DataDome Report Highlights 9x Faster Growth in Malicious Automated Traffic

DataDome Report- Malicious Automated Traffic Is Growing 9x Faster Than Human Traffic — and Targeting Deeper Into the Customer Journey
🕧 7 min

More than half of AI traffic now hits high-value login pages, but 65% of websites still have zero protection

DataDome, the leader in bot and agent trust management, released The State of Bot & Agent Security Report, 2026 Edition, an analysis of more than one trillion requests across 75,000+ customer sites and a test of more than 20,000 popular websites.

Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA

Malicious automated traffic grew more than nine times faster than human traffic between July 2025 and June 2026, with bad bot traffic increasing 124%. Scraping remained the leading threat, rising 185% year over year. At the same time, AI bots are moving beyond just crawling homepages, targeting login pages 8x more. Yet most websites are not prepared. The external website tests revealed that 65% were completely unprotected against bots.

“Automated traffic isn’t just a volume problem at the edge of the internet anymore. It’s growing fast, and it’s going deeper: into the login, account, and transaction flows at the center of the customer journey,” said Jerome Segura, VP of Threat Research at DataDome. “For businesses, the challenge is no longer simply identifying automation; it is determining whether that activity is beneficial or harmful.”

Key findings:

  • Bad bots are growing 9x faster than human traffic. Bad bot traffic increased 124% over 12 months.
  • Scraping is the largest and fastest-growing attack vector. It accounted for 70.9% of bad bot traffic across DataDome’s customer base and increased 185.2% during the study period. The growth may be connected to an expanding AI data supply chain, in which third-party data resellers and applications building AI agents collect web data at scale for training and other AI services.
  • AI traffic is reaching high-value user journeys. In H1 2026, AI agents generated 605.6 million requests to login pages, forms, carts, payment flows, and account-creation pages, with login pages accounting for 51.7% of that traffic. Total AI traffic increased 82.3% during the study period, bringing more automated traffic into the mix, including both beneficial and harmful activity. The same crawling that can help users discover products and information can be difficult to distinguish from unwanted scraping, particularly when it reaches these high-value endpoints. Identity-based controls cannot make that distinction, so businesses need to evaluate what each session is trying to do.
  • Scalping activity increased 290.7%. Median daily volume nearly quadrupled, putting continued pressure on businesses to protect high-demand inventory and purchase flows from automated abuse.
  • Account-related abuse is increasing across several attack paths. Fake account creation grew 34.5%. Credential stuffing remained cyclical rather than declining, with activity surging, dropping by nearly 90%, and later recovering to new single-day highs. This pattern suggests attackers are opportunistically leveraging batches of leaked credentials.
  • Most websites remain unprotected against bots and AI agents. In the expanded scan, 65.3% of tested websites stopped none of the 10 bot types evaluated. Only 2.4% stopped all of them, down from 8.4% in 2024 and 2.8% in 2025.

Taken together, these findings point to a widening gap between the traffic businesses need to understand and the defenses they have in place. As automated systems move through the same login, account, and transaction flows as human users, intent becomes the critical signal for deciding what to allow and what to stop.

Also Read: IT Tech Pulse Exclusive Interview with Michael Jack Chief Revenue Officer and Co-Founder of Datadobi

“Organizations are being asked to make more nuanced decisions with defenses that are still largely built around binary choices,” added Segura. “The ability to distinguish a legitimate AI assistant from a credential-testing bot or an automated account-abuse campaign will be critical to protecting customers without blocking beneficial activity.”

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

  • Business Wire has been synonymous with well-known press release distribution for more than half a century. Owned by Berkshire Hathaway, it combines regulatory compliance expertise with a powerful media network, helping enterprises large and small share news that influences markets and decision-makers alike.

Recommended Reads :