Malicious Automated Web Traffic Has More Than Doubled
DataDome testing reveals that most websites remain vulnerable to scraping and AI-driven bot activity.
Updated on Sept. 22, 2026 in Artificial Intelligence

Live Poll
Do you trust that the websites you frequent are effectively blocking harmful bot traffic?
Malicious automated traffic surged 124% between July 2025 and June 2026, driven largely by web scraping and scalping operations. New testing indicates that 65.3% of websites fail to block any bot traffic, while only 2.4% maintain full protection.
Why it matters
The massive rise in bot activity stems from third-party data resellers and agent builders harvesting content for model training. This trend forces a critical re-evaluation of web security as automated scrapers increasingly target login and form pages.
Testing across 21,491 websites revealed that scalping volume rose 290.7% while AI-related traffic grew 82.3%. Meta-affiliated bots generated 46.3% of these AI requests, with OpenAI-affiliated bots accounting for 34.6%.
The players
DataDome
A cybersecurity firm specializing in bot management and online fraud protection.
Meta
A technology conglomerate that develops large language models and social media platforms.
OpenAI
An artificial intelligence research organization known for developing the GPT series of models.
The details
DataDome tested sites by deploying 10 distinct bot types from residential addresses in the U.S., Canada, and France. These bots simulate human browsing patterns to bypass basic security, with scraping accounting for 70.9% of bad traffic. Distributed denial-of-service (DDoS) — an attack where multiple compromised systems overwhelm a target server — peaked above 2 billion requests in a single day in April 2026.
Timeline
July 2025 to June 2026: Period of reported malicious bot traffic growth.
Summer 2025: Observed surge in credential stuffing volume.
April 2026: Peak in DDoS attack volume exceeding 2 billion requests.
January 2026 to June 2026: Rise in AI agent requests targeting login pages.
June 2026: Timing of DataDome website bot testing.
The Tech Race
This study highlights an escalating arms race between web operators and AI data harvesters. It marks a significant departure from historical bot traffic patterns now dominated by AI model training requirements.
Users may experience increased site slowdowns as AI agents and scalping bots consume server resources. Web developers are now pressured to implement more robust blocking mechanisms, as traditional filters currently fail to stop the majority of automated probes.
The takeaway
The rapid expansion of AI-related traffic highlights a critical vulnerability in current web infrastructure. Organizations should monitor the escalating use of AI agent requests to login pages as a primary indicator of future security threats.
Further reading
For broader trends in bot-driven model training, visit the Artificial Intelligence section.
Live Poll
Do you trust that the websites you frequent are effectively blocking harmful bot traffic?






