Artificial Intelligence Fuels Rise of Hard-to-Detect Bots That Now Make up More Than Half of Global Internet Traffic, According to the 2025 Imperva Bad Bot Report
Thales, the leading global technology and security provider, today announced the release of the 2025 Imperva Bad Bot Report, a global analysis of automated bot traffic across the internet. This year’s report, the 12th annual research study, reveals that generative artificial intelligence (AI) is revolutionizing the development of bots, allowing less sophisticated actors to launch a higher volume of bot attacks with increased frequency. Today’s attackers are also leveraging AI to scrutinize their unsuccessful attempts and refine techniques to evade security measures with heightened efficiency, amidst a growing Bots-As-A-Service (BaaS) ecosystem of commercialized bot services.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250415432215/en/
©Thales
Automated bot traffic surpassed human-generated traffic for the first time in a decade, constituting 51% of all web traffic in 2024. This shift is largely attributed to the rise of AI and Large Language Models (LLMs), which have simplified the creation and scaling of bots for malicious purposes. As AI tools become more accessible, cyber criminals are increasingly leveraging these technologies to create and deploy malicious bots which now account for 37% of all internet traffic – a significant increase from 32% in 2023. This is the sixth consecutive year of growth in bad bot activity, posing security challenges for organizations striving to safeguard their digital assets.
Both the Travel and the Retail sectors face an advanced bot problem, with bad bots making up 41% and 59% of their traffic respectively. In 2024, the travel industry became the most attacked sector, accounting for 27% of all bot attacks, up from 21% in 2023. The most notable shift in 2024 is the decline in advanced bot attacks targeting the travel industry (41%, down from 61% in 2023) and the sharp increase in simple bot attacks (52%, up from 34%). This shift indicates that AI-powered automation tools have lowered the barriers to entry for attackers, allowing less sophisticated actors to initiate more basic bot attacks. Rather than relying exclusively on sophisticated techniques, cybercriminals are increasingly utilizing high volumes of simpler bots to inundate travel sites, resulting in more frequent and widespread attacks.
The Rise of AI-Driven Bots: A New Era of Cybersecurity Challenges
The emergence of advanced AI tools, including ChatGPT, ByteSpider Bot, ClaudeBot, Google Gemini, Perplexity AI, and Cohere AI, are transforming not just user interactions but also the methods by which attackers execute cyber threats.According to the Imperva Threat Research team, widely used AI tools are being leveraged for cyberattacks, with ByteSpider Bot alone responsible for 54% of all AI-enabled attacks. Other significant contributors include AppleBot at 26%, ClaudeBot at 13%, and ChatGPT User Bot at 6%.
“The surge in AI-driven bot creation has serious implications for businesses worldwide,” said Tim Chang, General Manager of Application Security at Thales. “As automated traffic accounts for more than half of all web activity, organizations face heightened risks from bad bots, which are becoming more prolific every day.”
As attackers become more adept at utilizing AI, they can execute a variety of cyber threats—ranging from DDoS attacks to custom rules exploitation and API violations. While bot-driven attacks have become increasingly sophisticated, they pose significant challenges for detection efforts.
“This year’s report sheds light on the evolving tactics and techniques utilized by bot attackers. What were once deemed advanced evasion methods have now become standard practice for many malicious bots,” Chang said. “In this rapidly changing environment, businesses must evolve their strategies. It's crucial to adopt an adaptive and proactive approach, leveraging sophisticated bot detection tools and comprehensive cybersecurity management solutions to build a resilient defense against the ever-shifting landscape of bot-related threats.”
Bad Bots Targeting API Business Logic Pose Increased Threat to Modern Enterprises
Recent findings from the Imperva Threat Research team reveal a significant surge in API-directed attacks, with 44% of advanced bot traffic targeting APIs. These attacks aren't just limited to overwhelming API endpoints; rather, they target the intricate business logic that defines how APIs operate. Attackers deploy bots specifically designed to exploit vulnerabilities in API workflows, engaging in automated payment fraud, account hijacking, and data exfiltration.
