AI-driven Bot Attacks Surged 12.5x According to Thales Bad Bot Report
29.4.2026 10:00:00 EEST | Business Wire | Press release
Thales today released the 2026 Bad Bot Report: Bad Bots in the Agentic Age, revealing a fundamental shift in how the internet operates, as AI-accelerated automation becomes a defining feature of modern digital infrastructure.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260428783532/en/
©Thales
The findings highlight three major structural changes: the emergence of AI agents as a new category of internet traffic, the dominance of automated activity over human interaction, and the rapid expansion of attacks targeting APIs and identity systems that serve as the backbone of digital business.
AI Is Redefining Internet Traffic and Security
The report shows that AI is not just increasing the volume of bot activity, but fundamentally changing its nature. In 2025, AI-driven bot attacks surged 12.5x compared to the previous year.
More significantly, AI agents are now emerging as a third category of traffic, alongside traditional “good” and “bad” bots, interacting directly with applications and APIs to retrieve data and perform tasks. This shift is blurring the line between legitimate and malicious automation, making it increasingly difficult for organizations to determine intent.
“AI is transforming automation from something organizations try to block into something they must also manage,” Tim Chang, Global Vice President and General Manager, Application Security at Thales, said. “The challenge is no longer identifying bots. It’s understanding what the bot, agent, or automation is doing, whether it aligns with business intent, and how it interacts with critical systems.”
This evolution is creating a growing visibility gap. Much of today’s AI-driven activity remains unverified or indistinguishable from legitimate traffic, meaning organizations are operating with an incomplete view of the risks they face.
Bots Increasingly Outnumber Humans Online
The report shows automation tightening its grip on the internet, with bots continuing to outpace human activity. In 2025, bots made up more than 53% of all web traffic, up from 51% the previous year, while human activity fell to 47%. This reflects a structural shift rather than a temporary trend, with bots no longer tied to specific events like scraping or credential stuffing campaigns, but instead operating as a persistent and expected presence across digital environments.
APIs and Identity Systems Become the Primary Attack Surface
As digital services increasingly rely on APIs to power core functionality, attackers are following suit. The report finds that 27% of bot attacks now target APIs, where bots can bypass user interfaces and interact directly with backend systems at machine speed.
These attacks often appear legitimate, using valid authentication and well-formed requests, but exploit business logic, extract sensitive data, or manipulate workflows at scale. The impact is especially pronounced in high-value sectors. Financial services accounted for 24% of all bot attacks and 46% of account takeover incidents, underscoring how automation is being used to directly monetize cyberattacks.
A New Era of Machine-Driven Interaction
As AI adoption accelerates, the report reveals that the internet is now fundamentally machine driven. Bots are no longer simply tools used by attackers; they are active participants in digital systems, shaping traffic patterns, influencing business metrics, and interacting with systems in real time. In this environment, the ability to manage automation at scale with precision is critical to maintaining security, performance, and trust.
Confronting the Rise of Uncontrolled Automation
The report concludes that traditional security approaches focused on identifying and blocking bots are not sufficient in an environment where automation is both pervasive and often legitimate. Organizations must move toward a governance-based model, combining visibility, policy enforcement, and behavioral analysis to distinguish between acceptable and harmful automation. This includes defining which AI agents are allowed to interact with systems, implementing controls at the API and identity layer, and designing defenses that can adapt as bots evolve.
For more information and recommendations, please download the full report and join our webinar to learn more about technologies that can be deployed against malicious bots.
Methodology
The 2026 Thales Bad Bot Report analyzes full-year 2025 bot activity using data from Thales Threat Research and Security Analyst Services teams. The report examines how automation, powered by AI, is reshaping application security, API exposure, and digital infrastructure globally.
