Bad Bot Traffic Outpaces Human Growth by Ninefold, DataDome Report Finds

Malicious automated traffic is expanding at a rate that dwarfs human activity on the web, according to a new study from cybersecurity firm DataDome. The report reveals that between July 2025 and June 2026, bad bot traffic surged by 124%, a pace nine times faster than the growth of legitimate human traffic during the same period. Meanwhile, traffic identified as originating from AI systems climbed by more than 82%, underscoring how rapidly automation is reshaping the internet's underlying traffic patterns.

The findings come from an analysis of over one trillion requests across more than 75,000 customer websites, making it one of the most extensive examinations of bot activity to date. The data paints a picture of an online ecosystem where automated agents are not only multiplying but also probing deeper into the sensitive areas of websites that handle user accounts, transactions, and personal information.

The report highlights a fundamental shift in the nature of web traffic. While human users navigate the internet at a relatively steady pace, automated scripts and AI-driven agents are multiplying at an unprecedented rate. This surge is not merely a nuisance; it represents a systemic challenge to the security and integrity of online services.

Scraping and Scalping Surge

Among the most striking trends is the explosion of scraping activity, which increased by more than 185% year over year. Bots designed to extract content, pricing data, and other information from websites are becoming more aggressive and sophisticated. In addition, bots engaged in scalping—the practice of snapping up tickets or other high-demand items for resale—operated at nearly three times the rate seen in the previous year. This suggests that automated tools are increasingly being weaponized to gain unfair advantages in consumer markets.

Perhaps most concerning to security professionals is the finding that AI bots are now targeting login pages at eight times the rate they did when DataDome conducted its 2025 report. This shift indicates that automated traffic is no longer content to skim the surface of the web; it is moving into the core flows that define the customer journey.

AI Agents and the Concentration of Bot Power

During the study period, DataDome detected 52.7 billion crawler requests originating from AI agents and large language models. A striking concentration emerged in who is dispatching these bots: Meta-affiliated systems accounted for more than 46% of the total, while OpenAI was the second-busiest source, responsible for nearly 35%. This dominance by a handful of major technology companies highlights how central AI development has become to the broader bot traffic landscape.

Jérôme Segura, vice president of threat research at DataDome, emphasized that the nature of the problem is evolving. He explained that automated traffic is no longer just a volume problem at the edge of the internet. Instead, it is growing quickly and moving deeper into the login, account, and transaction flows that sit at the center of the customer journey. For businesses, he said, the challenge is no longer simply identifying automation; it is determining whether that activity is beneficial or harmful.

A Protection Gap Widens

Despite the rising threat, many websites remain woefully unprepared. DataDome tested 20,000 websites and discovered that 65.3% had no protection whatsoever against the ten bot types included in the study. Only 2.4% of sites were fully protected—a significant drop from 8.4% in 2024 and slightly below last year's 2.8%. This decline suggests that as bot tactics advance, defensive measures are struggling to keep pace.

Segura warned about the downstream consequences of this vulnerability. He noted that automated traffic is moving into sensitive parts of the customer journey. Login pages, account-creation flows, carts, and payment endpoints connect directly to customer accounts, personal information, inventory, promotions, and transactions. Abuse at these endpoints can lead to a cascade of problems, including credential testing, account takeover, card testing, inventory abuse, promotion abuse, and fraudulent transactions.

What Businesses Can Do

The report's findings suggest that organizations need to rethink their approach to bot management. Traditional defenses that focus only on blocking high-volume attacks at the network edge may no longer be sufficient. Instead, companies must adopt strategies that can distinguish between beneficial automation—such as search engine crawlers or AI assistants that drive legitimate traffic—and malicious bots that seek to exploit vulnerabilities.

One of the key takeaways is that not all bots are malicious. Search engine crawlers, for example, play a vital role in indexing the web, and AI assistants can drive valuable traffic to websites. The challenge lies in distinguishing between these legitimate actors and those with harmful intent. A nuanced approach that combines technology, policy, and continuous adaptation is essential.

  • Deep inspection: Monitor login, account creation, and payment flows for signs of automated abuse, not just homepage traffic.
  • Behavioral analysis: Use machine learning to identify patterns that differentiate human users from bots, even when bots mimic human behavior.
  • Rate limiting and challenges: Implement adaptive rate limiting and CAPTCHA-style challenges at critical endpoints to slow down automated attacks.
  • Continuous monitoring: Regularly audit website protection levels and update defenses as bot tactics evolve.

The Road Ahead

As AI capabilities continue to expand, the line between helpful and harmful automation will only blur further. The DataDome report makes clear that bot traffic is not a static problem but a rapidly accelerating one. With bad bots growing nine times faster than human traffic and AI agents increasingly targeting the most sensitive parts of the web, businesses that fail to adapt may find themselves overwhelmed by an invisible army of automated actors.

The coming years will likely see increased regulatory attention on bot activity, as well as greater collaboration between cybersecurity firms and platform providers. For now, the data serves as a stark warning: the internet's automated underbelly is growing stronger, deeper, and more consequential than ever before.

This article is based on reporting by Fast Company. Read the original article.

Originally published on fastcompany.com