![]()
DataDome, the leader in bot and agent trust management, today released The State of Bot & Agent Security Report, 2026 Edition, an analysis of more than one trillion requests across 75,000+ customer sites and a test of more than 20,000 popular websites.
Malicious automated traffic grew more than nine times faster than human traffic between July 2025 and June 2026, with bad bot traffic increasing 124%. Scraping remained the leading threat, rising 185% year over year. At the same time, AI bots are moving beyond just crawling homepages, targeting login pages 8x more. Yet most websites are not prepared. The external website tests revealed that 65% were completely unprotected against bots.
“Automated traffic isn’t just a volume problem at the edge of the internet anymore. It’s growing fast, and it’s going deeper: into the login, account, and transaction flows at the center of the customer journey,” said Jerome Segura, VP of Threat Research at DataDome. “For businesses, the challenge is no longer simply identifying automation; it is determining whether that activity is beneficial or harmful.”
Key findings:
- Bad bots are growing 9x faster than human traffic. Bad bot traffic increased 124% over 12 months.
- Scraping is the largest and fastest-growing attack vector. It accounted for 70.9% of bad bot traffic across DataDome’s customer base and increased 185.2% during the study period. The growth may be connected to an expanding AI data supply chain, in which third-party data resellers and applications building AI agents collect web data at scale for training and other AI services.
- AI traffic is reaching high-value user journeys. In H1 2026, AI agents generated 605.6 million requests to login pages, forms, carts, payment flows, and account-creation pages, with login pages accounting for 51.7% of that traffic. Total AI traffic increased 82.3% during the study period, bringing more automated traffic into the mix, including both beneficial and harmful activity. The same crawling that can help users discover products and information can be difficult to distinguish from unwanted scraping, particularly when it reaches these high-value endpoints. Identity-based controls cannot make that distinction, so businesses need to evaluate what each session is trying to do.
- Scalping activity increased 290.7%. Median daily volume nearly quadrupled, putting continued pressure on businesses to protect high-demand inventory and purchase flows from automated abuse.
- Account-related abuse is increasing across several attack paths. Fake account creation grew 34.5%. Credential stuffing remained cyclical rather than declining, with activity surging, dropping by nearly 90%, and later recovering to new single-day highs. This pattern suggests attackers are opportunistically leveraging batches of leaked credentials.
- Most websites remain unprotected against bots and AI agents. In the expanded scan, 65.3% of tested websites stopped none of the 10 bot types evaluated. Only 2.4% stopped all of them, down from 8.4% in 2024 and 2.8% in 2025.
Taken together, these findings point to a widening gap between the traffic businesses need to understand and the defenses they have in place. As automated systems move through the same login, account, and transaction flows as human users, intent becomes the critical signal for deciding what to allow and what to stop.
“Organizations are being asked to make more nuanced decisions with defenses that are still largely built around binary choices,” added Segura. “The ability to distinguish a legitimate AI assistant from a credential-testing bot or an automated account-abuse campaign will be critical to protecting customers without blocking beneficial activity.”
For the full findings from DataDome’s report, click here. Follow DataDome on YouTube and LinkedIn for regular updates from Galileo, DataDome’s threat research team, and insights on how to ensure the traffic reaching your business is traffic you can trust.
About DataDome
DataDome is the leader in bot and agent trust management, providing complete visibility and control over all traffic, whether human, bot, or AI agent. Named a Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026, DataDome is trusted by enterprises like Etsy, PayPal, and SoundCloud. Acting as your real-time traffic control plane, DataDome’s multi-layered AI engine leverages thousands of models and 5 trillion signals daily to analyze the intent of every session in under 2 milliseconds, so only trusted traffic reaches your business, powering growth across your sites, apps, APIs, and MCP servers. A recognized Leader on G2, DataDome stops 20K+ attacks every second, ensuring traffic you can trust.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260922654101/en/
Media gallery
