Traffic spikes from Singapore exploiting recommended product URL parameters (Search & Discovery)

I am just wondering if Shopify are aware of bot traffic bombarding their network from Singapore currently? It is affecting thousands of merchants and there appears to be no acknowledgement from Shopify of the issue at all.

There have been numerous recent reports of this in the community forums (example 1 / example 2). There is a lot of other threads from years ago as well. That first example though contains the exact scenario we’re seeing on multiple Shopify stores right now where all of the hits are to product URLs containing every variation of the Search & Discovery parameters.

Shopify isn’t even detecting much of this traffic as bots in Shopify Analytics. They are simulating a real human as best as they can but is essentially an attack and every day, Shopify Analytics is just showing thousands of hits from countries that we don’t even sell to (largely Singapore).

I know there are workarounds such as using a third party app or even writing a script but it is just more bloat-ware being added to our themes.

Surely Shopify can just tackle the problem with Cloudflare? I am just not sure whether this feedback has actually reached anyone in the company that is able to investigate this…

It appears to have been a major issue since the end of last year.

If there is someone at Shopify that can respond so we know if they are dealing (or care) and we can figure out how to move forward because it will take a lot of time to come up with solutions to minimise or fully mitigate ourselves and/or configure analytics systems with segmentation and exclusions etc so that all of our data is not completely skewed.

@Liam-Shopify @Gray-Shopify sorry to tag you guys, not sure how to catch someone’s attention at Shopify :sweat_smile:

@GeoffJacksonAJP we’re getting 6-7k sessions from Singapore per day

However, in our standalone Cloudflare account, its shows around 20 events per day from Singapore. Looks as though the thousands in Shopify are considered non-malicious by Cloudflare (hence why the built-in Shopify Cloudlfare doesnt block them).

However, its causing a huge issue with our LCP stats so affecting our loas times for real customers

We had the same issue with China and USA Bot traffic recently but the separate Cloudflare account solved that but it hasnt worked for Singapore traffic - Im still trying to figure out why

@GeoffJacksonAJP all sorted! Had to change some DNS settings in Cloudflare to make sure it was properly configured to O2O but working now and no more Singapore bots!

@Paul_Vale are you on Shopify Plus? I think that is the only way we can use O2O with another Cloudflare in front of Shopify’s?

We are experiencing this as well, and at this point my concern goes beyond the current spike in Singapore traffic.

I have been raising related bot traffic, analytics, filtering, and reporting limitations with Shopify for months, including directly with our CSM, and I have seen very little meaningful movement.

During one recent spike in traffic from Singapore, our Shopify-reported LCP P75 increased from roughly the low 2-second range to nearly 6.8 seconds at its peak. I have attached a screenshot showing how closely the traffic spike and performance degradation aligned. Correlation alone does not prove that the traffic caused the LCP increase, but it demonstrates how disruptive these events can be to the analytics and performance data merchants rely on.

To Shopify’s credit, the native human/bot classification does appear to identify much of the automated traffic when looking at reports where that dimension is available. However, it is not perfect. I have also seen legitimate customers and actual purchases classified as bot traffic in the past.

The immediate problem is that merchants cannot simply apply that bot filter everywhere it is needed. In particular, Shopify’s Home dashboard can become heavily distorted by bot traffic, yet there is no way to filter it out. This directly affects the high-level metrics that executives and other stakeholders are most likely to see.

Our CSM understands the problem and how these analytics limitations affect our ability to provide accurate and effective executive performance overviews. Despite that, we are increasingly having to look at third-party systems for reporting, executive dashboards, traffic filtering, and potentially bot mitigation.

The dashboard limitations are particularly frustrating. Merchants should be able to build dashboards using custom Shopify reports, apply appropriate filters, and share those dashboards with executives, team members, agencies, consultants, and other authorized third parties. Instead, we are forced to recreate Shopify data elsewhere simply to produce a reliable and shareable executive overview.

I have also considered implementing a Cloudflare O2O configuration to gain greater control over automated traffic, but Shopify explicitly recommends against that approach. This creates a difficult situation for merchants. Shopify discourages putting additional infrastructure in front of the platform, while the native tools for controlling and reporting on unwanted traffic remain limited.

At this point, I would like to see Shopify prioritize:

  • Making the human/bot filter available across Shopify Analytics, especially on the Home dashboard.

  • Improving the accuracy of bot classification so legitimate customers and orders are not incorrectly excluded.

  • Improving platform-level bot mitigation and, where appropriate, challenging suspicious automated traffic.

  • Creating customizable, shareable dashboards where merchants can add their own reports, filters, and executive KPIs.

  • Allowing those dashboards to be securely shared with authorized third parties.

  • Providing more transparency about these recurring traffic patterns and what Shopify is doing to address them.

What is most frustrating is the lack of visible progress or even a broader discussion around these requests. These are not cosmetic analytics features. They directly affect merchants’ ability to understand website performance, report accurately to leadership, and make informed business decisions.

If Shopify does not intend to provide stronger native reporting and bot-management capabilities, merchants at least need clarity about the recommended path forward. Continuing to push merchants toward third-party reporting and traffic-management solutions while discouraging infrastructure-level alternatives does not feel like a sustainable answer.

We are experiencing the exact same issue. I also attached a screenshot in another comment in this thread showing the increase in LCP that coincided with the spike in bot traffic from Singapore.

@Paul_Vale Since implementing Cloudflare O2O, have you noticed any impact on conversions or other legitimate customer activity?

Also, could you clarify how you have Cloudflare configured? For example, are you challenging traffic from Singapore based on certain criteria, or blocking Singapore-based traffic entirely?