey there,

    It sounds like accounts are being created with obviously fake emails, which are erroring when trying to send email to those accounts. This is quite common with WooCommerce shops – I’ve had good luck solving it with Akismet.

    Are these customers making actual orders which are being paid for? If so, which payment gateway is being used?

    Kenin

    (@kbassart)

    Automattic Happiness Engineer

    We haven’t heard back from you in a while, so I’m going to mark this as resolved – if you have any further questions, you can start a new thread.

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Strange Bot Accounts – Friend or Enemy?’ is closed to new replies.