I'm having some issues with getting spam donations for public campaigns where I allow non-registered users to donate. Of course, I understand how this can happen by setting it to public without a captcha type system in place.
But I recently got some spam donations after having unpublished all donation modules and forms within content articles. The campaign was still published in the back-end, but there were no published ways for people to donate from the front-end. These donations did not have a campaign or user selected, its as if there is a hole in the code that's allowing direct access to be able to add new donors from the back-end.
Have there been other reports of something like this happening?