Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AI is helping attackers automate and vary bot campaigns, but the evidence does not show that AI alone caused the reported rise in attacks. The more durable risk is automation at scale exploiting familiar weaknesses: missing authorization checks, unbounded API requests and business processes that can be abused repeatedly. Bot traffic also includes useful crawlers, so defenses need to distinguish intent and behavior rather than block every bot.

What the recent bot and API figures actually show

Security providers report sharp increases, but their figures come from different networks, time periods and methods. They are signals of activity in each provider’s observations—not a single measurement of the whole internet.

Figure What it measures Scope and qualification
300% increase AI bot activity Akamai said activity observed on its platform rose 300% over the prior year in its November 4, 2025 announcement. Akamai said AI bots made up nearly 1% of total bot traffic on its platform; neither figure is a global census.
87% Organizations reporting at least one API-related security incident in 2025 Akamai’s 2026 survey result; it describes surveyed organizations, not all organizations worldwide.
113% increase Average daily API attacks Akamai reported a year-over-year increase in its 2026 reporting.
73% increase Web application attacks Akamai reported growth from 2023 to 2025.
104% increase Layer 7 DDoS attacks Akamai reported growth from 2023 to 2025.
47.9% Share of observed AI bot traffic associated with commerce Akamai’s global-network observation for July through December 2025. This is a sector share of Akamai-observed AI bot activity, not a share of all bots.
12.5-fold increase AI-enabled bot attacks Thales reported a year-over-year increase based on its analysis of full-year 2025 bot activity.
40% Bad bots’ share of internet traffic Thales’s figure from its 2026 Bad Bot Report analysis. It uses Thales’s own traffic analysis and should not be combined with another provider’s denominator.

Akamai’s 87% figure is a survey result; the other figures describe activity observed or analyzed by individual providers. Akamai, Thales and Cloudflare use their own telemetry and definitions, so their numbers should not be averaged or treated as interchangeable. Cloudflare’s 2025 review, for example, describes crawler behavior across Cloudflare customer sites rather than every site on the internet.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How AI is making bot attacks worse

Automation can lower the effort needed to repeat a campaign, change its pace or vary its behavior. That can make established tactics cheaper to run and harder to manage at scale. Patrick Sullivan, Akamai’s CTO of Security Strategy, said: “Automation and AI are making these sophisticated campaigns cheap, repeatable, and fast.” That is Akamai’s characterization, not an independent measurement of how much AI contributes to attacks.

#1 Best Overall
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

AI-enabled automation is only part of the picture. Akamai’s reporting describes harmful bot uses including content scraping, impersonation, phishing, identity fraud and abuse of commerce flows. Malicious traffic can also raise operating costs, slow services and make analytics less reliable. At the same time, automated traffic serves legitimate purposes, including search and other crawling, training-related crawling and visits triggered by a user asking a chatbot to retrieve a page. Cloudflare’s 2025 review tracks these kinds of crawler activity on its own network.

The evidence supports a careful conclusion: AI can help expand, speed up or vary automated campaigns, while API weaknesses and business-flow abuse remain underlying problems. Rising activity reported by providers does not establish AI as the sole cause.

Why APIs are a growing security risk

An API can expose data or trigger actions directly, often behind a normal-looking application feature. When an endpoint accepts an object identifier, processes a large request or starts a sensitive business action, automation can repeat the request rapidly. A conventional coding flaw is not required for a legitimate feature—such as account creation, ticket purchasing or password recovery—to be abused at scale.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Wintertion1U/Desktop/Rackmount Firewall Hardware,OPNsense, VPN, Network Security Appliance, Router PCN2600 D2700, 4 x Gigabit LAN, COM, VGA, Fan, 0 RAM, 0 Storage (Desktop Type, 4G RAM 64G SSD)
  • equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
  • Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
  • 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
  • Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
  • There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product

OWASP’s 2023 API Security Top 10 provides a useful map of the underlying risks:

  • Broken object-level authorization: a user can access or change an object they are not entitled to use.
  • Broken authentication: an API does not reliably establish who is making a request.
  • Broken object property-level authorization: sensitive fields are exposed or changed without permission.
  • Unrestricted resource consumption: requests can use excessive processing, bandwidth or third-party spending.
  • Broken function-level authorization: a user can invoke an action reserved for another role.
  • Unrestricted access to sensitive business flows: automated use can exploit a legitimate process such as account creation or purchasing.
  • Server-side request forgery: an API can be induced to make unintended requests from the server.
  • Security misconfiguration: insecure or inconsistent settings expose the service.
  • Improper inventory management: unknown, obsolete or poorly tracked API versions remain exposed.
  • Unsafe consumption of APIs: an application trusts data from a connected service without adequate validation.

Authorization failures can expose individual records or fields

Checking that a user may reach an endpoint is not enough. The service also needs to check whether that user may access the specific object identified in each request, and whether they may read or change each returned or submitted property. These checks need to apply consistently across functions and roles.

Unbounded requests threaten availability and cost

OWASP’s API4 guidance highlights limits on execution time, payload size, batch operations, records returned and the number of interactions. Rate limits can help, but metered third-party services also call for spending limits or billing alerts. Without such controls, a request pattern can consume resources even when it does not steal data.

Rank #3
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

Unknown APIs and trusted integrations create blind spots

An obsolete API version may remain reachable after teams stop monitoring it. A connected service can introduce another weakness if the application trusts its responses more than it would trust user input. Inventory needs to cover public, internal and third-party APIs, along with versions and sensitive-data exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to tell useful AI crawlers from harmful bots

Do not treat “AI bot” as a synonym for “malicious bot.” Some crawlers support search or training, and some fetch a page because a user asked an AI service to retrieve it. Other automation scrapes content, impersonates people, probes accounts or abuses a transaction flow. The label alone does not establish what a request is doing or whether it is authorized.

Assess purpose and behavior together. Identify known, useful crawlers and decide which access is acceptable for your site and data. Then look for behavior that conflicts with that purpose: unusual request sequences, repeated attempts against sensitive workflows, excessive volume, or actions that produce suspicious business outcomes. IP reputation and request volume can be useful signals, but neither reliably identifies intent by itself. A policy can allow known crawler activity while applying tighter controls to sensitive endpoints and unknown automation.

Rank #4
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How companies can protect APIs from bots and DDoS attacks

Start with the weaknesses that automated traffic can exploit, then layer traffic controls around the business impact of each endpoint.

  1. Inventory the APIs. Track public, internal and third-party APIs, their versions, owners and sensitive-data exposure. Identify obsolete endpoints that should be removed or protected.
  2. Enforce authorization at every level. Check access to each object, property and function for each request. Do not assume that authentication or permission to use an endpoint grants access to every record or field.
  3. Validate requests and reduce exposure. Apply authentication and schema or input validation appropriate to the API. Return only the data needed for the task, and validate data received from integrated APIs.
  4. Limit resource use. Set suitable caps for request size, processing time, batch work, returned records and interactions. Add rate limits suited to each endpoint, plus spending limits or alerts for metered external services.
  5. Protect sensitive workflows. Set controls around sequences and outcomes for flows such as login, password recovery, account creation or purchasing. Tune thresholds to the business purpose rather than applying one volume limit everywhere.
  6. Classify and monitor automation. Separate known, useful crawlers from unknown or harmful behavior. Monitor request sequences and business outcomes alongside traffic volume and IP signals.
  7. Layer application, API and DDoS defenses. Use controls at the relevant application and network deployment points, and account for Layer 7 traffic that resembles ordinary requests. No single bot filter replaces sound authorization and resource limits.
  8. Test throughout development. Include API security testing and OWASP guidance in development and review processes. Akamai’s 2025 infographic also recommends adaptive protection, specialized DDoS defenses and bot defenses.

What to look for in API security software

Compare capabilities against your architecture and risk, not a vendor’s headline bot statistic. A useful assessment includes both what the product can detect and how much effort it takes to operate reliably.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Discovery and inventory: Can it find APIs and versions across the deployment points you need to protect, including forgotten or undocumented services?
  • Authorization coverage: Does it help identify or enforce object-, property- and function-level access rules, or does it focus mainly on traffic filtering?
  • Schema and input controls: Can it validate requests against API schemas and help address unsafe inputs or risky interactions with third-party APIs?
  • Business-aware limits: Can teams tune rate limits and controls for sensitive sequences and business outcomes without disrupting legitimate use?
  • Bot classification: Can it distinguish useful crawler intent from suspicious automation and provide enough visibility to adjust policies?
  • Application-layer DDoS protection: Which deployment points and application traffic does it cover, and how does it handle requests that resemble normal user activity?
  • Operational fit: Evaluate integration effort, alert quality, visibility and the ongoing burden of tuning and response.

Cloudflare’s API Shield documentation is one example of a provider mapping capabilities such as discovery, schema validation, rate limiting and bot management to OWASP risks. That feature mapping is not a neutral comparison or proof of comparative effectiveness. Akamai also offers application and API security services, but the figures cited here do not establish a best provider; selection should follow your requirements and your own evaluation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.