Analysis in the report reveals a deliberate strategy by cyber attackers to exploit API endpoints that manage sensitive and high-value data. Implications of this trend are especially impactful for industries that rely on APIs for their critical operations and transactions. Financial services, healthcare, and e-commerce sectors are bearing the brunt of these sophisticated bot attacks, making them prime targets for malicious actors seeking to breach sensitive information.
APIs serve as the backbone of modern applications, enabling connectivity across services, streamlining operations, and delivering personalized customer experiences at scale. They underpin essential functions such as payment processing, supply chain management, and AI-driven analytics, making them indispensable for enhancing efficiency, accelerating product development, and unlocking new revenue streams.
“The business logic inherent to APIs is powerful, but it also creates unique vulnerabilities that malicious actors are eager to exploit,” Chang said. “As organizations embrace cloud-based services and microservices architectures, it’s vital to understand that the very features that make APIs essential can also leave them susceptible to risk of fraud and data breaches.”
Financial Services, Healthcare, and E-commerce Industries Face Heightened Risk
The 2025 Imperva Bad Bot Report provides an in-depth analysis highlighting the industries most at risk. Financial services, healthcare, and e-commerce are the most affected sectors, industries that rely on APIs for critical operations and sensitive transactions, making them attractive targets for sophisticated bot attacks.
The financial services sector was the most targeted industry for account takeover (ATO) attacks, accounting for 22% of all incidents, followed by Telecoms and ISPs with 18%, and Computing & IT with 17%. Financial Services has long been a prime target for ATO attacks due to the high value of accounts and the sensitive nature of the data at stake. Banks, credit card companies, and fintech platforms possess vast amounts of Personally Identifiable Information (PII), including credit card and bank account details, which can be profitably sold on the dark web. Additionally, the growing proliferation of APIs within the industry has broadened the attack surface, allowing cyber criminals to exploit vulnerabilities such as weak authentication and authorization methods, thereby facilitating account takeovers and data theft.
About the Research
The 12th Annual Imperva Bad Bot Report is based on insights from our Threat Research and Security Analyst Services (SAS) teams. Our analysis draws from data collected from across the Imperva global network in 2024, including the blocking of 13 trillion bad bot requests across thousands of domains and industries. This dataset provides key insights into bot activity to help organizations understand and address the growing risks of automated attacks.
About Thales
Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion.
The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies.
Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.
PLEASE VISIT
Thales Group
Cybersecurity Products
Cybersecurity Solutions
View source version on businesswire.com: https://www.businesswire.com/news/home/20250415432215/en/
Contacts
PRESS CONTACT
Thales, Media Relations
Security & Cybersecurity
Marion Bonnet
+33 (0)6 60 38 48 92
marion.bonnet@thalesgroup.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
The 2025 Japan Prize Award Ceremony Is Held With Their Majesties the Emperor and Empress of Japan in Attendance16.4.2025 20:00:00 EEST | Press release
The Japan Prize Foundation (President: Ryozo Nagai) held an award ceremony on Wednesday, April 16 at the New National Theatre, Tokyo in Tokyo's Shibuya Ward to confer the Japan Prize on scientists who have made creative and dramatic achievements in the global scientific and technological fields and who have contributed significantly to realizing peace and prosperity for all humanity. Russell Dean Dupuis, Ph.D. (USA), the winner in the field of Materials Science and Production, and Carlos M.・Duarte, Ph.D. (Spain), the winner in the field of Biological Production, Ecology/Environment, were in attendance at the award ceremony, and each field was awarded 1 million Yen together with a certificate and a medal. Each year, the winners of the Japan Prize are recommended by approximately 15,500 prominent scientists and engineers from around the world, and decided by a rigorous examination taking about one year. For 2025, the Foundation received 149 nominations for the field of Materials Science
