Bot Test Failures: 66% of Websites Fail Security Checks
Malicious bot activity surged by 124% from July 2025 to June 2026, outpacing human traffic growth, according to DataDome’s report.
Surge in Malicious Bot Activity
Malicious bot activity surged by 124% from July 2025 to June 2026, outpacing the 13.2% growth in human traffic, according to DataDome’s State of Bot Agent Security Report 2026. AI agent and large language model crawler traffic rose 82.3% during the same period. Bot traffic expanded at a rate nine times faster than human traffic, with the company analyzing trillions of requests across 75,000 customer sites. Bots and AI agents accounted for 26.5% of total traffic in the dataset. Human traffic’s share of requests declined, with bad bots absorbing most of the shift. AI traffic grew more than six times faster than human traffic.
Web Scraping and Credential Stuffing
Scraping, scalping, spamming, and DDoS activity rose during the study period. Credential stuffing remained stable annually but experienced periodic fluctuations. Web scraping dominated bad bot traffic, representing 70.9% of incidents. The proliferation of scraping tools and demand for large-scale data fueled these campaigns. Credential-stuffing attacks followed a cyclical pattern, with high-volume operations interrupted by credential list refreshes and infrastructure rotations before resuming at full scale.
Bot Complexity and Attack Patterns
A 30-day analysis of bad bot traffic revealed simple bots as the largest category. These require minimal effort to deploy and remain effective against sites with limited bot defenses. Attackers use them for reconnaissance, scanning, and targeting weaker defenses. Average-complexity bots are prevalent in scraping, fake-account creation, and credential-testing operations. They employ browser automation frameworks to mimic legitimate browsing sessions, complicating detection. Advanced actors often isolate sophisticated tools from basic bots to avoid exposing campaigns through simplistic automation signals. Some campaigns combine basic and intermediate techniques, initially using simple automation and escalating to advanced browser simulations when necessary.
Challenges in Bot Detection
Browser-side signals alone cannot ensure comprehensive protection, as attackers can suppress or mimic them. Requests targeting APIs, mobile endpoints, or server-side services may bypass client-side code execution. AI bots increasingly infiltrate critical areas. Monthly AI bot traffic to login pages increased eightfold in the first half of 2026. This trend reflects the expanding use of assistants capable of performing user tasks such as order checks, account information retrieval, and purchase support.
Jerome Segura, VP of Threat Research at DataDome, noted, “Organizations face heightened challenges in making nuanced security decisions with defenses still reliant on binary classifications. Distinguishing legitimate AI assistants from credential-testing bots or automated account-abuse campaigns will be vital to safeguarding users without disrupting beneficial interactions.”
Targeted Attacks and Website Vulnerabilities
Login pages also attract bots testing stolen credentials. Shopping carts face manipulation to reserve inventory or exploit promotions. Payment pages draw card-testing tools, while online forms remain targets for spam, false leads, and automated data harvesting. A single request may not reveal a visitor’s intent. An authorized assistant checking an order could initially resemble a bot attempting account access. Security systems must analyze interaction sequences, speed, volume, and context. Malicious software can mimic the user-agent strings of recognized AI services to appear as trusted crawlers. Unfamiliar bots can evade rules designed for established services.
Website Security Gaps
Most websites fail to identify automated threats. 65.3% of tested popular websites did not detect any of the 10 simulated bots. Only 2.4% blocked or challenged all types. Tests included simple scripts, bots impersonating AI services, tools with forged browser fingerprints, and automated real-browser versions. Requests originated from residential internet addresses in the U.S., Canada, and France. Traffic volume offered no reliable indicator of protection levels. High-traffic sites performed similarly to lower-traffic counterparts. Large organizations with substantial security budgets still face gaps due to complex infrastructure, fragmented tools, and legacy systems. Testing focused on the homepages of 21,491 popular websites. Some protections may operate on login, account, or payment pages, which were outside the test scope. Attack-classified traffic represents attempted actions, not confirmed breaches or financial losses.
