The problem

The unprotected channel map: every door strangers can knock on

Most organisations protect their login page and nothing else. Here is every inbound channel that accepts input from strangers, what abuse looks like on each, and how exposed it usually is.

INBOXESSpam filter onlyFORMSSolvable CAPTCHASUPPORTUsually noneAPPLICATIONSUsually noneREVIEWSModeration, unevenSIGN-UPSEmail checkCOMMENTSMinimalAPISRate limits, keysBOOKINGSQueues, CAPTCHA
Typical protection today. Red: little or none.

The map

ChannelWhat automated abuse looks likeTypical protection today
Personal and shared inboxesPersonalised outreach at scale, impersonation, invoice fraudSpam filter only
Contact and quote formsFake leads, SEO and link spam, phishing links, sales pitches disguised as enquiriesA CAPTCHA, often solvable
Support queues and chatTicket flooding, refund and return fraud, social engineering of agentsUsually none
Job applicationsHundreds of AI-written applications per posting, fake candidatesUsually none
Reviews and ratingsFabricated reviews, rating attacks on competitorsPlatform moderation, uneven
Account sign-upFake accounts for free-tier abuse, promotions, later fraudEmail verification, sometimes CAPTCHA
Public comment and petitionsMass fabricated submissions using real people's identitiesMinimal
Public APIsScraping, credential stuffing, resource exhaustionRate limits and keys
Booking and waitlistsSlots and tickets grabbed by automation and resoldQueues, sometimes CAPTCHA

Three kinds of damage

Direct fraud

Money leaves: a redirected invoice, a fake refund, a fraudulent account. This is what security budgets are built around, and it is real. The costs in detail.

Volume as damage

Nothing is stolen, but the channel stops working. A recruiter can't find real candidates among a thousand generated applications. A support team spends its day on tickets nobody needed answered. A consultation's comment count says nothing about public opinion. This damage is rarely measured, because nothing shows up as a loss.

Poisoned data

Fake leads distort the sales pipeline, fake reviews distort reputation, fake sign-ups distort growth metrics. Decisions made on that data are wrong in ways that are hard to trace.

Why the soft channels are ignored

Security spending follows breaches, and breaches are measured in money stolen. The channels above mostly lose time and signal instead. They also belong to teams without security budgets: marketing owns the forms, operations owns the shared inbox, HR owns applications. Nobody owns the question "is anyone on the other end a person?"

Match the protection to the question

  • Does a person need to be present? Useful for voting, petitions and limited-supply bookings. Needs proof of personhood or hardware attestation.
  • Is the sender who they claim? Useful for payments and account changes. Needs authentication, not bot detection.
  • Does the sender care enough? Enough for inboxes, forms, applications and support. A small refundable cost answers it without identifying anyone.

The five approaches compared.

Sources

  1. Thales Imperva, 2026 Bad Bot Report: Bad Bots in the Agentic Age
  2. New York Attorney General, Fake Comments: How U.S. Companies & Partisans Hack Democracy (2021)
  3. FBI Internet Crime Complaint Center, 2025 IC3 Annual Report