Are AI Bots Overtaking Human Web Activity and Creating Cyber Risks?

Article Highlights
Off On

The prevalence of automated bot traffic on the internet has been a rising concern, with recent reports indicating that bots have started to dominate web activity, surpassing human interactions. Bot traffic accounted for 51% of the total web activity last year. Among this, bad bot traffic grew significantly, from 32% to 37%, posing clear cyber risks. This surge can be attributed to advancements in artificial intelligence and large language models (LLMs), which now make it easier to create bots on a massive scale. Prominent bots like ByteSpider Bot, responsible for 54% of AI-enabled attacks, along with others such as Applebot, ClaudeBot, and the ChatGPT User Bot, are at the forefront of this alarming trend.

Rising Threat of Bad Bots in Key Industries

Certain sectors have been particularly targeted by bot attacks, with dramatic effects on their operations. In the travel industry, bot attacks accounted for 41% of total incidents, while the retail sector faced an even higher threat at 59%. The travel industry, having faced the most attacks last year, experienced a decline in the complexity of attacks but an increase in volume. This shift is largely due to AI, allowing less skilled threat actors to execute a higher number of less complex assaults, further stressing the security infrastructures of these sectors. Bad bots exhibit a high degree of versatility, being exploited for Distributed Denial of Service (DDoS) attacks, custom rules violations, and breaches of Application Programming Interfaces (APIs). A salient point from the report indicates that advanced bot traffic targeted APIs in 44% of recorded cases for executing automated payment fraud, account hijacking, and data exfiltration. Financial services, healthcare, and e-commerce sectors are especially vulnerable due to the sensitive nature of the data they manage. The vulnerabilities in APIs are primarily attributed to their intrinsic business logic, which can be easily manipulated by experienced attackers.

The adoption of cloud-based services and microservices architectures, while offering numerous operational advantages, also brings associated risks. It is essential for organizations to fully comprehend the risks related to APIs and take active measures to mitigate fraud and data breaches. Failing to secure these touchpoints can lead to significant harm, both financially and reputationally.

Conclusion and Future Considerations

The rise of automated bot traffic on the internet is causing increasing concern. Recent reports reveal that bots are now more active online than humans. Bot traffic made up 51% of total web activity last year. This includes a notable increase in bad bot traffic, which climbed from 32% to 37%, highlighting distinct cyber risks. This trend is linked to the progress in artificial intelligence and large language models (LLMs), which have simplified the mass production of bots. Major bots such as ByteSpider Bot, responsible for 54% of AI-driven attacks, and others like Applebot, ClaudeBot, and the ChatGPT User Bot are leading this troubling development. These bots have become highly sophisticated, making it challenging to distinguish between human and automated interactions online, thereby increasing threats to cybersecurity. As bots continue to advance, mitigation efforts must be enhanced to protect web integrity and user security.

Explore more

How Will the New UPI MDR Impact Digital Payments?

Government officials have designed the 0.4 percent rate to ensure that the vast majority of grassroots economic activity remains unaffected by digital payment costs. This strategic move represents a maturation of the Indian digital payments ecosystem, which has long relied on government subsidies to maintain its celebrated zero-fee structure. As the volume of transactions reaches unprecedented levels, the need for

OLRB Clarifies Workplace Harassment Investigation Standards

Employers who fail to interview relevant witnesses identified in an initial complaint may find their entire harassment investigation invalidated by regulatory bodies for a lack of procedural thoroughness. This warning stems from a pivotal ruling by the Ontario Labour Relations Board, which recently clarified the murky legal requirements surrounding workplace harassment inquiries. Under the Occupational Health and Safety Act, employers

What Are the Best All-in-One Accounting Platforms for SMBs?

In the highly competitive landscape of 2026, financial agility has transformed from a competitive advantage into a fundamental requirement for small and medium-sized businesses. Many organizations continue to struggle with fragmented legacy systems, employing a disparate array of applications for billing, bank reconciliation, and inventory tracking. This disconnected approach, frequently described as a Frankenstein’s monster software configuration, inevitably leads to

How Do We Secure the Modern SaaS Attack Surface?

Transitioning to an integrated governance model is essential for preventing security gaps that naturally occur between siloed detection and recovery systems in the cloud. The shift from on-premise infrastructure to these expansive cloud-centric models has fundamentally dissolved the traditional security perimeter that once defined corporate safety. As organizations now manage an average of 100 different software-as-a-service applications, the obsolete walled

NLRB Memo Signals Shift Toward Employer-Friendly Policies

A proposed return to traditional back-pay models would eliminate the Biden-era expansion of consequential damages for foreseeable financial harms in labor disputes. This directive, central to Memorandum GC 26-04 issued on August 26, 2026, by National Labor Relations Board General Counsel Crystal S. Carey, marks a profound pivot in the federal government’s approach to workplace regulation. As the American labor