DataDome reported that malicious automated traffic increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Analysis spanning more than one trillion requests across over 75,000 customer sites found that bots and AI agents accounted for roughly 26.5% of traffic. Web scraping represented 70.9% of malicious bot activity and rose 185.2%, driven in part by collection of data for AI-model training; scalping, fake-account creation, and DDoS activity also grew.
AI-agent and LLM-crawler traffic rose 82.3%, while monthly AI-bot activity against login pages increased more than eightfold during the first half of 2026, increasing exposure to credential testing and account abuse. In testing of 21,491 popular websites, 65.3% failed to detect any of 10 simulated bot types and only 2.4% stopped or challenged all of them; telecommunications organizations performed worst. DataDome advised organizations to distinguish authorized AI assistants from malicious automation through behavioral context rather than relying only on individual-request or browser-side indicators.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Between July 2025 and June 2026, DataDome observed malicious automated traffic rise 124%, compared with 13.2% growth in human traffic. Web scraping comprised 70.9% of bad-bot traffic, while AI-agent and LLM-crawler traffic increased 82.3%.
DataDome published its State of Bot & Agent Security Report based on analysis of more than one trillion requests across more than 75,000 customer sites. The report warned that organizations struggle to distinguish legitimate AI automation from malicious activity targeting authentication, transactions, and other workflows.
In a June test, DataDome tested 10 simulated bot types against 21,491 popular websites and found that 65.3% failed to detect any of them; only 2.4% stopped or challenged every bot type. Telecommunications sites were identified as the weakest sector in the testing.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.