top of page

Malicious Bot Traffic Surges 124% as AI Agents Target Login Pages

20 minutes ago
1 min read

Malicious bot traffic increased 124 percent over the past year as AI agents and inexpensive proxy networks made automated abuse easier to build and harder to distinguish from legitimate users, according to new research from DataDome.


The company's State of Bot and Agent Security Report analyzed trillions of requests across more than 75,000 customer sites. DataDome reported that scraping rose 185.2 percent, scalping activity climbed 290.7 percent and AI-agent traffic to login pages increased more than eightfold during the first half of 2026.


Monthly AI bot requests to login pages rose from 11.9 million in January to 99.7 million in June, according to the report. That pattern suggests automated systems are moving beyond passive collection and into workflows involving credentials, protected accounts and customer transactions.


The figures come from DataDome's customer network and should be interpreted as vendor telemetry rather than a census of the entire internet. Even so, the scale highlights a growing problem for application security teams: AI-driven automation can browse, click and type in ways that resemble human behavior.


The defensive challenge is no longer simply separating bots from people. Legitimate AI assistants may act on behalf of customers, while malicious automation can use valid credentials and consumer IP addresses. Blanket blocking risks disrupting approved agents, but permissive controls create room for scraping, account takeover and transaction abuse.


Security teams increasingly need to verify both identity and intent across websites, mobile applications and APIs. That means correlating client integrity, authentication signals, session behavior and transaction context rather than relying on a single device fingerprint or behavioral score.

bottom of page