

The Growing Threat of Bad Bots in eCommerce and How to Fight Back


Listen Full Blog Here
Key Takeaways
- »Bad bots made up 43% of eCommerce traffic in holiday 2025, up from 31%.
- »Nearly 70% of bad bot traffic was low-sophistication, as AI makes bots easier to build.
- »Scraping, account takeover, fake signups, cart abuse, and carding all hurt revenue.
- »AI agents sent 605.6 million requests to logins, carts, and payment flows in H1 2026.
- »Native mobile apps need their own protection, since CAPTCHA and browser checks fall short.
- »Layered defense works best: bot management, mobile protection, integrated security, and managed services.
Imagine that on the busiest shopping days of the year, more than half the traffic to your eCommerce site isn’t human. Instead, it’s automated bots.
That’s not hyperbole! It’s reality! During the 2024 holiday shopping season, an astonishing 57% of total eCommerce website traffic came from bots, both benign and malicious, far outpacing human visitors for the first time.
Even more alarming, bad bots alone accounted for roughly 31% of total traffic, nearly doubling from just 16% two years prior. And the tactics are more devious than ever. Nearly 60% of these malicious bots used advanced behavioral mimicry, like realistic mouse movements and human-like navigation, to slip past legacy defenses undetected.
The 2025 holiday season pushed those numbers further. According to Radware's 2026 E-Commerce Bot Threat Report, bad bots made up 43% of eCommerce traffic, up from 31% a year earlier, while human shoppers generated 46%.
This is more than click fraud. The bots are sabotaging your revenue, hijacking inventory, and quietly eroding customer trust right under your nose.
How Bots Attack eCommerce

Bots are no longer crude scripts that are easy to detect and block. Today’s automated threats are sophisticated, distributed, and adaptive. They don’t just slow down your site. They directly target revenue, brand reputation, and customer trust.
Based on analysis of client traffic data during the 2024 holiday shopping season, here are the primary bot attack types and their impact:
1. Price Scraping
Attack Mechanism:
Bots systematically extract product pricing information at scale, typically by competitors or aggregators tracking flash sales, limited-time offers, and dynamic price adjustments. Modern scraping bots can harvest massive datasets while mimicking human browsing behavior.
Holiday Traffic Data:
- Over 1.2 million scraping attempts were detected and blocked during a 30 day holiday period.
- On Black Friday alone, 112,000 instances were recorded across 63,000 unique product pages.
Business Impact:
- Competitive Disadvantage: Competitors neutralize your pricing strategy by gaining real time insights.
- Infrastructure Overload: High bot traffic strains systems, slowing down genuine shoppers.
- Skewed Analytics: Inflated traffic distorts customer behavior insights, leading to poor marketing decisions.
2. Content Scraping
Attack Mechanism:
Bots extract proprietary content like product descriptions, reviews, and images, to repurpose on competing sites.
Holiday Traffic Data:
- 5x spike in scraping activity the day before Black Friday (58,000 bot hits in a single day).
- Attacks targeted over 7,000 unique URLs and 340+ category pages.
Business Impact:
- SEO Damage: Duplicate content hurts rankings.
- Lost Differentiation: Competitors copy your unique value proposition.
- Customer Confusion: Identical content across sites erodes trust.
3. Account Takeover (ATO)
Attack Mechanism:
Bots use stolen credentials and brute force attempts to hijack customer accounts, targeting stored payment info and personal data.
Holiday Traffic Data:
- 3x increase in ATO attempts the day before Black Friday (~50,000 hits).
- Over 500,000 ATO attempts were detected in just 30 days.
- 60% of peak day bot hits required behavioral based detection, showing attackers deployed their most advanced bots.
Business Impact:
- Financial Losses: Fraud, chargebacks, lawsuits, and remediation costs.
- Customer Distrust: Breaches of sensitive data erode loyalty.
- Regulatory Risk: Potential GDPR, CPRA, and NIS2 penalties.
4. Fake Account Registrations
Attack Mechanism:
Bots create large volumes of fake accounts to abuse promotions, discounts, and referral programs.
Holiday Traffic Data:
- 613,000 fake accounts created in one day (Nov 26, 2024).
- Over 14 million attempts during the 30 day holiday season.
