SKevo Another question is whether its appropriate to forcefully enable hCaptcha for all forums? I was thinking that I could send out an e-mail for all forum owners and encourage them to turn on anti-spam extensions too, which is probably better, but this wouldn't ensure 100 % anti-spam coverage, as not everyone would enable the extensions. I will make a decision today, and honestly I am leaning towards sending out an informational e-mail...
I agree with an informational e-mail, plus some advice to owners to check their user numbers regularly and their admin panels. My advice would be to recommend:
Anti spam protection is turned on (FOF Stop Forum Spam)
first post approval (so new users require approval of 1st post/discussion)
Auto moderator (with new user and user promotion parameters) to work with above
No e-mail verification (pointless for this attack, makes the problem worse)
Definitely implement hCaptcha
It's broadly what I do and my latest addition hCaptcha has reduced the problem to zero, hopefully with minimal server impact..
In addition I strongly recommend that if people use simplelogin anonymous e-mail service, or a similar service to be able to receive e-mails from other members, their signature contains "contact me"a link to their bio, where the simple login alias is stored. Then make user bios only visible by automoderated members who have been promoted from "new user" to "user".