Malicious Automated Web Traffic Has More Than Doubled

DataDome testing reveals that most websites remain vulnerable to scraping and AI-driven bot activity.

Updated on Sept. 22, 2026 in Artificial Intelligence

Isometric editorial illustration of a dense cluster of matte metallic server racks and fiber-optic cables, representing automated web infrastructure.
Malicious automated web traffic increased by 124% between mid-2025 and 2026 as web scrapers and AI bot builders exploited widespread security vulnerabilities. AI Illustration. Upload story photo >

Live Poll

Do you trust that the websites you frequent are effectively blocking harmful bot traffic?

Malicious automated traffic surged 124% between July 2025 and June 2026, driven largely by web scraping and scalping operations. New testing indicates that 65.3% of websites fail to block any bot traffic, while only 2.4% maintain full protection.

Why it matters

The massive rise in bot activity stems from third-party data resellers and agent builders harvesting content for model training. This trend forces a critical re-evaluation of web security as automated scrapers increasingly target login and form pages.

Testing across 21,491 websites revealed that scalping volume rose 290.7% while AI-related traffic grew 82.3%. Meta-affiliated bots generated 46.3% of these AI requests, with OpenAI-affiliated bots accounting for 34.6%.

The players

DataDome

A cybersecurity firm specializing in bot management and online fraud protection.

Meta

A technology conglomerate that develops large language models and social media platforms.

OpenAI

An artificial intelligence research organization known for developing the GPT series of models.

The details

DataDome tested sites by deploying 10 distinct bot types from residential addresses in the U.S., Canada, and France. These bots simulate human browsing patterns to bypass basic security, with scraping accounting for 70.9% of bad traffic. Distributed denial-of-service (DDoS) — an attack where multiple compromised systems overwhelm a target server — peaked above 2 billion requests in a single day in April 2026.

Timeline

  1. July 2025 to June 2026: Period of reported malicious bot traffic growth.

  2. Summer 2025: Observed surge in credential stuffing volume.

  3. April 2026: Peak in DDoS attack volume exceeding 2 billion requests.

  4. January 2026 to June 2026: Rise in AI agent requests targeting login pages.

  5. June 2026: Timing of DataDome website bot testing.

The Tech Race

This study highlights an escalating arms race between web operators and AI data harvesters. It marks a significant departure from historical bot traffic patterns now dominated by AI model training requirements.

Users may experience increased site slowdowns as AI agents and scalping bots consume server resources. Web developers are now pressured to implement more robust blocking mechanisms, as traditional filters currently fail to stop the majority of automated probes.

The takeaway

The rapid expansion of AI-related traffic highlights a critical vulnerability in current web infrastructure. Organizations should monitor the escalating use of AI agent requests to login pages as a primary indicator of future security threats.

Further reading

For broader trends in bot-driven model training, visit the Artificial Intelligence section.

Live Poll

Do you trust that the websites you frequent are effectively blocking harmful bot traffic?

Malicious Automated Web Traffic Has More Than Doubled