We're getting a lot of spammy user registrations on our custom user registration form. Luo suggested I set up an email alert to notify me when someone uses the form, but I must have set it up incorrectly, since it wasn't triggered, and I thought the regs must be coming from another place. After checking, though, I fixed the form, and it turns out that all of the spammy registrations ARE coming from our registration form, even though we have a CAPTCHA set up on it -- I've started receiving emails when these registrations take place, and they're all coming from the form.
Our registration page is here: hidden link
I'm not sure how they're getting around the CAPTCHA, though I do know Toolset doesn't use the newer versions of Google's reCAPTCHA which I wish I could try. It's not feasible for our use case to manually approve each registration at this stage, and I'm hoping to figure out how these bulk registrations are happening, and how our CAPTCHA is being bypassed.