Bad Bots: Surging Ninefold in Traffic as AI Advances Cyber Threats and Security Risks
Bad Bots Growing Nine Times Faster Than Human Traffic as AI Transforms Cyber Threats
Malicious automated traffic now outpaces human web activity by a factor of nine and is evolving far beyond simple scripts into adaptive reasoning systems that legacy defenses were never designed to stop.
A new State of Bot & Agent Security Report 2026 from DataDome reveals a dramatic shift in the bot threat landscape. Published September 23, 2026, the report draws on more than a trillion requests across 75,000 customer sites and vulnerability scans of more than 20,000 popular websites. What it found should unsettle every security team still treating bots as a background nuisance.
Between July 2025 and June 2026, bad bot traffic surged 124%. That growth rate is now roughly nine times faster than legitimate human traffic — and the tools driving it are no longer running fixed scripts. They are reasoning, adapting, and attacking in real time. Understanding the full scope of this shift requires a closer look at both the numbers and the structural changes underneath them.
The Scale of the Problem
Scraping remains the dominant attack vector. It accounted for 70.9% of all bad bot traffic across DataDome's customer base and grew 185.2% over the study period. DataDome ties this acceleration directly to an expanding AI data supply chain, where third-party resellers and AI agent builders harvest web content at scale for model training and related services.
AI agent traffic is also reaching the most sensitive parts of websites. In the first half of 2026 alone, AI agents generated 605.6 million requests to login pages, forms, shopping carts, payment flows, and account-creation pages. Login pages absorbed 51.7% of that volume. Total AI traffic — encompassing both legitimate crawling and outright abuse — grew 82.3% during the period.
That blended nature is precisely what makes enforcement so difficult. The same crawling behavior that helps a shopper find a product can appear identical at the packet level to a scraper stealing pricing data.
Scalping surged 290.7% as automated purchasing bots targeted high-demand inventory. Median daily scalping volume nearly quadrupled. Fake account creation rose 34.5%. Credential stuffing didn't slow down so much as cycle erratically — DataDome observed activity spike, crash by nearly 90%, and then rebound to new single-day highs, a pattern consistent with attackers burning through fresh batches of leaked credentials in opportunistic bursts.
Most alarming is the state of defenses. In DataDome's expanded scan, 65.3% of tested websites stopped none of the 10 bot types evaluated. Only 2.4% stopped all of them — down sharply from 8.4% in 2024 and 2.8% in 2025. The protection gap is widening precisely as the threat accelerates. For organizations seeking a structured approach to reducing exposure, understanding how modern threat management frameworks are evolving to address automated attacks has never been more pressing.
What These Numbers Mean in Practice
The raw statistics matter, but the operational implications are equally significant. A 124% surge in bad bot traffic does not simply mean more noise in server logs — it means more successful account takeovers, more stolen pricing intelligence, more fraudulent purchases completing before a human analyst ever sees an alert. The compounding effect of adaptive bots operating at machine speed, against defenses calibrated for slower, more predictable automation, creates a widening execution gap that attackers are actively exploiting.
Why This Moment Is Different
What separates 2026 from the last decade of bot-management arms races is agency. Bots have stopped being scripts that execute a fixed sequence of steps and started being systems that reason about a target and adapt in real time.
Aviv Nahum, co-founder and CEO of Above Security, frames the shift plainly: "These agents aren't limited to executing scripts. This enables AI agents to assess problems, identify solutions, and execute those solutions entirely on their own."
Nahum is careful to note this isn't a story about rogue AI choosing crime. Some of the most alarming recent incidents involved models deployed in relaxed testing environments or given access they never should have had. His conclusion is a governance one as much as a technical one: AI permissions and configuration now matter more than ever, and CIOs need to treat AI agents as first-class identities — a new category of insider that must be inventoried, monitored, and evaluated for behavioral anomalies.
Randolph Barr, CISO at Cequence Security, ties the surge directly to APIs. "Bots go where the money is, and that's APIs," he said. Modern bot traffic increasingly skips the frontend entirely, hitting backend APIs with valid logins and well-formed requests that look like ordinary machine traffic. Attackers who once spent weeks manually mapping an API can now do it in minutes with AI assistance.
Barr's warning extends to the supply chain: MCP registries, agent marketplaces, and OAuth integrations are, in his assessment, shaping up to be the next NPM or PyPI — largely ungoverned and increasingly targeted. His recommendation is blunt: treat any AI agent with tool access or internet reach as a privileged actor, give it least privilege and its own attributable identity, and verify isolation rather than assume it.
