Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

How to stop spam and bot attacks on Adobe Commerce Cloud

Fake registrations, newsletter spam and card testing on Adobe Commerce Cloud — how to detect them and block them with Fastly WAF, reCAPTCHA and rate limits.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·9 min read
QUICK ANSWER

Fake registrations, newsletter spam and card testing on Adobe Commerce Cloud — how to detect them and block them with Fastly WAF, reCAPTCHA and rate limits.

KEY TAKEAWAYS
✓Most Adobe Commerce spam targets customer registration, newsletter, contact and checkout endpoints.
✓Adobe Commerce Cloud includes Fastly — use its WAF and rate limiting before adding plugins.
✓Enable Google reCAPTCHA v3 on every public form in the Magento admin.
✓Card-testing attacks need gateway-side rules too, not just front-end protection.

Signs your store is under a spam attack

Spam attacks rarely take a store offline, so they often go unnoticed until something else breaks — your email provider flags bounces, your payment gateway warns about declined transactions, or your CRM fills with gibberish accounts.

  • Hundreds of new customer accounts with random names or Cyrillic/Chinese characters
  • Newsletter sign-ups from disposable email domains
  • Spikes of $0–$1 authorisation attempts in your gateway (card testing)
  • Contact-form messages full of links
  • High traffic to /customer/account/createpost or /newsletter/subscriber/new
RELATED GUIDEWordPress security checklist: 15 steps to protect your site in 2026 →

Step 1: Turn on reCAPTCHA for every public form

Adobe Commerce ships with Google reCAPTCHA support. In the admin go to Stores → Configuration → Security → Google reCAPTCHA Storefront and enable reCAPTCHA v3 (invisible) for customer create, login, forgot password, newsletter, contact, product reviews, PayPal PayFlow and place order.

Use v3 “invisible” where you can — it scores traffic without showing a puzzle to real customers, so conversion is not affected.

Step 2: Use Fastly WAF and rate limiting

Every Adobe Commerce Cloud project includes Fastly CDN, and Pro plans include the Fastly Next-Gen WAF. Rules at the edge stop bots before they reach PHP, which also protects your server capacity during an attack.

  • Rate-limit POST requests to registration, newsletter and checkout endpoints
  • Block or challenge known bad ASNs and data-centre IP ranges
  • Use Fastly Edge ACLs to block repeat offenders
  • Add geo rules if you only sell in certain countries
Under attack right now?Our engineers can stop an active spam or card-testing attack on Adobe Commerce Cloud today.Get emergency help →

Step 3: Stop card testing at checkout

Card testing is the most expensive form of spam: fraudsters use your checkout to validate stolen cards, and your gateway may suspend your account. Combine platform and gateway defences.

  • Enable reCAPTCHA on “place order” and payment methods
  • Turn on your gateway’s fraud tools (Stripe Radar, Adyen RevenueProtect, Braintree Advanced Fraud)
  • Require a minimum order value for guest checkout during an attack
  • Alert on unusual numbers of failed payments per hour

Step 4: Clean up the damage

Once the attack is blocked, remove fake customers and subscribers so they don’t damage email deliverability or skew analytics. Export suspicious accounts by creation date and email domain, review, then delete in bulk. Re-check your email platform list and suppress disposable domains.

Step 5: Monitor so it doesn’t happen again

Set alerts for new-account spikes, failed payments and 4xx/5xx rates in New Relic (included with Adobe Commerce Cloud). Review Fastly WAF logs weekly for the first month after an attack.

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get emergency help →Free · No obligation · Reply within 24 hours

Frequently asked questions

Does Adobe Commerce Cloud include a WAF?

Yes. Adobe Commerce Cloud Pro includes the Fastly Next-Gen WAF, and all Cloud projects include Fastly CDN with configurable rate limiting and edge ACLs.

Will reCAPTCHA hurt conversion?

reCAPTCHA v3 is invisible to most users and rarely affects conversion. Avoid v2 checkbox challenges on checkout.

How do I know if I am being card-tested?

Look for many small or failed authorisations from different cards in a short time, often with the same IP ranges or email patterns.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINWordPress security checklist: 15 steps to protect your site in 2026Read →SECURITY · 8 MINMagecart and card skimming: how to protect your checkoutRead →SECURITY · 7 MINMy website has been hacked — what should I do?Read →
FREE · NO OBLIGATION

Under attack right now?

Our engineers can stop an active spam or card-testing attack on Adobe Commerce Cloud today.

Get emergency help →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.