
Facebook
Twitter
LinkedIn
Rise in accessible AI tools significantly lowered the barrier to entry for cyber attackers, enabling them to create and deploy malicious bots at scale.
For the first time in a decade, automated traffic surpassed human activity, accounting for 51% of all web traffic.
API-directed attacks surged to 44% of advanced bot traffic, with the travel sector topping the list for bot attacks overall.
Thales, the leading global technology and security provider, today announced the release of the 2025 Imperva Bad Bot Report, a global analysis of automated bot traffic across the internet. This year's report, the 12th annual research study, reveals that generative artificial intelligence (AI) is revolutionizing the development of bots, allowing less sophisticated actors to launch a higher volume of bot attacks with increased frequency. Today's attackers are also leveraging AI to scrutinize their unsuccessful attempts and refine techniques to evade security measures with heightened efficiency, amidst a growing Bots-As-A-Service (BaaS) ecosystem of commercialized bot services.
Automated bot traffic surpassed human-generated traffic for the first time in a decade, constituting 51% of all web traffic in 2024. This shift is largely attributed to the rise of AI and Large Language Models (LLMs), which have simplified the creation and scaling of bots for malicious purposes. As AI tools become more accessible, cyber criminals are increasingly leveraging these technologies to create and deploy malicious bots which now account for 37% of all internet traffic - a significant increase from 32% in 2023. This is the sixth consecutive year of growth in bad bot activity, posing security challenges for organizations striving to safeguard their digital assets.
Both the Travel and the Retail sectors face an advanced bot problem, with bad bots making up 41% and 59% of their traffic respectively. In 2024, the travel industry became the most attacked sector, accounting for 27% of all bot attacks, up from 21% in 2023. The most notable shift in 2024 is the decline in advanced bot attacks targeting the travel industry (41%, down from 61% in 2023) and the sharp increase in simple bot attacks (52%, up from 34%). This shift indicates that AI-powered automation tools have lowered the barriers to entry for attackers, allowing less sophisticated actors to initiate more basic bot attacks. Rather than relying exclusively on sophisticated techniques, cybercriminals are increasingly utilizing high volumes of simpler bots to inundate travel sites, resulting in more frequent and widespread attacks.
The Rise of AI-Driven Bots: A New Era of Cybersecurity Challenges
The emergence of advanced AI tools, including ChatGPT, ByteSpider Bot, ClaudeBot, Google Gemini, Perplexity AI, and Cohere AI, are transforming not just user interactions but also the methods by which attackers execute cyber threats. According to the Imperva Threat Research team, widely used AI tools are being leveraged for cyberattacks, with ByteSpider Bot alone responsible for 54% of all AI-enabled attacks. Other significant contributors include AppleBot at 26%, ClaudeBot at 13%, and ChatGPT User Bot at 6%.
The surge in AI-driven bot creation has serious implications for businesses worldwide, said Tim Chang, General Manager of Application Security, Thales Cybersecurity Products. As automated traffic accounts for more than half of all web activity, organizations face heightened risks from bad bots, which are becoming more prolific every day.
As attackers become more adept at utilizing AI, they can execute a variety of cyber threats-ranging from DDoS attacks to custom rules exploitation and API violations. While bot-driven attacks have become increasingly sophisticated, they pose significant challenges for detection efforts.
This year's report sheds light on the evolving tactics and techniques utilized by bot attackers. What were once deemed advanced evasion methods have now become standard practice for many malicious bots, Chang said. In this rapidly changing environment, businesses must evolve their strategies. Its crucial to adopt an adaptive and proactive approach, leveraging sophisticated bot detection tools and comprehensive cybersecurity management solutions to build a resilient defense against the ever-shifting landscape of bot-related threats.
Bad Bots Targeting API Business Logic Pose Increased Threat to Modern Enterprises
Recent findings from the Imperva Threat Research team reveal a significant surge in API-directed attacks, with 44% of advanced bot traffic targeting APIs. These attacks arent just limited to overwhelming API endpoints; rather, they target the intricate business logic that defines how APIs operate. Attackers deploy bots specifically designed to exploit vulnerabilities in API workflows, engaging in automated payment fraud, account hijacking, and data exfiltration.
Analysis in the report reveals a deliberate strategy by cyber attackers to exploit API endpoints that manage sensitive and high-value data. Implications of this trend are especially impactful for industries that rely on APIs for their critical operations and transactions. Financial services, healthcare, and e-commerce sectors are bearing the brunt of these sophisticated bot attacks, making them prime targets for malicious actors seeking to breach sensitive information.
APIs serve as the backbone of modern applications, enabling connectivity across services, streamlining operations, and delivering personalized customer experiences at scale. They underpin essential functions such as payment processing, supply chain management, and AI-driven analytics, making them indispensable for enhancing efficiency, accelerating product development, and unlocking new revenue streams.
The business logic inherent to APIs is powerful, but it also
Most recent headlines
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
15/04/2025
As women in Afghanistan are stripped of their rights - banned from education, barred from public life and rendered invisible - a number of women journalists con...
15/04/2025
In March this year, Spotify unveiled its annual Loud & Clear report, a transpare...
15/04/2025
As the world's most popular audio-streaming subscription service, Spotify is...
15/04/2025
Claudia Karvan, Tom Gleeson, and Mark Coles Smith join in the adventure of a lif...
15/04/2025
SBS and Volleyball World sign landmark deal for Beach Volleyball World Champions...
15/04/2025
Seven different platforms deliver March's most-watched streaming titles.
St...
15/04/2025
WASHINGTON The Federal Communication Commission's Media Bureau has issued a Notice seeking comments on a major filing by the National Association of Broadca...