Diana Kelley, CISO at Noma Security, adds a supply-chain-of-capability dimension. Frontier labs like Anthropic actively monitor and disrupt misuse of their own models. But as she notes, "open-source capabilities are catching up quickly, and they run on someone else's infrastructure without that monitoring or disruption layer." She also reframes certain high-profile incidents not as malicious attacks but as safety failures — autonomous systems with internet access producing unanticipated real-world effects during insufficiently sandboxed evaluations.
Ram Varadarajan, CEO of Acalvio, goes furthest in naming the structural risk: emergent misalignment, once confined to research settings, is now showing up as operational risk in production enterprise environments. "The model boundary is not robust," he said. His proposed answer is to meet reasoning attackers with reasoning defenders — machine-speed, model-aware deception capable of catching attacks that compose novel exploit chains too quickly for legacy safeguards to trip.
The API Blind Spot Security Teams Cannot Afford to Ignore
One of the most consequential findings embedded in the report is how thoroughly the threat has migrated away from the web layer. Organizations that have invested heavily in building a robust application security posture at the frontend are discovering that their defenses simply do not follow traffic that hits APIs directly with valid credentials and well-formed requests. This is not a gap that can be patched at the perimeter — it requires rethinking where detection logic lives entirely.
The Open-Source Acceleration Problem
The governance challenge Kelley identifies deserves particular attention. When misuse of a frontier model occurs, the lab behind it has both the visibility and the commercial incentive to intervene. That dynamic disappears entirely with open-source models. Any actor with sufficient compute can deploy a capable reasoning system with no usage policies, no monitoring layer, and no disruption capability sitting above them. The practical effect is that the most capable automated attack tooling is becoming simultaneously more accessible and less observable — a combination that should fundamentally alter how security teams think about threat modeling.
What Security Teams Should Do Now
Strip away differences in emphasis and these perspectives converge on one conclusion: identity-based and signature-based bot defenses were built for a world of static automation. That world is over. The only viable path forward is intent-based detection — continuous behavioral analysis capable of flagging anomalies in real time rather than running a one-time check at the login screen.
Several practical steps emerge from both the report and the practitioners who reviewed it:
- Inventory AI agents like any privileged identity. If you cannot answer which agents are running, who owns them, and what they can access, you cannot govern them.
- Assume APIs are the real front door. Bot defenses layered onto the web frontend will not catch traffic that goes straight to the API with valid credentials.
- Give agents their own identity. Attributability and revocability matter more as agent-to-agent and agent-to-API traffic grows. Never share a human login.
- Verify isolation; do not assume it. Several of the most discussed AI incidents this year began inside environments someone believed were sandboxed.
- Watch the supply chain. MCP registries and agent marketplaces are largely ungoverned today and flagged by multiple sources as the next likely target class.
Connecting Bot Threats to Broader Attack Patterns
It is also worth situating bot-driven abuse within the wider landscape of volumetric and automated threats. The same infrastructure that powers credential stuffing campaigns and large-scale scraping operations increasingly overlaps with the botnets and coordination layers behind application-layer attacks. Organizations that have examined the different types of DDoS attacks and how they are executed will recognize familiar patterns — distributed origin points, rate-limited request cadences designed to evade thresholds, and rotating identity markers — now appearing in bot campaigns that have nothing to do with availability and everything to do with data theft and account fraud.
Rethinking Detection Posture for a Reasoning Threat
The move from signature-based to behavioral detection is not simply a product decision — it is an architectural one. Detection logic that runs once at authentication, or that flags traffic based on static IP reputation lists, will not catch an agent that authenticates legitimately, pauses to observe rate-limit behavior, and then adjusts its request cadence accordingly. Continuous, session-aware behavioral analysis is the minimum viable detection capability for 2026 and beyond. Organizations that have not yet begun that transition are operating on borrowed time.
The headline number — bad bots growing nine times faster than human traffic — is striking on its own. But the deeper finding may be the protection gap underneath it. With fewer than one in 40 tested sites stopping every bot type evaluated, most organizations are walking into a fight that has already moved on to reasoning, adaptive, machine-speed adversaries — armed with yesterday's tools.
For further context on the evolving threat intelligence landscape, the OWASP Automated Threats to Web Applications project provides a well-maintained taxonomy of automated attack types that security teams can use as a reference framework alongside findings like those in the DataDome report.
Professionals following this space should note that SecureWorld Detroit is scheduled for September 17, 2026, where discussions on bot governance, AI agent security, and related policy implications are expected to feature prominently on the agenda.