- Attacks were distributed across 200,000+ unique IPs and user agents to evade detection.
Business Impact:
- Promotion Abuse: Exploiting offers meant for new customers.
- Distorted Metrics: Inflated customer acquisition and conversion numbers.
- Fraud Gateway: Fake accounts often enable further carding and scam activity.
5. Cart Abuse
Attack Mechanism:
Bots add items to carts without completing purchases, blocking real customers from buying limited stock goods.
Holiday Traffic Data:
- 130,000+ cart abandonment attempts recorded on Black Friday alone.
- Attacks were distributed across thousands of IPs to bypass detection.
Business Impact:
- Lost Sales: Genuine buyers are locked out of high demand items.
- Skewed Analytics: Inflated cart abandonment rates mislead marketing teams.
- Inventory Chaos: False demand signals disrupt supply chain forecasting.
6. Carding Attacks
Attack Mechanism:
Bots test stolen credit/debit cards in bulk against eCommerce payment workflows, validating data for fraud or resale.
Holiday Traffic Data:
- 768,000 carding attempts were detected and blocked in a 30 day holiday window.
Business Impact:
- Chargebacks & Penalties: Costly refunds, payment processor fines, and investigation expenses.
- Customer Distrust: Victims lose confidence in your platform.
- Regulatory Exposure: Non-compliance with PCI DSS and data protection laws.
What Changed in the 2025 Holiday Season
Radware's 2026 E-Commerce Bot Threat Report, covering the 2025 holiday season, added three findings:
- Bad bots reached 43% of traffic. That is up from 31% a year earlier and close behind the 46% generated by human shoppers.
- Most bad bots were basic. Nearly 70% of bad bot traffic was low-sophistication, up from 44% the year before. AI tools let more attackers build working bots, so volume is growing faster than cleverness.
- AI agents joined the mix. AI crawlers and shopping agents now visit stores to collect content, compare prices, and sometimes buy on a customer's behalf. Some of that traffic is wanted, so "block every bot" is a poor rule.
Rising Bot Threats Retailers Can't Ignore in 2026
Bad bots are evolving rapidly, and several emerging threat vectors are expected to challenge eCommerce security teams in the upcoming holiday season.
1. AI-Enhanced Bots
The most significant shift is the rise of AI powered bots, fueled by generative AI and automation tools. These bots are:
- Easier to build: Even less experienced attackers can now script bots with simple prompts.
- Smarter & stealthier: Capable of human like browsing, adaptive decision making, and evading detection.
- Equipped with advanced capabilities:
Natural language processing to auto fill forms, create fake accounts, or simulate engagement.
Optical Character Recognition (OCR) and machine learning to bypass image and audio based CAPTCHA.
Autonomous, agentic AI bots that require minimal human input and continuously retool themselves.
This enables faster bot development cycles and more persistent attack campaigns.
2. Mobile Focused Attacks
With mobile shopping dominating eCommerce growth, malicious actors are increasingly turning to mobile applications as targets:
- Native apps rely heavily on APIs and often lack browser based validation.
- Traditional defenses like CAPTCHA or JavaScript checks are far less effective in mobile environments.
- These gaps make mobile apps vulnerable to account fraud, credential stuffing, and API abuse.
3. Distributed Infrastructure Attacks
The use of cloud infrastructure and residential proxy networks is making detection harder:
- Attack traffic appears to come from legitimate, trusted sources.
- Constant IP and identity rotation allow bots to slip past defenses.
- This distributed approach enables large scale attacks that overwhelm security systems.
4. Multi Vector Attack Strategies
Modern attackers increasingly deploy coordinated, multi layered campaigns, combining:
- Bot driven scraping and credential abuse.
- Exploits targeting web application vulnerabilities.
- Business logic manipulation.
- API – specific attacks.
This multi pronged approach complicates defense efforts and increases the chances of successful breaches.
How Retailers Can Defend Against Bot Attacks
The numbers are alarming, but eCommerce organizations are not powerless. With the right strategies, businesses can strengthen their defenses against even the most sophisticated bot threats. Here are the key steps retailers should prioritize:
1. Implement Advanced, Multi-Layered Bot Management
Modern bots are designed to slip past legacy defenses, so businesses need equally advanced countermeasures. A multi layered solution should include:
- Preemptive Protection: Block known malicious identities using the latest threat intelligence before attacks even materialize.
