AI News Feed
Market watch
Cybersecurity

DataDome Report Finds Malicious Bot Traffic Growing Nine Times Faster Than Human Traffic

A new DataDome report says malicious automated traffic rose 124% from July 2025 to June 2026, more than nine times the growth of human traffic, while 65.3% of 21,491 popular websites tested blocked none of the ten bot types thrown at them.

The findings come from the 2026 edition of DataDome's State of Bot & Agent Security Report, which draws on more than a trillion requests across more than 75,000 customer sites, alongside a June test of 21,491 popular websites. Scraping dominated the bad bot mix at 70.9% of traffic and was up 185.2% over the year. DataDome attributes part of that growth to third-party data resellers and agent builders harvesting the web at scale for model training, activity that does not always identify itself as an artificial intelligence crawler.

Scalping, the use of bots to buy up limited inventory for resale, rose 290.7%, with median daily volume close to quadrupling, and fake account creation was up 34.5%. Distributed denial-of-service attacks grew 39.9% and peaked above 2 billion requests in a single day in April, making them the second-largest category at 12.7% of bad bot traffic.

Credential stuffing was flat on the year. DataDome calls that pattern cyclical rather than fading, since volume surged through the summer of 2025, collapsed by nearly 90% and then reached new single-day highs by April.

AI traffic grew 82.3% over the same 12 months. DataDome logged 52.7 billion AI agent and crawler requests across its customer base, with Meta-affiliated bots generating 46.3% of the identified total and OpenAI-affiliated bots 34.6%. Of the 29.02 billion AI bot requests logged in the first half of 2026, 97.9% still went to homepages and other general content.

The remaining 2.1% is where the change shows up. AI agents sent 605.6 million requests to login, form, cart, payment and account-creation pages between January and June, and login pages took 51.7% of that, against 23% a year earlier. Monthly login-page volume from AI bots ran from 11.9 million requests in January to 99.7 million in June.

Jerome Segura, vice president of threat research at DataDome, said automated traffic is growing fast and moving into the login, account and transaction flows at the center of the customer journey. Identifying automation is not the hard part anymore, he said. The harder question is whether a given session is beneficial or harmful.

DataDome's website test ran in June, sending 10 bot types at 21,491 sites across 15 industries from residential addresses in the U.S., Canada and France. Nearly two in three sites, 65.3%, stopped none of them, and the share reaching full protection has fallen two years running, to 2.4% from 8.4% in 2024, though this year's test added harder bot types. Telecommunications sites were the weakest, at 82.9% unprotected.

Spoofed AI agents walked past more than seven sites in 10. DataDome calls identity-based trust a widespread weakness, since a request claiming to be GPTBot, ClaudeBot or another trusted crawler is often let through on the name alone. Only 5.5% of sites caught the test's disguised bot, which forges the network fingerprint of a real browser.

Most of the defenses in use are still largely built around binary choices, Segura said, even as the calls organizations have to make get finer. The critical test, in his view, is whether a site can separate a legitimate AI assistant from a credential-testing bot or an account-abuse campaign. Blocking everything would also cut off beneficial activity, he added.

Editor's Summary

DataDome's 2026 State of Bot & Agent Security Report records a 124% rise in malicious automated traffic over the year to June 2026, with scraping accounting for 70.9% of it and AI agent requests increasingly aimed at login pages. A June test of 21,491 sites found 65.3% blocked none of ten bot types, and only 2.4% reached full protection. The vendor argues that distinguishing useful automation from abuse, rather than simply detecting bots, is now the central problem for site operators.