Hi Marketo Community,
Our company has been receiving a lot of spam leads on Salesforce. All the leads have gibberish names and specific fieId types filled out with links.
On Salesforce, it looks like it was entered in by one of our members because the"Created By" field shows a name and a time during odd-hours. When I circle back to Marketo on that specific lead, the first piece of information is "New Person... Source: SFDC". It seems like our account has been hacked or something.
We do have a lot of Marketo forms, but the spam leads are filling out fields that are not in any of our forms (that I know of). One custom field type that remains consistent across all the spam leads is "how did they reach us" which is always entered in as "web form". Is there a way to trace back all of our forms that sync to Salesforce as "web form" for the "how did they reach us" field?
I'm not sure how to proceed with this and hopefully someone on this community can help me out.
Thank you!
Check for an active Web-2-Lead form in Salesforce. The most likely culprit. And even if the form isn't visible on any pages, the form endpoint will still accept posts.
Hey Sanford,
Thanks for your response.
I looked at our settings in SF for web-to-lead form. The settings show "The user who will be listed as Creator when a Lead is created online" as the user we see inputting leads during odd hours. That means it has to be through a form.
But it's weird because on all the activity logs of the spam leads show as created on SFDC.
It doesn't seem weird to me. It seems to be working like it should.
1. The spam lead comes in through the Web2Lead form.
2. The lead is created in SFDC by the "The user who will be listed as Creator when a Lead is created online".
3. SFDC then syncs the user to Marketo and the activity log in MKTO is updated with the New person from SFDC details.
4. There is no filled out form activity on the Marketo side because the filled out form activity was through a SFDC form.
Best,
Hey there.
If the first thing on the activity log is a new person entry from SFDC, then they didn't come in to Marketo through the form fill.
Is there a form fill on the activity log for the spam leads?
Are the spam leads in SFDC being created by your Marketo sync user?
Hey Jaime,
Thanks for your response. No there's no form fill on the activity log of the spam leads.
Spam leads are not being created by Marketo Sync, it's being created by one of our team member's account.
I looked at our settings in SF for web-to-lead form. The settings show "The user who will be listed as Creator when a Lead is created online" as the user we see inputting leads during odd hours. That means it has to be through a form.
But it's weird because on all the activity logs of the spam leads show as created on SFDC.
What's weird though? It means somebody's hitting your W2L.