About Thales
|
PLEASE VISIT
Thales Group
Cybersecurity Products | Thales Group
Cybersecurity Solutions | Thales Group
View source version on businesswire.com: https://www.businesswire.com/news/home/20260428783532/en/
Contacts
PRESS CONTACT
Thales, Media Relations
Security & Cybersecurity
Marion Bonnet
+33 (0)6 60 38 48 92
marion.bonnet@thalesgroup.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Andreas Goppelt Appointed Managing Director of OrphaCare29.4.2026 11:27:00 EEST | Press release
OrphaCare, a global specialist for the development and marketing of medical devices for drug delivery and part of the AOP Health Group, has appointed Andreas Goppelt as its new Managing Director, succeeding Georg Fischer. In this role, the seasoned medical device expert will focus on broadening the company’s strategic scope and driving its next phase of growth. OrphaCare plays a key role in supporting AOP Health’s integrated therapies approach, and the Group’s long-term expansion. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260429303533/en/ Portrait Andreas Goppelt, Managing Director OrphaCare (copyright: AOP Health/Studio Koekart) Andreas Goppelt brings more than 25 years of leadership experience across MedTech, biotechnology and the pharmaceutical industry. He has a proven track record of driving innovation, scaling global organizations, and delivering growth in highly regulated healthcare environments. In his new role,
The Jury Has Been Announced for the Third Edition of the Reply AI Film Festival, Dedicated to the Best Short Films Generated With Artificial Intelligence29.4.2026 11:00:00 EEST | Press release
Reply [EXM, STAR: REY], an international group specialized in creating new business models enabled by AI and long committed to guiding younger generations in exploring emerging technologies, presents the jury of the third edition of the Reply AI Film Festival, the international competition aimed at creatives, directors, and filmmakers who want to challenge themselves in producing short films created using Artificial Intelligence tools. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260429288361/en/ “Imaginatio Nova” is the theme of the 2026 edition, an invitation to explore a new phase of imagination, where human creativity is renewed through technology. Leading the jury will be Gabriele Salvatores, Italian director and screenwriter known for films such as Nirvana, Siberian Education, and Napoli - New York, and Academy Award® winner for Best Foreign Language Film with Mediterraneo. Joining him on the panel for the third edit
Bregal Milestone Announces Majority Growth Investment in CoreGo, a Leading European Open-Loop Payment and Event Technology Company29.4.2026 11:00:00 EEST | Press release
Bregal Milestone, a leading European software growth private equity firm, today announced a majority strategic growth investment in CoreGo Oy ("CoreGo" or the "Company"), a leading provider of open-loop payments and integrated technology solutions for festivals, sports events, and venues across Europe. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260427991105/en/ Founded in Helsinki in 2015 by Hannu Elomaa and CTO Nikoteemu Väänänen, CoreGo has built one of Europe's most differentiated open-loop payment infrastructure and event technology businesses. Serving approximately 250 customers across the Nordics and DACH region, the Company delivers an integrated showtime-critical suite of solutions through CoreGo Cloud, unifying payments, access, networks, and data into a single real-time operating system. CoreGo’s in-house private network capability, the only such offering among pure-play event technology providers in Europe, en
Vonage Named a Leader in the 2026 IDC MarketScape for Worldwide Communications Engagement Platforms29.4.2026 10:30:00 EEST | Press release
Vonage, a part of Ericsson (NASDAQ: ERIC), today announced that it has been positioned in the Leaders Category in the 2026 IDC MarketScape for the Worldwide Communications Engagement Platforms (CEP) sector. Vonage believes this recognition reflects Vonage's comprehensive communications platform that enables enterprises to reimagine customer and employee engagement at global scale. The IDC MarketScape: Worldwide Communications Engagement Platforms 2026 Vendor Assessment (Doc #US53542326, April 2026) provides a comprehensive assessment of select communications engagement platform (CEP) vendors, highlighting their strengths, challenges, and strategic direction to guide technology buyers in making informed decisions. Vonage believes its placement in the Leaders Category underscores the breadth and depth of its portfolio, underpinned by advanced AI capabilities. Built with enterprise businesses and developers in mind, Vonage provides the tools and flexibility to quickly build and customize
OpenGate Capital Signs Definitive Agreement to Acquire Total Safety’s Europe and Middle East Division29.4.2026 10:00:00 EEST | Press release
OpenGate Capital (“OpenGate”), a global private equity firm, announced today that it has signed a definitive agreement to acquire the European and the Middle Eastern (“EMEA”) division of Total Safety, a Littlejohn & Co. portfolio company. Total Safety EMEA is a leading provider of mission-critical safety and compliance solutions serving petrochemical and oil & gas customers across EMEA. The company focuses on workforce protection and regulatory compliance in complex, safety critical environments. Terms of the acquisition were not disclosed. Headquartered in Diepenbeek, Belgium, Total Safety EMEA offers a fully integrated, one-stop platform spanning safety services, rental equipment and product sales. Services include the deployment of highly trained personnel for critical safety operations, short- and long-term rental of essential equipment and the supply of personal protective equipment. As a trusted partner embedded in highly regulated environments, Total Safety EMEA supports clients
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom