AI-driven Bot Attacks Surged 12.5x According to Thales Bad Bot Report
29.4.2026 09:00:00 CEST | Business Wire | Press Release
Thales today released the 2026 Bad Bot Report: Bad Bots in the Agentic Age, revealing a fundamental shift in how the internet operates, as AI-accelerated automation becomes a defining feature of modern digital infrastructure.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260428783532/en/
©Thales
The findings highlight three major structural changes: the emergence of AI agents as a new category of internet traffic, the dominance of automated activity over human interaction, and the rapid expansion of attacks targeting APIs and identity systems that serve as the backbone of digital business.
AI Is Redefining Internet Traffic and Security
The report shows that AI is not just increasing the volume of bot activity, but fundamentally changing its nature. In 2025, AI-driven bot attacks surged 12.5x compared to the previous year.
More significantly, AI agents are now emerging as a third category of traffic, alongside traditional “good” and “bad” bots, interacting directly with applications and APIs to retrieve data and perform tasks. This shift is blurring the line between legitimate and malicious automation, making it increasingly difficult for organizations to determine intent.
“AI is transforming automation from something organizations try to block into something they must also manage,” Tim Chang, Global Vice President and General Manager, Application Security at Thales, said. “The challenge is no longer identifying bots. It’s understanding what the bot, agent, or automation is doing, whether it aligns with business intent, and how it interacts with critical systems.”
This evolution is creating a growing visibility gap. Much of today’s AI-driven activity remains unverified or indistinguishable from legitimate traffic, meaning organizations are operating with an incomplete view of the risks they face.
Bots Increasingly Outnumber Humans Online
The report shows automation tightening its grip on the internet, with bots continuing to outpace human activity. In 2025, bots made up more than 53% of all web traffic, up from 51% the previous year, while human activity fell to 47%. This reflects a structural shift rather than a temporary trend, with bots no longer tied to specific events like scraping or credential stuffing campaigns, but instead operating as a persistent and expected presence across digital environments.
APIs and Identity Systems Become the Primary Attack Surface
As digital services increasingly rely on APIs to power core functionality, attackers are following suit. The report finds that 27% of bot attacks now target APIs, where bots can bypass user interfaces and interact directly with backend systems at machine speed.
These attacks often appear legitimate, using valid authentication and well-formed requests, but exploit business logic, extract sensitive data, or manipulate workflows at scale. The impact is especially pronounced in high-value sectors. Financial services accounted for 24% of all bot attacks and 46% of account takeover incidents, underscoring how automation is being used to directly monetize cyberattacks.
A New Era of Machine-Driven Interaction
As AI adoption accelerates, the report reveals that the internet is now fundamentally machine driven. Bots are no longer simply tools used by attackers; they are active participants in digital systems, shaping traffic patterns, influencing business metrics, and interacting with systems in real time. In this environment, the ability to manage automation at scale with precision is critical to maintaining security, performance, and trust.
Confronting the Rise of Uncontrolled Automation
The report concludes that traditional security approaches focused on identifying and blocking bots are not sufficient in an environment where automation is both pervasive and often legitimate. Organizations must move toward a governance-based model, combining visibility, policy enforcement, and behavioral analysis to distinguish between acceptable and harmful automation. This includes defining which AI agents are allowed to interact with systems, implementing controls at the API and identity layer, and designing defenses that can adapt as bots evolve.
For more information and recommendations, please download the full report and join our webinar to learn more about technologies that can be deployed against malicious bots.
Methodology
The 2026 Thales Bad Bot Report analyzes full-year 2025 bot activity using data from Thales Threat Research and Security Analyst Services teams. The report examines how automation, powered by AI, is reshaping application security, API exposure, and digital infrastructure globally.
About Thales
|
PLEASE VISIT
Thales Group
Cybersecurity Products | Thales Group
Cybersecurity Solutions | Thales Group
View source version on businesswire.com: https://www.businesswire.com/news/home/20260428783532/en/
Contacts
PRESS CONTACT
Thales, Media Relations
Security & Cybersecurity
Marion Bonnet
+33 (0)6 60 38 48 92
marion.bonnet@thalesgroup.com
(c) 2024 Business Wire, Inc., All rights reserved.
Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
MTU Maintenance Lease Services Invests in TRecs to Digitalise Engine Transition Management13.5.2026 10:05:00 CEST | Press Release
MTU Maintenance Lease Services B.V. (“MLS”), the engine leasing and asset management arm of MTU Maintenance, today announced a strategic minority investment in TRecs (trecs.aero). TRecs is a platform digitalising Open Item List (OIL) management across the engine lifecycle, from initial technical review through transitions, shop visits, and beyond. Terms of the transaction are kept confidential. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260513682497/en/ Through its deployment of TRecs, MLS moves further into its leading role in moving the engine leasing industry toward a cloud-based, collaborative standard designed specifically for leasing and asset management customers. MLS will use the platform across the engine lifecycle, from the initial technical review of acquired or leased-in engines through end-of-lease documentation and task tracking for lease returns, shop visits, and asset transitions, in a centralised, real-t
NIPPON KINZOKU Strengthens Promotion of "L-Core" as an Eco-Product: Functional Stainless Steel Achieving High Conductivity via Surface Modification13.5.2026 10:01:00 CEST | Press Release
NIPPON KINZOKU CO., LTD. (TOKYO: 5491) (Headquarters: Minato-ku, Tokyo) is proud to announce the strengthened promotion of "L-Core," a functional stainless steel that utilizes proprietary surface modification technology to achieve extremely low contact resistance while maintaining the inherent corrosion resistance of stainless steel. We have repositioned L-Core as a strategic "Eco-Product" to support sustainable manufacturing. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260513728897/en/ While conventional stainless steel excels in corrosion resistance due to its "passive film," this same film typically acts as an electrical insulator. Consequently, components requiring conductivity have traditionally relied on high-cost nickel (Ni) plating or conductive tapes. L-Core solves this challenge by making the passive film itself conductive. This breakthrough ensures high conductivity in the material alone, streamlining the manuf
Hermes Reply Presents Brick Cognitive, the Agentic Operating System for Manufacturing13.5.2026 10:00:00 CEST | Press Release
Hermes Reply, the Reply Group company specialized in digital transformation for manufacturing, presents Brick Cognitive, the new agentic operating system designed to bring AI to the centre of industrial operations. A natural extension of Brick Reply, Reply’s next-generation MES/MOM platform, Brick Cognitive introduces a model in which factory systems no longer simply execute and monitor operations, but isable to interpret what is happening, correlate events and guide action across production, quality, maintenance and planning. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260513981153/en/ Brick Reply, Reply’s next-generation MES/MOM platform, Brick Cognitive introduces a model in which factory systems no longer simply execute and monitor operations, but is able to interpret what is happening, correlate events and guide action across production, quality, maintenance and planning. In production environments, data and processe
MC Advances Supply Chain Transformation with Blue Yonder Cognitive Solutions13.5.2026 10:00:00 CEST | Press Release
MC, the retail division of Sonae and a leading player in Portugal’s grocery market and health, wellness, and beauty retail across the Iberian Peninsula, has selected Blue Yonder Cognitive Solutions for Allocation and Replenishment to advance its supply chain transformation. With more than 400 stores across multiple formats, MC operates major supermarkets and hypermarkets such as Continente, along with convenience stores, health and wellness shops, and online grocery services. Blue Yonder’s advanced artificial intelligence (AI) and machine learning (ML) enabled solutions will help the company improve visibility into demand forecasting. The new solutions will be implemented by Blue Yonder Services. “The grocery retail sector is adapting to a period of significant change, underlining the need for more agile operations across the supply chain. We needed end-to-end visibility and faster, more accurate inventory planning to address demand uncertainty while prioritizing our business goals,” s
Oral‑B Announces The Big Rethink 2026 , Launching One of Europe’s Largest Disability‑Focused Oral Health Studies13.5.2026 09:06:00 CEST | Press Release
Oral‑B today announces The Big Rethink 2026, the next evolution of its flagship oral health inclusion programme, developed in partnership with the International Association for Disability and Oral Health (iADH). The new phase introduces Project Steady, one of Europe’s largest real‑world studies exploring oral care experiences among people with disabilities, their carers and dental professionals. The programme aims to reduce everyday barriers to oral care through inclusive design, evidence-based research and professional education. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260511175864/en/ Oral B Announces The Big Rethink 2026, Launching One of Europe’s Largest Disability Focused Oral Health Studies Oral health for Whole-Body Health Since its launch in 2022, The Big Rethink has been grounded in a clear belief: oral health is fundamental to whole‑body health, confidence and quality of life. For people with disabilities, b
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom