Are AI Bots Overtaking Human Web Activity and Creating Cyber Risks?

Article Highlights
Off On

The prevalence of automated bot traffic on the internet has been a rising concern, with recent reports indicating that bots have started to dominate web activity, surpassing human interactions. Bot traffic accounted for 51% of the total web activity last year. Among this, bad bot traffic grew significantly, from 32% to 37%, posing clear cyber risks. This surge can be attributed to advancements in artificial intelligence and large language models (LLMs), which now make it easier to create bots on a massive scale. Prominent bots like ByteSpider Bot, responsible for 54% of AI-enabled attacks, along with others such as Applebot, ClaudeBot, and the ChatGPT User Bot, are at the forefront of this alarming trend.

Rising Threat of Bad Bots in Key Industries

Certain sectors have been particularly targeted by bot attacks, with dramatic effects on their operations. In the travel industry, bot attacks accounted for 41% of total incidents, while the retail sector faced an even higher threat at 59%. The travel industry, having faced the most attacks last year, experienced a decline in the complexity of attacks but an increase in volume. This shift is largely due to AI, allowing less skilled threat actors to execute a higher number of less complex assaults, further stressing the security infrastructures of these sectors. Bad bots exhibit a high degree of versatility, being exploited for Distributed Denial of Service (DDoS) attacks, custom rules violations, and breaches of Application Programming Interfaces (APIs). A salient point from the report indicates that advanced bot traffic targeted APIs in 44% of recorded cases for executing automated payment fraud, account hijacking, and data exfiltration. Financial services, healthcare, and e-commerce sectors are especially vulnerable due to the sensitive nature of the data they manage. The vulnerabilities in APIs are primarily attributed to their intrinsic business logic, which can be easily manipulated by experienced attackers.

The adoption of cloud-based services and microservices architectures, while offering numerous operational advantages, also brings associated risks. It is essential for organizations to fully comprehend the risks related to APIs and take active measures to mitigate fraud and data breaches. Failing to secure these touchpoints can lead to significant harm, both financially and reputationally.

Conclusion and Future Considerations

The rise of automated bot traffic on the internet is causing increasing concern. Recent reports reveal that bots are now more active online than humans. Bot traffic made up 51% of total web activity last year. This includes a notable increase in bad bot traffic, which climbed from 32% to 37%, highlighting distinct cyber risks. This trend is linked to the progress in artificial intelligence and large language models (LLMs), which have simplified the mass production of bots. Major bots such as ByteSpider Bot, responsible for 54% of AI-driven attacks, and others like Applebot, ClaudeBot, and the ChatGPT User Bot are leading this troubling development. These bots have become highly sophisticated, making it challenging to distinguish between human and automated interactions online, thereby increasing threats to cybersecurity. As bots continue to advance, mitigation efforts must be enhanced to protect web integrity and user security.

Explore more

How AI Agents Work: Types, Uses, Vendors, and Future

From Scripted Bots to Autonomous Coworkers: Why AI Agents Matter Now Everyday workflows are quietly shifting from predictable point-and-click forms into fluid conversations with software that listens, reasons, and takes action across tools without being micromanaged at every step. The momentum behind this change did not arise overnight; organizations spent years automating tasks inside rigid templates only to find that

AI Coding Agents – Review

A Surge Meets Old Lessons Executives promised dazzling efficiency and cost savings by letting AI write most of the code while humans merely supervise, but the past months told a sharper story about speed without discipline turning routine mistakes into outages, leaks, and public postmortems that no board wants to read. Enthusiasm did not vanish; it matured. The technology accelerated

Open Loop Transit Payments – Review

A Fare Without Friction Millions of riders today expect to tap a bank card or phone at a gate, glide through in under half a second, and trust that the system will sort out the best fare later without standing in line for a special card. That expectation sits at the heart of Mastercard’s enhanced open-loop transit solution, which replaces

OVHcloud Unveils 3-AZ Berlin Region for Sovereign EU Cloud

A Launch That Raised The Stakes Under the TV tower’s gaze, a new cloud region stitched across Berlin quietly went live with three availability zones spaced by dozens of kilometers, each with its own power, cooling, and networking, and it recalibrated how European institutions plan for resilience and control. The design read like a utility blueprint rather than a tech

Can the Energy Transition Keep Pace With the AI Boom?

Introduction Power bills are rising even as cleaner energy gains ground because AI’s electricity hunger is rewriting the grid’s playbook and compressing timelines once thought generous. The collision of surging digital demand, sharpened corporate strategy, and evolving policy has turned the energy transition from a marathon into a series of sprints. Data centers, crypto mines, and electrifying freight now press