Skip to content

UPDATED 06:00 EDT / SEPTEMBER 22 2026

SECURITY

DataDome report finds bad bot traffic growing nine times faster than human traffic

A new report out today from bot protection company DataDome SAS finds that malicious automated traffic grew 124% between July 2025 and June 2026, more than nine times the rate of human traffic growth — and most of the popular websites it tested could not stop a single bot.

The findings, from the 2026 edition of the company’s “State of Bot & Agent Security Report,” draw on more than a trillion requests across more than 75,000 customer sites, together with a June test of 21,491 popular websites. Scraping dominated the mix, at 70.9% of bad bot traffic and up 185.2% over the year. DataDome ties some of that growth to third-party data resellers and agent builders harvesting the web at scale for model training, activity that does not always identify itself as an artificial intelligence crawler.

Scalping, the use of bots to buy up limited inventory for resale, rose 290.7%, with median daily volume close to quadrupling, and fake account creation was up 34.5%. Distributed denial-of-service attacks grew 39.9% and peaked above 2 billion requests in a single day in April, which made them the second-largest category at 12.7% of bad bot traffic.

Credential stuffing was flat on the year. DataDome calls that pattern cyclical rather than fading, since volume surged through the summer of 2025, collapsed by nearly 90% and then reached new single-day highs by April.

AI traffic grew 82.3% over the same 12 months. DataDome logged 52.7 billion AI agent and crawler requests across its customer base, with Meta-affiliated bots generating 46.3% of the identified total and OpenAI-affiliated bots 34.6%. Of the 29.02 billion AI bot requests logged in the first half of 2026, 97.9% still went to homepages and other general content.

The other 2.1% is where the change shows up. AI agents sent 605.6 million requests to login, form, cart, payment and account-creation pages between January and June, and login pages took 51.7% of that, against 23% a year earlier. Monthly login-page volume from AI bots ran from 11.9 million requests in January to 99.7 million in June.

Jerome Segura, vice president of threat research at DataDome, said automated traffic is “growing fast” and moving into the login, account and transaction flows at the center of the customer journey. Identifying automation is not the hard part anymore, he said. The harder question is whether a given session is beneficial or harmful.

DataDome’s website test ran in June, sending 10 bot types at 21,491 sites across 15 industries from residential addresses in the U.S., Canada and France. Nearly two in three sites, 65.3%, stopped none of them, and the share reaching full protection has fallen two years running, to 2.4% from 8.4% in 2024, though this year’s test added harder bot types. Telecommunications sites were the weakest, at 82.9% unprotected.

Spoofed AI agents walked past more than seven sites in 10. DataDome calls identity-based trust a widespread weakness, since a request claiming to be GPTBot, ClaudeBot or another trusted crawler is often let through on the name alone. Only 5.5% of sites caught the test’s disguised bot, which forges the network fingerprint of a real browser.

Most of the defenses in use are “still largely built around binary choices,” Segura said, even as the calls organizations have to make get finer. The critical test, in his view, is whether a site can separate a legitimate AI assistant from a credential-testing bot or an account-abuse campaign. Blocking everything would also cut off beneficial activity, he added.

Image: SiliconANGLE/GPT Image 2.5

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

 

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.
  • Max. file size: 244 MB.

Sign in

SIGN IN

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry