DataDome recently released the State of Bot & Agent Security Report 2026, examining trends through analysis of trillions of requests across more than 75,000 customer sites and testing of over 20,000 popular websites. According to the report, AI requests to login pages have increased eightfold in the first half of the year, with January’s 11.9 million figure ballooning to 99.7 million in June. This activity is likely partially made up of legitimate agents taking action on behalf of users, but the same behavior at the endpoint is often the result of malicious intent.
Machines Outpacing Human Users
In the year from July 2025 to June 2026, traffic from malicious bots increased by 124%, more than nine times the growth rate for human users. Total AI traffic went up 82.3%, with 52.7 billion requests from AI agents and LLM crawlers during the period analyzed for the report.
These numbers are in line with recent trends in AI traffic reported by other sources. The 2026 State of AI Traffic & Cyberthreat Benchmark Report published by HUMAN Security earlier in the year showed a nearly 8,000% year-over-year increase in agentic AI traffic and a growth rate eight times that of human users. No matter who is doing the research, the numbers don’t lie: AI and bot activity is continuously experiencing explosive growth and outpacing traffic from human users.
Scraping Feeds the AI Data Supply Chain
The DataDome report found that scraping is still the most popular attack vector in this malicious activity, increasing 185.2% year-over-year and making up 70.9% of bad bot traffic. This increase can likely be partly attributed to the growth of the AI data market, where data resellers and agent builders harvest data from the web at scale. This scraped information can be used for LLM training, agent responses, and bolstering other AI services.
The most commonly used AI providers for crawler activity are Meta-affiliated bots, making up 46.3% of observed AI crawler traffic, and OpenAI-affiliated bots, accounting for 34.6%. These numbers demonstrate where malicious actors are turning for the AI technology that enables their attacks, as well as underlining that any AI tool or agent can be manipulated for nefarious ends.
Taking Action Beyond Reading Pages
One significant trend is an immense volume of agentic AI traffic on high-risk endpoints. According to DataDome’s analysis, H1 2026 saw 605.6 million AI agent requests to logins, forms, carts, payment flows, and account creation pages. Login pages alone constituted more than half (51.7%) of this high-value traffic. AI agent spoofing has also increased by 45% between February and July of 2026; user-prompted agents lead this statistic with a category-level increase of 300%.
Scalping activity also surged, increasing 290.7% with the median daily volume growing almost fourfold. The increase in this type of traffic comes at a time when scalping is a common complaint and a hot-button issue in industries from collectibles to concert tickets. The continuing growth of the scalping economy and increase in scalping bot activity emphasizes the need for companies to take steps “to protect high-demand inventory and purchase flows from automated abuse.”
Account Abuse Cycles Rather Than Declining
DataDome’s numbers show account-related abuse increasing across the board: fake account creation went up by 34.5%, whereas credential stuffing showed a cyclical trend. Credential stuffing activity was observed dropping by almost 90% before shooting back up to new single-day record highs. This demonstrates that attackers are putting certain campaigns on pause and coming back to them when fresh batches of credentials are leaked, rather than abandoning them outright for other techniques.
Defenses Moving Backward
Alongside the many statistics showing rapidly increasing bad bot activity, the report also reveals alarming numbers regarding how websites are protecting themselves against this activity. Of the more than 20,000 sites tested, nearly two-thirds (65.3%) were not able to stop any of the 10 bot types included in DataDome’s assessment.
The proportion of sites achieving full protection decreased for the second year in a row, from 8.4% in 2024 to 2.8% in 2025 to 2.4% in 2026. While a much less steep decline than the previous year-over-year change—and possibly impacted by the more robust test suite used for the 2026 testing period—it still shows a discouraging downward trend while bot threats are on the rise.
Only 5.5% of the sites were able to stop every basic bot tested against them, and 3.1% blocked every real-browser bot, highlighting that the gap is not exclusive to protecting against particularly advanced attackers. Simple, undisguised bots still make up almost half (49%) of bad bot traffic, and more than nine in ten websites fail to block activity even from these basic threats.
Identity Alone is Not Enough
One of the biggest challenges in defending against bad bot traffic is that attackers utilize many of the same tools and agents as legitimate actors. The same crawling activity that helps defenders with discovery of threats. “Modern bots skip the frontend entirely and hit backend APIs directly with valid logins and well-formed requests, so they look like normal machine traffic,” says Randolph Barr, Chief Information Security Officer at Cequence Security, a San Francisco, Calif.-based API security and bot management provider. “When an attack looks exactly like legitimate business, it doesn't trip a security alert; it shows up as fraud, scraped pricing, and abused inventory.”
The distinction between malicious and benign activity cannot be put down to whether the user is a human or a bot. Blocking all AI traffic inherently means blocking some non-threatening activity to the site, which can cost businesses revenue unnecessarily. On the other hand, allowing all AI traffic through means leaving the site open to a vast range of fraud and abuse via bad bot activity.
Protection Based on Intent
This problem requires deeper and more sophisticated measures than simply turning away all bots at the door. The ongoing rise in bad bot traffic underlines the necessity of intent-based detection, evaluating user intent at login, checkout, and signup. User-prompted agents must be verified as a growing traffic class, and their presence at scale must be reckoned with by defenders and organizations protecting their websites.