We’ve always had steady leads through our embedded forms but are seeing an increase of spam leads even with ReCaptcha installed.
Our agents have been contacting inbound leads and continously hearing they don’t know who/what we are or how we got their information.
I think there needs to be more protocols in place to reduce the number of spam/bot leads so we can navigate our incoming leads easier.
We’ve had the same problem (about 100 of 200 form submissions last quarter!) and I did a little research using Lucky Orange. The spam submissions aren’t stopped by ReCaptcha because it’s human hackers filling out the form, not bots.
The hackers gain access to compromised devices (usuallly Android mobile running Facebook browser) and then use the devices’ autocomplete to fill out forms. The goal of this hack is to fill up that user’s inbox with spam so that they don’t see fradulent charges on their accounts.
I determined that most of the spam traffic is coming from Google PPC, so my current experiment to mitigate the spam is to remove the direct link to our contact form from our Google ads.
If this plan doesn’t work, I’m going to use javascript to hide the form if the visitor is using a mouse with a mobile device. (An unusual combination, unless you are hacking someone’s phone from a computer.)
We took the same approach and paused our Google Ads for the time being - thanks for the additional info that will definilty help me make a better plan moving forward!