15/04/2025
PHILADELPHIA As cable operators face increased competition from fixed wireless plans, Comcast is introducing the option to choose a five-year price guarantee wh...
15/04/2025
MOUNTAIN VIEW, Calif. Kaleidescape has announced that it has joined the 8K Association (8KA)....
15/04/2025
Jan Krupp, VFX supervisor at Scanline VFX, tells TVBEurope how the company created a range of environments for the Netflix film
By Matthew Corrigan
Published...
15/04/2025
Ateliere said that due to the current, unforeseen turbulence in the US and in the global business and financial markets the company is no longer in a position t...
15/04/2025
WASHINGTON In a wide-ranging filing with the Federal Communications Commission, Sinclair applauded the agency's push towards deregulation while arguing that...
15/04/2025
From Homer to Mickey, How ESPN Is Blazing the Live Animated Broadcast Trail ESPNs Amy Nelson, Sparky Sparrgrove, and Spike Szykowny offer an inside look at the ...
15/04/2025
SVG College Sports Media Awards 2025: Final Deadline to Enter is Wednesday All entries must be received by end-of-day April 16 By Brandon Costa, Director of Di...
15/04/2025
Football Summit 2025: BBC Sport and Sunset Vine share plans for UEFA Women's...
15/04/2025
SVG New Sponsor Spotlight: ScorePlay Cofounder and CEO Vic Tixier on Media Manag...
15/04/2025
Inside IOWN: Envisioning a high-speed, high-capacity future for live productions By Joe OHalloran
Tuesday, April 15, 2025 - 09:38
Print This Story
As dele...
15/04/2025
Neither fair nor objective , Mediapro reacts strongly to LaLiga decision to awar...
15/04/2025
HBS and NVP take LaLiga production and distribution for first and second divisio...
15/04/2025
LA28 Details Venue Plans for 2028 Summer Games By Ken Kerschbaumer, Editorial Director
Tuesday, April 15, 2025 - 1:37 pm
Print This Story | Subscribe
St...
15/04/2025
Rohde & Schwarz unleashes the key to unlocking true spectrum dominance in multid...
15/04/2025
Rohde & Schwarz expands testing equipment portfolio to support Telesat Lightspee...
15/04/2025
Matter interoperability has become the foundation of uniting diverse ecosystems. The universal connectivity standard developed by the Connectivity Standards All...
14/04/2025
Rwanda's vulnerability to climate change is underscored by its ranking of 124th out of 182 countries in the Notre Dame Global Adaptation Initiative's in...
14/04/2025
By Bailey Pennick
One of the most exciting things about the Sundance Film Festi...
14/04/2025
On Monday, April 14, Blue Origin's NS-31 mission lifted off from Launch Site...
14/04/2025
Whether it's having first access to tickets, being a part of once-in-a-lifet...
14/04/2025
SBS becomes first Australian broadcaster to have near-and long-term carbon reduc...
14/04/2025
For 190 years, innovation and technology from our talented workforce have distin...
14/04/2025
As Calrec continues to lead a new era of technical innovation with its portfolio of complimentary broadcast audio solutions, the company has today announced the...
14/04/2025
For the first time, advertisers and agencies can directly compare campaign perfo...
14/04/2025
WASHINGTON The Federal Communication Commission's Media Bureau has issued a Notice seeking comments on a major filing by the National Association of Broadca...
14/04/2025
magic multi media unveils new customizable features and advanced AI for EDIUS 11...
14/04/2025
Rotating around an object or layer in After Effects
Graham Quince April 14, 2025
0 Comments
One of the most frequently asked questions on forums is: ...
14/04/2025
Does Clearing the Cache Really Work in Premiere Pro?
Colin Smith April 14, 2025
0 Comments
This tutorial clearly outlines the types of problems that c...
14/04/2025
Stanley has been promoted to the role following seven years as general manager with the company
By Matthew Corrigan
Published: April 14, 2025 Updated: Apri...
14/04/2025
StreamAMG delivers more than 15,000 live events each year, with over 52,000 hours of content watched in 200 countries
By Matthew Corrigan
Published: April 14...
14/04/2025
TVBEurope content director Jenny Priestley sums up her 2025 NAB Show experience, from the end of AI hype to the impact of tariffs, trying out virtual production...
14/04/2025
Ottawa, April 14, 2025 - Ross Video is pleased to announce a new creative partne...
14/04/2025
14 Apr 2025
VEON Publishes 2024 Integrated Annual Report Detailing Commitment t...
14/04/2025
NAB 2025 in Review: Broadcast Audio Faces a Future of Tariff-Induced Higher Cost...
14/04/2025
Changing the world: Behind the collaborative production of the 2025 Special Olym...
14/04/2025
From Paris to Milano Cortina: The International Paralympic Committee on the move...
14/04/2025
SVG College Summit 2025: Jimmy Platt, ESPN's College Football Playoff, Women...
14/04/2025
NAB 2025 in Review: SVG Audio Roundtable Reflects On a Changing Industry Global sports, speech intelligibility, digital microphones are on the table By Dan Dal...
14/04/2025
NAB 2025 in Review: The Pairing of AI and Audio Is Possible But it won't necessarily happen tomorrow By Dan Daley, Audio Editor
Monday, April 14, 2025 - ...
14/04/2025
WNBA Draft 2025: ESPN's Onsite Effort Fits Into NYC Grid for National Teleca...
14/04/2025
Monday 14 April 2025
On an unmissable day of world-class sporting drama, Sky Sports created its own history by breaking viewership records on Sunday 13 April, ...