I spent a bit more than a year as the most senior dev on the team that owned the sign up page for a cloud computing company. We faced bot attacks constantly. They had a variety of reasons to attack, but International revenue sharing fraud (IRSF) was a major one. In short, bots would convince our sign up flow to make verification phone calls to numbers that charge a lot of money but don't actually exist. (Note: whatever "why don't you just" you're about to reply with, we had an entire team of people doing nothing but trying to stop this for months and years- we tried that and it didn't succeed, or there were business reasons it was not feasible.)
I switched companies. In my new role, I happened to be on a team in the same org as their sign up page. Chatting with them, I learned that they were not facing similar attacks, but identical ones. The countries involved, the patterns of the attack, everything- this was the same attacker, going up against two completely unrelated companies.
I don't know if this system is the right implementation- I need to do a deeper dive on this- but I do know that something like this is needed so that companies can coordinate their defenses.