It appears we had a data breach in 2020 and there are over 18K fake accounts in out systems all having "name@example.com as an email address. Has this happened to anyone else and if so, what steps can be taken to purge those accounts out of system?
Thank you for your help,
Jason
Hi Jason,
We had a similar thing happen to one of our consortium organizations a little over a year ago, so I feel your pain! The fraud event resulted in almost 8,000 records with dummy emails and address info and approximately $2,500 in small fraudulent donations. It was essentially a credit card testing scheme that exploited the org’s low minimum contribution amount on one of their donation pages.
Everyone's suggestions so far sound right on the money. We enforce reCAPTCHA in all available locations on our org’s TNEW sites, but somehow, they were able to get around it for some transactions. I forget the exact numbers, but if that wasn’t configured, we could have easily seen double or triple the number of fraudulent accounts created, so it’s definitely good to have that in place.
Here are the broad steps for what we did in terms of cleanup:
Thank you so much for this. I/we greatly appreciate you and everyone else's time in helping us out with this.
-Jason