Malicious Automated Traffic Has Grown 124 Percent

A new report shows that most websites remain vulnerable as malicious bot activity continues to surge.

Updated on Sept. 22, 2026 in Artificial Intelligence

Isometric editorial illustration of abstract copper server cooling fins and signal filaments, representing automated data harvesting and cybersecurity infrastructure.
Malicious automated web traffic increased by 124 percent between mid-2025 and mid-2026, as data harvesting by bots significantly outpaced website defensive measures. AI Illustration. Upload story photo >

Live Poll

Do you trust that the websites you frequent are effectively blocking harmful bot traffic?

Malicious automated traffic surged 124% between July 2025 and June 2026, driven largely by web scraping and scalping operations. DataDome found that 65.3% of websites failed to block a single bot during tests conducted in June 2026.

Why it matters

The rise in automated activity stems from third-party data resellers and agent builders harvesting massive amounts of web information for model training. This trend leaves most online platforms exposed to security threats and unauthorized data collection.

AI traffic increased by 82.3% during the 12-month period, with Meta and OpenAI bots accounting for 80.9% of identified requests. Tests revealed that only 2.4% of websites currently maintain full protection against automated intrusions.

The players

DataDome

This cybersecurity firm specializes in bot protection and online fraud detection for enterprise websites.

Meta

This technology conglomerate develops social media platforms and large-scale artificial intelligence models.

OpenAI

This organization researches and develops artificial intelligence technologies, including generative language models.

The details

DataDome tested 21,491 websites using 10 different bot types originating from residential addresses in the U.S., Canada, and France. Scraping dominated the landscape at 70.9% of bad traffic, while scalping volume jumped 290.7% and DDoS attacks peaked at over 2 billion requests in April 2026.

Timeline

  1. Malicious bot traffic rose 124% from July 2025 to June 2026.

  2. Credential stuffing volume saw a significant surge during the summer of 2025.

  3. DDoS attack requests reached a peak of over 2 billion in April 2026.

  4. AI agents targeted login and form pages between January 2026 and June 2026.

  5. DataDome conducted its comprehensive website bot testing in June 2026.

The Tech Race

The report highlights an accelerating arms race between automated data scrapers and website security providers. This mirrors a broader shift where platforms struggle to defend against AI-affiliated bots designed to harvest training data at an industrial scale.

Users may encounter more aggressive security challenges, such as CAPTCHAs, as websites scramble to implement defenses against AI scrapers. Consumers may also experience slower site performance or temporary service disruptions as platforms attempt to filter high-volume bot requests.

The takeaway

The overwhelming failure of most websites to block automated traffic suggests that current defense strategies are largely ineffective against modern AI tools. Site administrators should prioritize updated bot management solutions to safeguard their data and maintain platform integrity.

Further reading

For more on how software companies are navigating bot threats, explore our Artificial Intelligence section.

Live Poll

Do you trust that the websites you frequent are effectively blocking harmful bot traffic?