- AI Powered Detection: Use behavioral based algorithms to spot human like bots in real time, even those using tactics like rotating IPs, distributed attacks, or CAPTCHA solving.
- Granular Mitigation: Apply adaptive mitigation challenges (including invisible, non interactive methods) to stop malicious bots without disrupting genuine shoppers.
2. Develop Mobile-Specific Security Strategies
Mobile shopping now drives the majority of eCommerce traffic, which also makes it a prime target. Retailers should:
- Integrate mobile bot management SDKs within native apps for deeper visibility into mobile specific threats.
- Defend against emulators, device spoofing, and tampered apps to ensure only genuine devices can transact.
- Recognize that traditional web defenses (like browser validation and CAPTCHA) are not enough for mobile environments.
3. Adopt an Integrated Application Security Strategy
Attackers don’t rely on one method, nor should defenders. A siloed approach to security leaves blind spots. Instead:
- Consolidate bot management, WAF, API security, DDoS protection, and client side protection into a holistic, integrated strategy.
- Cross correlate threats across different modules for end to end visibility.
- Maintain consistent security policies across all application layers to ensure coordinated defense against multi vector campaigns.
4. Onboard Managed Security Services
For many retailers, especially during peak holiday seasons, internal teams may not have the bandwidth to manage 24/7 defense. Partnering with specialized security experts can provide:
- 24/7 monitoring and rapid incident response.
- Proactive intelligence on emerging threats.
- Expert skillsets to handle complex, large scale attacks.
- Shared responsibility that reduces downtime and ensures protection even during traffic surges.
5. Separate Helpful AI Agents From Harmful Bots
Not every automated visitor is an attacker. AI crawlers index your catalog for search and AI assistants, and shopping agents may act for a real customer with real purchase intent. Blanket blocking can cost you sales and AI visibility. Set rules by behavior: allow verified agents that follow your policies, challenge or rate-limit unverified ones, and block the ones that scrape, hoard carts, or test cards.
Prepare Before Peak Season Starts
Bad bots made up 43% of eCommerce traffic in the 2025 holiday season, and AI keeps making them easier to build. Layered bot management, mobile protection, and a plan for AI agents are worth having in place before Black Friday on November 27, not after the first attack.
If you want a second opinion on how your Adobe Commerce (Magento) or Shopify store handles automated traffic, get in touch with Codilar.
FAQs
Bad bots are automated programs designed to perform malicious activities on websites. In eCommerce, they can scrape pricing and content, hijack accounts, create fake accounts, manipulate carts, and execute fraudulent transactions. These activities can directly impact revenue, skew analytics, damage brand reputation, and erode customer trust.
Bot attacks are now a regular part of eCommerce traffic. In the 2024 holiday season, bots made up 57% of eCommerce traffic and bad bots 31%. In the 2025 holiday season, bad bots rose to 43%, close behind the 46% generated by human shoppers.
Advanced bots mimic human behavior with realistic mouse movements and distributed proxy networks, and some use AI to solve CAPTCHAs and fill forms. At the same time, most bad bot traffic is now basic: nearly 70% in the 2025 holiday season, because AI makes bots easier to build. Stores now face more attackers, using a mix of simple and advanced bots.
Price and content scraping: stealing pricing and proprietary content. Account takeover (ATO): hijacking customer accounts with stolen credentials. Fake account registrations: exploiting promotions and enabling further fraud. Cart abuse: blocking genuine customers from buying limited-stock items. Carding attacks: testing stolen payment cards against checkout.
A multi-layered defense works best: Advanced bot management with AI-based detection. Mobile-specific protection for native apps. Integrated application security that combines WAF, API security, DDoS protection, and client-side defenses. Rules that treat AI agents by behavior instead of blocking them all. Managed security services for continuous monitoring and rapid incident response.

eRetail Growth
in Mind?
Get tailored technology solutions to scale your retail business online
Request A Quote
Subscribe to
Stay in Know
Stay ahead with insights, trends, and brand success stories from the world of Digital Commerce.






