Malicious Bot Traffic Surges 124%, Outpacing Human Growth
A new report reveals a dramatic 124% increase in malicious bot traffic over the past year, significantly outpacing human user growth and challenging website defenses.

Malicious bot activity has surged by an alarming 124% between July 2025 and June 2026, dramatically outpacing the 13.2% growth observed in legitimate human traffic during the same period. This stark increase highlights a growing challenge for website operators and security professionals attempting to distinguish automated threats from genuine user interactions.
The latest findings come from DataDome's State of Bot & Agent Security Report 2026, which analyzed trillions of requests across more than 75,000 customer websites. The report indicates that bots and sophisticated AI agents are becoming increasingly prevalent and effective at evading detection.
Beyond traditional malicious bots, the study also noted a significant 82.3% rise in traffic originating from AI agents and large language model (LLM) crawlers. This surge suggests that the capabilities of AI are being increasingly leveraged for automated web scraping, content harvesting, and potentially more nefarious purposes, posing a new frontier in bot security.
Compounding the problem, the report found that nearly two-thirds of tested websites failed to adequately detect and block bot traffic. This widespread failure indicates a significant gap between the sophistication of automated threats and the current defensive capabilities deployed by many organizations. The inability to effectively identify and mitigate bot activity leaves websites vulnerable to a range of attacks, including credential stuffing, scraping, and denial-of-service.
DataDome's analysis underscores the evolving nature of bot threats. As AI technologies advance, so too do the methods employed by malicious actors to automate their attacks. The sheer volume and speed at which bots can operate mean that even a small percentage of compromised websites can lead to widespread disruption and data breaches.
The implications of this trend are far-reaching. For businesses, it means increased risks of account takeovers, inventory hoarding, content theft, and distributed denial-of-service (DDoS) attacks. For end-users, it can translate into compromised accounts, fraudulent transactions, and a degraded online experience.
As bot traffic continues its exponential growth, organizations must prioritize robust bot management solutions. This includes employing advanced detection techniques that can identify behavioral anomalies, leverage machine learning, and adapt to new evasion tactics. Staying ahead of these automated threats requires continuous monitoring, analysis, and adaptation of security strategies.
The report serves as a critical wake-up call for the cybersecurity industry, emphasizing the urgent need for more effective defenses against the ever-increasing tide of malicious bot activity and the growing sophistication of AI-driven attacks.