#040
2026-09-27

Bad Bots Growing 9x Faster Than Human Traffic: Two-Thirds of Sites Blocked None of the Test Bots

📰 Want to read more?
View full news list

DataDome, the bot-protection firm, published its State of Bot & Agent Security Report 2026 this week, analyzing more than one trillion requests across 75,000+ customer sites over a 12-month window. The headline is blunt: between July 2025 and June 2026, malicious bot traffic grew 124%, while legitimate human traffic grew only 13.2% — bad traffic is compounding about nine times faster than real users. AI agent and LLM crawler traffic rose 82.3% in the same period, more than six times the human growth rate.

In practical terms: a growing share of the requests hitting your site are no longer people. They don't buy anything or read anything — they scrape data, test stolen credentials, and stress your infrastructure — and every one of them still consumes your CDN bandwidth and backend capacity.

Scraping Is the Dominant Player: 70.9% of Bad Bots, Up 185%

Within malicious bot traffic, web scraping is the overwhelming majority — 70.9% of the total, up 185% year over year. The economics are simple: AI model training and RAG applications demand data at scale, and the cost of scraping tooling keeps falling — harvesting your content has become a low-barrier, high-yield business.

Next comes credential stuffing, which the report describes in distinct waves: a high-volume attack, a pause to refresh credential lists and rotate infrastructure, then a return at full scale. Scalping, spam, and DDoS activity all grew over the same window. Notably, in a 30-day sample, "simple" bots — cheap, low-effort scripts that work against most sites — were the largest share. The implication: if you have done nothing to defend your edge, you are the easiest target in the room.

AI Agents Are Moving Into Sensitive Territory

The most alarming figure in the report: AI bot traffic to login pages increased more than eightfold in H1 2026. Some of it is legitimate — AI assistants checking orders or placing purchases on behalf of users — but attackers can drive exactly the same motions with stolen credentials. As DataDome's VP of Threat Research put it, organizations are being asked to make nuanced judgments while most defenses are still built around binary allow/block decisions. Worse still, malware can simply copy the user-agent of a recognized AI service and impersonate a trusted crawler, turning your own allow-rules into an attack vector. A single request never reveals intent — only the sequence, speed, volume, and context do. That is the part no hand-written rule set can keep up with.

Live Testing: 65.3% of Sites Caught Not a Single Bot

DataDome fired 10 types of simulated bots — plain scripts, bots impersonating known AI services, forged browser fingerprints, and automated real browsers, sent from residential addresses in the US, Canada, and France — at the homepages of 21,491 popular websites:

The takeaway: "big company = secure" is a myth. Fragmented tooling, complex architectures, and legacy systems leave gaps that budget size cannot close.

What This Means for Your Bill

Most operators treat bots purely as a security problem, but first it is a cost problem: every successful bot consumes your CDN egress, bandwidth, backend CPU, and database queries. A 124% growth curve, applied to an invoice, means your share of genuinely useful traffic is being diluted while you keep paying for the whole thing.

The answer is not a longer blocklist — attackers rotate user-agents and IPs in a minute. It is automated, behavior-based detection and response: interaction-sequence analysis, fingerprint verification, risk scoring, and sub-second automatic blocking — the core of 24/7 AI-driven operations. Legitimate AI crawlers pass; malicious automation dies at the edge. No one needs to be watching the alerts at 3 a.m.

💡 LAFA Perspective

When bad traffic compounds nine times faster than real users, being scraped, probed, and pressured is no longer an incident — it is the daily baseline. Lafa System runs bot detection, WAF, and DDoS scrubbing fully automated at the machine layer, 24/7: your infrastructure answers only to real humans and legitimate AI, and everything else stops at the edge — protecting both your uptime and your bill.