The map
| Channel | What automated abuse looks like | Typical protection today |
|---|---|---|
| Personal and shared inboxes | Personalised outreach at scale, impersonation, invoice fraud | Spam filter only |
| Contact and quote forms | Fake leads, SEO and link spam, phishing links, sales pitches disguised as enquiries | A CAPTCHA, often solvable |
| Support queues and chat | Ticket flooding, refund and return fraud, social engineering of agents | Usually none |
| Job applications | Hundreds of AI-written applications per posting, fake candidates | Usually none |
| Reviews and ratings | Fabricated reviews, rating attacks on competitors | Platform moderation, uneven |
| Account sign-up | Fake accounts for free-tier abuse, promotions, later fraud | Email verification, sometimes CAPTCHA |
| Public comment and petitions | Mass fabricated submissions using real people's identities | Minimal |
| Public APIs | Scraping, credential stuffing, resource exhaustion | Rate limits and keys |
| Booking and waitlists | Slots and tickets grabbed by automation and resold | Queues, sometimes CAPTCHA |
Three kinds of damage
Direct fraud
Money leaves: a redirected invoice, a fake refund, a fraudulent account. This is what security budgets are built around, and it is real. The costs in detail.
Volume as damage
Nothing is stolen, but the channel stops working. A recruiter can't find real candidates among a thousand generated applications. A support team spends its day on tickets nobody needed answered. A consultation's comment count says nothing about public opinion. This damage is rarely measured, because nothing shows up as a loss.
Poisoned data
Fake leads distort the sales pipeline, fake reviews distort reputation, fake sign-ups distort growth metrics. Decisions made on that data are wrong in ways that are hard to trace.
Why the soft channels are ignored
Security spending follows breaches, and breaches are measured in money stolen. The channels above mostly lose time and signal instead. They also belong to teams without security budgets: marketing owns the forms, operations owns the shared inbox, HR owns applications. Nobody owns the question "is anyone on the other end a person?"
Match the protection to the question
- Does a person need to be present? Useful for voting, petitions and limited-supply bookings. Needs proof of personhood or hardware attestation.
- Is the sender who they claim? Useful for payments and account changes. Needs authentication, not bot detection.
- Does the sender care enough? Enough for inboxes, forms, applications and support. A small refundable cost answers it without identifying anyone.