DataDome, the leader in bot and agent trust management, today released The State of Bot & Agent Security Report, 2026 Edition, an analysis of more than one trillion requests across 75,000+ customer sites and a test of more than 20,000 popular websites.
Malicious automated traffic grew more than nine times faster than human traffic between July 2025 and June 2026, with bad bot traffic increasing 124%. Scraping remained the leading threat, rising 185% year over year. At the same time, AI bots are moving beyond just crawling homepages, targeting login pages 8x more.
"Automated traffic isn't just a volume problem at the edge of the internet anymore. It's growing fast, and it's going deeper: into the login, account, and transaction flows at the center of the customer journey," said Jerome Segura, VP of Threat Research at DataDome. "For businesses, the challenge is no longer simply identifying automation; it is determining whether that activity is beneficial or harmful."
Key findings: Bad bots are growing 9x faster than human traffic. Scraping is the largest and fastest-growing attack vector accounting for 70.9% of bad bot traffic. The growth may be connected to an expanding AI data supply chain, in which third-party data resellers and applications building AI agents collect web data at scale for training and other AI services.
Scalping activity increased 290.7% with median daily volume nearly quadrupling. Account-related abuse is increasing across several attack paths. Fake account creation grew 34.5%. Credential stuffing remained cyclical rather than declining, with activity surging, dropping by nearly 90%, and later recovering to new single-day highs. This pattern suggests attackers are opportunistically leveraging batches of leaked credentials.
AI traffic is reaching high-value user journeys. In H1 2026, AI agents generated 605.6 million requests to login pages, forms, carts, payment flows, and account-creation pages, with login pages accounting for 51.7% of that traffic. Total AI traffic increased 82.3% during the study period, bringing more automated traffic into the mix, including both beneficial and harmful activity.
The same crawling that can help users discover products and information can be difficult to distinguish from unwanted scraping, particularly when it reaches these high-value endpoints. Identity-based controls cannot make that distinction, so businesses need to evaluate what each session is trying to do.
Most websites remain unprotected against bots and AI agents. In the expanded scan, 65.3% of tested websites stopped none of the 10 bot types evaluated. Only 2.4% stopped all of them, down from 8.4% in 2024 and 2.8% in 2025.
"Organizations are being asked to make more nuanced decisions with defenses that are still largely built around binary choices," added Segura. "The ability to distinguish a legitimate AI assistant from a credential-testing bot or an automated account-abuse campaign will be critical to protecting customers without blocking beneficial activity."
Taken together, these findings point to a widening gap between the traffic businesses need to understand and the defenses they have in place. As automated systems move through the same login, account, and transaction flows as human users, intent becomes the critical signal for deciding what to allow and what to stop.
About DataDome
DataDome is the leader in bot and agent trust management, providing complete visibility and control over all traffic, whether human, bot, or AI agent. Named a Leader in The Forrester Wave: Bot and Agent Trust Management Software, Q2 2026, DataDome is trusted by enterprises like Etsy, PayPal, and SoundCloud. Acting as your real-time traffic control plane, DataDome's multi-layered AI engine leverages thousands of models and 5 trillion signals daily to analyze the intent of every session in under 2 milliseconds.