HUMAN BLOG

Report Test

July 17, 2026

Uncategorized

The Automated Internet Report

How AI and Bots Are Reshaping Traffic, Growth, and Risk

Lorem ipsum dolor sit amet consectetur. Egestas vestibulum aliquet maecenas purus purus cursus ullamcorper. Adipiscing vulputate ultrices enim enim cursus ullamcorper.

  • ~8x

    Automation is growing roughly 8x faster than human traffic

  • 3.10%

    Human traffic growth YoY

  • 23.51%

    Automation growth YoY

Key Findings

The most consequential signals from our 2025 telemetry

Traffic Automation vs. Human Growth

  • Automation is growing roughly 8 times faster than human traffic. Human traffic grew 3.10% YoY while automation grew 23.51% YoY.
  • Approximately 48% of total traffic growth in 2025 came from automation.
  • At current differential growth, automation will double human growth contribution within 3 to 4 years.
  • Traffic from AI scrapers grew approximately +597%, a 7x increase. In peak months, request volume was up as much as 1,125% higher than the January baseline, or 12x.
  • Media, travel, and ecommerce drove 97% of total increase.

Agents AI Agent Activity

  • 7,851.3% increase in traffic from AI agents and agentic browsers YoY.
  • 77% of agent interactions are with product and search pages.

Agents AI Agent Activity

  • 7,851.3% increase in traffic from AI agents and agentic browsers YoY.
  • 77% of agent interactions are with product and search pages.

Agents AI Agent Activity

  • 7,851.3% increase in traffic from AI agents and agentic browsers YoY.
  • 77% of agent interactions are with product and search pages.

Attacks Threat Landscape Shifts

  • Attempted ATO attacks fell 30.6% from 2024 to 2025, while attempted scraping attacks rose 46.9%.
  • Scraping now approaches 20% of all traffic globally at the median.
  • Fake account creation volume increased 89% from 2024 to 2025, after a 259% increase from 2023 to 2024.

Attacks Threat Landscape Shifts

  • Attempted ATO attacks fell 30.6% from 2024 to 2025, while attempted scraping attacks rose 46.9%.
  • Scraping now approaches 20% of all traffic globally at the median.
  • Fake account creation volume increased 89% from 2024 to 2025, after a 259% increase from 2023 to 2024.

Introduction

The new reality of AI-mediated commerce

Agentic commerce isn’t a hypothetical anymore. Consumers are shopping through AI-powered assistants, comparing across platforms, and even checking out without ever visiting a website.
The data confirms this acceleration is already underway: our recent analysis shows that traffic from AI Agents grew over 1,300% in just nine months.

Every retailer, brand, and marketplace now operates in a world where non-human actors influence human decisions.

In this new paradigm, trust decides who wins.

The companies that grow through this transition are those that can see, verify, and govern AI activity in real time. That is the job of the Agentic Trust Stack.

Gain Visibility into AI Agent Traffic

See how AgenticTrust provides real-time governance over agentic activity on your properties.

Request a Demo

Methodology

How we measured

The data in this report was collected from interactions observed by the Human Defense Platform of HUMAN’s cybersecurity customers on an aggregated, anonymized basis, which make up a subset of the full set of interactions observed by the platform.

Throughout this report, we’ve used the term “typical HUMAN customer” to reference the median value in the data set. Additionally, we’ve used the term “heavily-targeted HUMAN customer” to reference the value at the 90th percentile. These two values were selected to reduce the impact of outliers and extreme cases and to give an accurate representation of the trends observed.

AI Agents, Scrapers, Crawlers, and the Future of Automated Traffic

The infrastructure built to establish trust was never designed for non-human actors
AI Scraper and Crawler traffic growth. Source: HUMAN Security
AI Scraper and Crawler traffic growth. Source: HUMAN Security

Agentic AI Traffic Explodes Amongst Agentic Commerce

AI agent interactions by page path. 77% of interactions target Products & Search. Source: HUMAN Security
AI agent interactions by page path. 77% of interactions target Products & Search. Source: HUMAN Security
Lorem ipsum
Lorem ipsum
Satori Threat Intelligence: Abusive Behavior from OpenClaw Instances
HUMAN’s Satori Threat Intelligence team discovered OpenClaw instances where the border between legitimate use and abuse is indistinguishable. Based on behavioral consistency and automation patterns, we have high confidence that the majority of traffic originating from these nodes is generated by browser automation controlled by OpenClaw.

Baseline Cyberthreat Figures

Of the more than one quadrillion interactions analyzed by the Human Defense Platform in 2025
Traffic Type
Change from 2024

Human Traffic

Down 1.8%

Benign Automation

Up 0.9%

Malicious Automation

Up 1.1%

The main takeaway: the internet is shifting quickly. The proportion of traffic that’s verifiably human is dropping, and the proportion that’s automated — through benign sources like agentic AI or malicious sources like attempted attacks — is rising, and fast.

A 1.1% increase in the proportion of malicious traffic may not sound like much, but consider that’s of all traffic analyzed for this report. The total number of interactions analyzed rose more than 5% from 2024 to 2025. So the actual number of attempted attacks rose more than 23% from 2024 to 2025. Small numbers become big numbers quickly at this scale.

Year
Account Takeover (ATO)
Transaction Abuse (Carding)
Scraping

2024

9.7%

0.1%

50.0%

2025

5.4%

0.1%

59.5%

Change

-4.3pp

Flat

+9.5pp

The above shows how quickly and dramatically threat actors can change their tactics. The overall proportion of malicious automation attempting an ATO attack dropped nearly in half year over year, but that difference is made up for and then some by a nearly 10% jump in attempted scraping attacks.

Translated to actual attack volumes, the number of attempted ATO attacks fell by 30.6% from 2024 to 2025, while the number of attempted scraping attacks rose by 46.9%.

Attack Trends

Enterprise-focused attacks in 2025 across four major categories

This report details enterprise-focused attacks in 2025 as analyzed by the Human Defense Platform, covering four attack types: account takeover (ATO), carding, web scraping, and fake account creation. Each category includes a variety of targets and tactics, and incorporates automation into one stage or another of their kill chain.

Account Takeover (ATO)

Key Findings Account Takeover

  • Shifting geography and context: While the number of attempted ATO attacks fell by more than 30%, the percentage of overall login traffic attempting an ATO attack saw its biggest jump in years, particularly in EMEA, where it exceeded 13% (compared to less than 3.5% globally).
  • Tactical evolution to post-login compromise: Attacks focused on post-login account compromise more than tripled in 2025, with HUMAN flagging an average of 402,000 attempts per customer, suggesting widespread adoption of login-point protections is forcing attackers to adopt more complex tactics.
  • EMEA as a primary target: For heavily-targeted organizations, ATO attempts in EMEA exceeded 75% of login attempts, and EMEA’s share of all attempted ATO attacks was nearly three times larger in 2025 than in 2024.

Account takeover is one of the most common — and profitable — attack paths for threat actors. When an ATO attempt succeeds, attackers can monetize it directly by draining stored funds, harvest credentials for resale, or enrich the account data and sell access. Once an account is compromised, it can be emptied of funds or loyalty balances, used for fraudulent purchases, posted from to generate fake reviews, or exploited to send spam.

Most takeovers start with compromised credentials sourced from a data breach. Those credential pairs are traded in underground markets and then used to target services where users have reused the same passwords. Two of the most common techniques are credential stuffing and credential brute forcing.

AI agent interactions by page path. 77% of interactions target Products & Search. Source: HUMAN Security
AI agent interactions by page path. 77% of interactions target Products & Search. Source: HUMAN Security
AI agent interactions by page path. 77% of interactions target Products & Search. Source: HUMAN Security
AI agent interactions by page path. 77% of interactions target Products & Search. Source: HUMAN Security
In the Wild: Major Betting Provider

One major betting provider saw their attempted ATO percentage decrease significantly from 2024 to 2025. In December 2024, HUMAN blocked more than 163 million ATO attempts. That number decreased steadily, bottoming out at 1.75 million in August 2025. Their ATO rates have remained low ever since. HUMAN’s customer was protected.

Carding Attackes

Key Findings Carding

  • Substantial volume increases: While the percentage of checkout traffic attempting a carding attack remained low and stable, the volume of global checkout interactions blocked increased by more than 20% from 2024 to 2025, and 250% from 2022.
  • US businesses as primary target: For the second consecutive year, attempted carding attacks disproportionately targeted American businesses, making up an outright majority of all attacks stopped.

Carding is a technique cybercriminals use to test and confirm stolen payment card details. Using automated tools, they run small “probe” transactions on e-commerce sites to see which cards are still active. Once a card clears a test purchase, it becomes far more valuable and is often immediately used for larger purchases, frequently targeting digital goods like gift cards.

Merchants can lower their exposure by hardening payment and checkout controls. For merchants that don’t, the downside shows up fast — through chargebacks, elevated fraud losses, and higher processing costs.

Stop Transaction Abuse Before It Hits Your Bottom Line

Learn how HUMAN’s Sightline Cyberfraud Defense detects and blocks carding attacks in real time.

See how it works

Web scraping

Key Findings Web scraping

  • Significant volume and percentage increases: Global volume of attempted attacks up almost 47% from 2024 and 138% since 2022. The median global percentage of traffic attempting a scraping attack nearly doubled from 2022 to 2025, approaching 20%.
  • Heavy targeting of EMEA organizations: For heavily-targeted companies, scraping attacks now account for over 61% of traffic globally, and a staggering 87% of traffic in EMEA.
  • Geographic disparity: Despite high EMEA percentages, American businesses remain the most frequent targets, accounting for almost two-thirds of all scraping attacks blocked in 2025.

Scraping attacks are carried out by bots that hit a website, extract large volumes of data, and move on. The activity can range from competitive intelligence to outright theft, but the common thread is automation and scale.

High-volume scraping can siphon off intellectual property like product descriptions and images, enable direct content theft, dilute brand credibility, and strain affiliate relationships. It also drives up bandwidth and compute usage, leading to higher hosting costs.

For e-commerce businesses, scraped pricing, inventory, and catalog data can be used to undercut offers or match promotions, eroding differentiation and margin. For subscription-based sites, scraping can violate terms of service and bypass paywalls.

The continued growth in scraping volumes coincides with the rise of AI crawlers and scrapers. Automation is growing, for both good and ill, and scraping is one of the key tasks asked of these bots and agents.

Of the entire universe of interactions analyzed by the Human Defense Platform, only one half of one percent separates the rate of benign automation from the rate of malicious automation.

HUMAN Security, Satori Threat Intelligence

In the Wild: Pharmaceutical E-Commerce

One pharmaceutical company with an e-commerce business is heavily targeted by scraping attacks, seeing 30-40% of their web traffic on average. In October and November 2025, rates ballooned to over 70% of traffic before falling again. HUMAN’s customer was protected.

Fake Account Creation

Key Findings Fake Accounts

  • Significant growth in attack volume: Fake account creation attempts increased by 259% from 2023 to 2024, and by an additional 89% in 2025.
  • Tactic of choice for incentive abuse: Fake account creation remains highly attractive for threat actors, particularly when organizations offer incentives for new users, leading to rapid draining of promotional budgets and serving as a precursor to other fraud.

Fake account creation is a common abuse pattern where attackers use automation and stolen or fake identity data to create accounts that look legitimate on the surface. Account quality is often the difference between noisy abuse and durable fraud: attackers will age accounts, add profile details, and mimic normal user behavior to make them harder to detect.

Fake accounts can be used to drain promotional budgets through new user program abuse, free trials, and referral programs. They’re also frequently a precursor to other fraud: testing stolen payment instruments, placing fraudulent orders, laundering transactions, or carrying out return and refund abuse.

Fake account creation continues to grow steadily. Source: HUMAN Security
Fake account creation continues to grow steadily. Source: HUMAN Security
Fake account creation continues to grow steadily. Source: HUMAN Security
Fake account creation continues to grow steadily. Source: HUMAN Security
Spread the Word
Spread the Word