
On a public holiday — exactly when attackers assume no one's watching — an ecommerce client came under a coordinated bot attack on checkout, subscriptions and contact forms. Here's how our team detected it, contained it, and locked it down within hours.
On Good Friday, automated scripts began hammering the client's checkout, newsletter and contact forms simultaneously — timed deliberately for a holiday when most teams are offline.
Bots targeted the checkout flow, the newsletter form and the contact form at once — attempting to trigger fraudulent transactions, flood the subscriber database with fake emails, and disrupt genuine customer communication.
Risk-scoring and invisible bot challenges added to all public forms.
Hidden fields that silently trap and block bot submissions.
Filtering tuned specifically to the attack signatures observed.
Forms rebuilt at the structural level, invalidating the bots' scripts entirely.
Holiday periods are peak windows for bot attacks — attackers assume your team is unavailable. Our response proved that proactive monitoring can neutralise even a multi-vector attack before it causes lasting harm.
Don't wait for an attack to find your vulnerabilities. We offer web security audits, bot protection setup, and ongoing managed security for ecommerce businesses.
Get a Free Security Audit