Kinaxis Recognized as a Leader in the 2025 Gartner ® Magic Quadrant™ for Supply Chain Planning Solutions for the 11th Consecutive Time16.4.2025 19:05:00 EEST | Press release
Kinaxis® Inc. (TSX:KXS), a global leader in end-to-end supply chain orchestration, today announced that it has been positioned as a Leader in the 2025 Gartner® Magic Quadrant™ for Supply Chain Planning Solutions for the 11th consecutive time. According to the report, Kinaxis was positioned as a Leader once again based on its Completeness of Vision and Ability to Execute. Kinaxis delivers end-to-end supply chain orchestration through Maestro™, its AI-powered platform with capabilities spanning sales and operations planning (S&OP), demand and supply planning, production planning, and execution. Kinaxis continues to invest in innovation and scale through its AI-driven automation, composable architecture, and growing global customer base, particularly in high-tech, electronics, and life sciences. "Kinaxis delivered fully fledged attribute-based planning at scale, giving us far more confidence than other suppliers," said Karl Alsop, vice president, Supply Planning, Systems and Analytics at
Dubai AI Week 2025 to Host World’s Largest Generative AI Championship with $272K Prize16.4.2025 16:32:00 EEST | Press release
Dubai is set to unite the global AI ecosystem and advance its future-readiness during a bold exploration of how artificial intelligence is reshaping our world at Dubai AI Week, taking place April 21 to 25. The inaugural event will bring together over 10,000 participants, AI pioneers and policymakers from 100 countries to explore AI’s transformative role in business, governance, and society. Featuring global championships, high-level summits, hackathons and an expo zone, the Week will set the stage for the future of global AI innovation. With collaboration being integral to the success of the global AI landscape, the event joins forces with key government entities, global tech organisations and industry pioneers including Meta, IBM, Google, Microsoft, Gartner, OpenAI, Swift, Nvidia, Palantir, Cohere, and ElevenLabs. The week opens with the AI Retreat on April 21, a closed-door gathering of global AI leaders, policymakers, and industry experts focusing on shaping AI strategies and govern
Abu Dhabi Launches Life Sciences Cluster to Advance Healthcare Innovation Worldwide, tapping a $25.3 trillion market16.4.2025 16:30:00 EEST | Press release
Abu Dhabi has launched the groundbreaking life sciences cluster, reinforcing its position as a global hub for biotechnology, MedTech, and digital health. Developed by the Abu Dhabi Department of Economic Development, Abu Dhabi Investment Office (ADIO) and the Department of Health – Abu Dhabi, the Health, Endurance, Longevity, and Medicine (HELM) cluster is designed to drive healthcare innovation, attract international investment, and deliver lasting benefits to global populations. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250416840862/en/ Abu Dhabi Launches Life Sciences Cluster to Advance Healthcare Innovation Worldwide, tapping a $25.3 trillion market (Photo: AETOSWire) Announced during Abu Dhabi Global Health Week, the HELM cluster will serve as a platform for the research, development, manufacturing and commercialisation of advanced health and life science solutions. From AI-powered diagnostics and pharmaceutical ma
Artificial Intelligence Triumphs in World’s Most Sophisticated Autonomous Drone Race in Abu Dhabi16.4.2025 16:15:00 EEST | Press release
The Abu Dhabi Autonomous Racing League (A2RL), part of the Advanced Technology Research Council (ATRC), in collaboration with the Drone Champions League (DCL), concluded the inaugural A2RL x DCL Autonomous Drone Championship in the Middle East, at ADNEC Marina Hall, Abu Dhabi, UAE. In a major breakthrough for autonomous flight and aerial robotics, Team MavLab’s AI drone outpaced a world-leading human pilot to win the AI vs Human Challenge. The head-to-head duel was the most complex ever staged, featuring finalists from the DCL Falcon Cup—some of the top drone pilots in the world. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250416147445/en/ Artificial Intelligence Triumphs in World’s Most Sophisticated Autonomous Drone Race in Abu Dhabi (Photo: AETOSWire) Over two high-intensity days, 14 international teams qualified for the finals week, with the top four advancing to compete across multiple challenging race formats. Teams
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom