{
  "id": 9123225,
  "title": "DataDome report finds bad bot traffic growing nine times faster than human traffic",
  "url": "https://urgent.news/2026/09/22/datadome-report-finds-bad-bot-traffic-growing-nine-times-faster-than",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-22T10:00:51.000Z",
  "source": {
    "name": "SiliconANGLE",
    "slug": "siliconangle",
    "url": "https://siliconangle.com/2026/09/22/datadome-report-finds-bad-bot-traffic-growing-nine-times-faster-than-human-traffic/"
  },
  "original_language": "en",
  "account": "A recent report from bot protection firm DataDome SAS reveals that malicious automated traffic has surged 124% between July 2025 and June 2026, outpacing human traffic growth by more than ninefold. Out of the over 75,000 customer sites analyzed, most popular websites could not stop a single bot. Scraping ranked as the dominant form of bad bot traffic, comprising 70.9% of all malicious activity, which saw an astonishing 185.2% increase year-over-year. This surge is attributed to third-party data resellers and agent builders harnessing vast amounts of web data for model training, often failing to disclose their AI origins.\n\nAnother concerning trend is the sharp rise in scalping, with bot-driven purchases of limited inventory rising by 290.7% and daily volumes nearing quadrupling. Concurrently, fake account creation surged by 34.5%. Distributed denial-of-service (DDoS) attacks increased by 39.9%, peaking at over 2 billion requests in a single day in April, marking them as the second-largest category at 12.7% of bad bot traffic.\n\nCredential stuffing, however, remained flat throughout the period. The report highlights a cyclical pattern in bot activity, with volume surging in the summer of 2025, plummeting nearly 90% before rebounding to new highs by April. AI traffic grew by 82.3% over the same period, with Meta-affiliated bots contributing 46.3% and OpenAI-affiliated bots accounting for 34.6% of the identified total.\n\nSurprisingly, 97.9% of AI bot requests were directed to homepages and general content, revealing a shift in the focus of AI agents. Jerome Segura, DataDome's vice president of threat research, noted that automated traffic is intensifying and infiltrating critical areas like login, account, and transaction flows. Identifying automation has become easier, but the bigger challenge lies in determining whether a session is beneficial or harmful.\n\nDuring a June website test involving 10 bot types across 21,491 sites in 15 industries, nearly two-thirds of sites failed to block all bots, while the percentage of fully protected sites has declined from 8.4% in 2024 to 2.4% this year. Telecommunications sites were the weakest, with 82.9% unprotected. Spoofed AI agents bypassed more than seven sites out of ten. DataDome emphasizes the widespread weakness of identity-based trust, as requests claiming to be trusted crawlers like GPTBot or ClaudeBot are often trusted without scrutiny. Only 5.5% of sites detected disguised bots that mimic legitimate browser fingerprints.\n\nThe report underscores the need for more sophisticated defenses that can differentiate between legitimate AI assistants and malicious bots or account-abuse campaigns. Over-reliance on binary choices in security measures remains insufficient, as the evolving nature of bot attacks demands finer distinctions.",
  "summary": "A new report out today from bot protection company DataDome SAS finds that malicious automated traffic grew 124% between July 2025 and June 2026, more than nine times the rate of human traffic growth — and most of the popular websites it tested could not stop a single bot. The findings, from the 2026 edition […] The post DataDome report finds bad bot traffic growing nine times faster than human…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}