Skip to main content
Contributor I
September 2, 2026
Solved

HELP! Spam profiles being added to account

  • September 2, 2026
  • 2 replies
  • 105 views

There have been about 900 fake profiles added to my account.  They are starting a checkout on a product that isn’t available for purchase. There is no information on most of the profiles other than the email and it shows that they started a checkout for a necklace chain (which isn’t for sale). When this started last December Shopify hid the item but it has begun happening again. I created a segment to suppress the profiles but I keep getting emails from Klaviyo about being over the limit. How do I stop these profiles from being added to my account and get rid of the fake profiles that have been added to my account?

 

 

Best answer by Temi O.

Hi there ​@GodFirst2017

This sounds consistent with automated checkout activity coming through Shopify. Checkout activity can create profiles with only an email address, even when the checkout does not result in a completed order.
 

For the profiles already added, I’d recommend suppressing them rather than only deleting them. A segment by itself will not reduce your active profile count, and bulk suppression applies only to the profiles currently in that segment, so newly added profiles would need to be addressed separately. Suppressed profiles cannot receive marketing emails and do not count toward your email plan limit. You can find the steps here: How to manage email suppressions and delete profiles in bulk.
 

To help prevent more from being created, I’d also check Shopify’s CAPTCHA, bot filtering, and any fraud-prevention or checkout apps. Since the activity has returned after the product was hidden, Shopify Support may need to review the checkout sessions and webhooks to identify what is generating them. Klaviyo’s guide on list bombing and removing fake profiles has additional mitigation steps.

I hope this is helpful! 

 


Temi@Klaviyo

2 replies

Temi O.
Community Manager
Temi O.Answer
Community Manager
September 3, 2026

Hi there ​@GodFirst2017

This sounds consistent with automated checkout activity coming through Shopify. Checkout activity can create profiles with only an email address, even when the checkout does not result in a completed order.
 

For the profiles already added, I’d recommend suppressing them rather than only deleting them. A segment by itself will not reduce your active profile count, and bulk suppression applies only to the profiles currently in that segment, so newly added profiles would need to be addressed separately. Suppressed profiles cannot receive marketing emails and do not count toward your email plan limit. You can find the steps here: How to manage email suppressions and delete profiles in bulk.
 

To help prevent more from being created, I’d also check Shopify’s CAPTCHA, bot filtering, and any fraud-prevention or checkout apps. Since the activity has returned after the product was hidden, Shopify Support may need to review the checkout sessions and webhooks to identify what is generating them. Klaviyo’s guide on list bombing and removing fake profiles has additional mitigation steps.

I hope this is helpful! 

 


Temi@Klaviyo

Nanette
Problem Solver I
Problem Solver I
September 16, 2026

I’ve had similar profile activity using the “...@inbound.godigitalpigeon.com” domain. They show as “Subscribed to Newsletter” via public API, but we have no such connections, and the source names shown in these profiles don't exist. Because they didn’t actually sign up using a legitimate form, they aren’t added to our lists, nor do they enter flows - they just sit in our profile history.

 

What’s interesting is that they leave zero footprints in WooCommerce or our website connection history. It seems these spambots are bypassing our user-facing website forms entirely. Instead, they are operating completely from the outside, I’m guessing using scripts to send automated POST requests straight to Klaviyo's public API endpoints.

 

@Temi O., I read through the guide you included in your response and am wondering if these bots fake profiles are completely bypassing our frontend code to hit the API directly, would adding a honeypot field to our embedded website forms even be effective? Otherwise, is there a way we can actually lock this down from Klaviyo's side to stop these direct API injections?

 

(Sorry, ​@GodFirst2017 ...I didn’t mean to hijack your post. 😏)

Nanette Gauny - Founder & Pleasure Curator at Taboodoir, Artisan Bath and Body Skincare | taboodoir.com