What are third party created customers

I have just noticed 4 new customers who are “third party created” in my system. I have a very small business, know all my customers- either I make an appointment for them after an email exchange or I get a notification that they have scheduled an appointment for themselves. 

These people have no appointments and I can think of no valid reason for their information to be stored in my system.

I am concerned that there is some funny business going on here, even though I can’t imagine what that might be. 

Over the past 7 years, I’ve never noticed this. Given today’s service disruption, I’m on high alert. What is going on?

7,800 Views
Message 1 of 38
Report
1 Best Answer
Square Community Moderator

Best Answer

Hi everyone,

 

We appreciate everyone bringing this to our attention and your patience while we investigated this further.

We are reviewing your feedback and will be taking action to delete unverified customer profiles from your Customer Directories.  These were created by failed payment attempts, and we do not believe they represent a security issue with your Customer Directory.

 

We’ve also implemented a fix so that customer profiles are only created via Square after a payment is successfully processed. This should reduce the creation of unknown customer profiles. 

Ellie
Community Moderator, Square
Sign in and click Mark as Best Answer if my reply answers your question.

View Best Answer >

6,568 Views
Message 37 of 38
Report
37 REPLIES 37

I still don't understand how they're gaining access to add themselves. The only third party apps I have still connected are "Square Seller Community" and "Square Communities." I guess I'll revoke access to those, too, and see what happens. I'm at a loss, and it's a security issue that I'm not willing to ignore. 

************
TIF HOLMES
FINE ART PHOTOGRAPHY
WWW.TIFHOLMES.COM
3,203 Views
Message 22 of 38
Report

Exactly!!! How are they getting in there and why does nobody care???

3,198 Views
Message 23 of 38
Report

I too am having this issue! The emails are all @example.com We also noticed that one of the fake emails made a purchase of $50 from an item that is no longer available!!! Square doesn't have an answer for this.. very concerning.

3,023 Views
Message 24 of 38
Report

Yikes! It’s just creepy that someone can muck about in our business like this. 

3,014 Views
Message 25 of 38
Report

After multiple emails with Support and multiple phone calls as well. I have a little more understanding on what’s going on with this situation. But I still do not understand it completely. Square has escalated my support ticket and what they are saying is that my donation link is where the third-party customers are coming in. However, I do not have any donations. Other than the eight tickets I have sold personally. on one of the phone calls with Support I was told that the API needs to be checked, although I have no idea what that is. I hope Support can help me more. I will continue to update as I find more information. The customers in my situation have the same first name.last name @Email address. The interesting thing is they are signed up for marketing which I do not have marketing with Square. customer service is actually looking into this for me because they find it odd that the customers are being added by the third-party through this link or back door. Whatever you wanna call it. I’m just concerned about possible fraudulent activity through my account. I have removed third-party access for Massage book. The only other third-party access I have is Linktree and Square go. I think customer support is concerned more so that they are being signed up for marketing unintentionally. Luckily, they took my ticket seriously and hopefully I will have more information soon!

3,191 Views
Message 26 of 38
Report

Wow. What a strange and confounding situation it is. It’s good to know others are recognizing this risk.

3,182 Views
Message 27 of 38
Report

Indeed. I just deleted 68 more fake customers this morning. I've canceled my Marketing subscription with Square and will use a free e-mail list to send out updates instead. I've been researching another web host option as well. Frustrating. 

************
TIF HOLMES
FINE ART PHOTOGRAPHY
WWW.TIFHOLMES.COM
3,164 Views
Message 28 of 38
Report

This has happened to me as well.  My first support outreach to Square went nowhere as the rep said I could "keep them there without issues" and I've tried contacting Square again today as I'm concerned about any fraudulent activity connected to my account; this is definitely an information security issue that needs to be addressed ASAP.  As for how this "3rd party" integration may have occurred, I do have an embedded "pay now" link on my Google Sites webpage and have posted that link on FB and in emails to customers as well, but isn't that something we're supposed to be able to do without negative effect?  Those links are for selling a service, not for "marketing" which is how these customers are categorized.  If I don't get a satisfactory response from Square this time, I'll be taking my business elsewhere.

3,096 Views
Message 29 of 38
Report

It’s just nuts that Square is not concerned about this security breach! We should indeed be able to post pay now links without opening the door to fraud! That’s the whole point, isn’t it? I removed all the links weeks ago, but it’s still happening! Four “new clients” today alone!

I was outraged and disappointed but that sparked my need to take my business elsewhere, and now I’m so happy I did. At least we’re on record for pointing out this security issue. Should anything happen, at least we won’t be in the wrong. 

 

And we won’t be onboard this sinking ship either. 

3,092 Views
Message 30 of 38
Report

Who are you using now? I need someone new also. 

3,049 Views
Message 31 of 38
Report

I found 150 fake users today just by searching for email addresses with example.com. I was curious about how out of control it’s gotten- there are tons of others, but I gave up trying to count. 

3,040 Views
Message 32 of 38
Report

Who are you using? I need to find someone else too because I just don't have confidence in Square any longer.

3,049 Views
Message 33 of 38
Report

I’m using Stripe for credit card processing and Acuity as my online calendar. I’m two months in and things are going really well. 

3,044 Views
Message 34 of 38
Report

Thank you for the info!

3,029 Views
Message 35 of 38
Report

No problem. Hope it helps. 

3,013 Views
Message 36 of 38
Report
Square Community Moderator

Best Answer

Hi everyone,

 

We appreciate everyone bringing this to our attention and your patience while we investigated this further.

We are reviewing your feedback and will be taking action to delete unverified customer profiles from your Customer Directories.  These were created by failed payment attempts, and we do not believe they represent a security issue with your Customer Directory.

 

We’ve also implemented a fix so that customer profiles are only created via Square after a payment is successfully processed. This should reduce the creation of unknown customer profiles. 

Ellie
Community Moderator, Square
Sign in and click Mark as Best Answer if my reply answers your question.
6,569 Views
Message 37 of 38
Report

I appreciate you putting some effort into fixing this issue. However, we already had 1 person make a purchase with a credit card on the "fake account." The purchased an item that we no longer offer, and haven't had it offered for over 5 years. Not sure where they were even able to access a payment option.

2,784 Views
Message 38 of 38
Report