Is anyone experiecing an odd spam user attack? Any way to block?

Maybe spam attacks are so pervasive that what’s happening to us is just par for the course.

I believe we use SSO, but it’s limited just to our site. We don’t use any external authentications.

The pattern is very clear

  • they always fill our “Gender” field with a random string of uppper and lower case letters.
  • The username is almost always a “real” sounding first and last name followed by a string of numbers
  • The email used is always some custom domain, usually very unusual looking. Never a popular service

We haven’t adjusted anything with our spam filters. We might get three or four of these per day. Maybe 10 per week or more. So far I have just been deleting them so they haven’t had time to post.

Any ideas?

I’ll share this from a staff member giving advice on how to detect spam accounts

‘Classic “FirstLast1234” email address format’

just typical spam account tactics

maybe that one confuses the AI?

Maybe. In any case I’m glad it does. It’s hard to believe that an AI based bot wouldn’t know the next logical answer to a question about gender, though.