Invisible by Design. The New Reality of Bad Bots in the Age of AI. Download the Thales Bad Bot Report 01 Introduction 02 The figures 03 Real-world attacks 04 Reality check 05 Report 06 Contact Beneath the surface What you see is only half the truth. Bots analyse prices, take over customer accounts, attack APIs and manipulate business processes. Often without anyone even noticing. New attack patterns identified With artificial intelligence, bots are becoming smarter, faster and harder to detect. They navigate websites, customer portals and apps just like real visitors, or access the underlying APIs directly. The key question is no longer whether bots are active. Rather, it is which forms of automation are legitimate and which ones are harmful to your business. Traffic Analysed API activity Recognised Identity Unknown The figures speak for themselves The new reality in six figures. Bots are no longer a marginal phenomenon. They shape internet traffic, attack APIs, manipulate business processes and, thanks to artificial intelligence, are evolving faster than traditional defence mechanisms. 01 53% The Invisible Majority Bots now generate more internet traffic than humans. Automated systems have become the new normal. For businesses, it is therefore becoming increasingly difficult to identify who is actually using their websites, portals and digital services. Bots 53 % People 47 % 02 40% Almost one in two internet connections comes from a bad bot Automated attacks have long been part of everyday life. They collect data, scrape prices, test login credentials and manipulate digital processes. In doing so, their activities increasingly resemble legitimate user behaviour. Critical automation detected 03 27% The invisible back door More than one in four bot attacks are directed specifically at APIs. Modern bots bypass the visible website and access the digital processes behind it directly. This is precisely where authentication, orders, payments and core business functions come together. API anomaly detected 04 21% Legitimate procedures. Manipulated results. 21 per cent of all automated attacks target business logic. Attackers do not necessarily look for a traditional security vulnerability. They exploit standard processes such as login, booking, shopping basket or payment, and alter the outcome. Process deviation detected 05 12,5× AI is accelerating the threat AI-powered bot attacks have increased by a factor of 12.5 within a year. Artificial intelligence helps bots to constantly adapt their behaviour, circumvent security measures and imitate legitimate users even more convincingly . Accelerated attack pattern 06 17,2 trillions Real attacks. Real data. That is how many bot requests Thales blocked in 2025 alone. The findings in the report are not based on theoretical assumptions, but on actual internet traffic from a wide variety of sectors and regions. Global analysis active Real-life attack scenarios Invisible attacks. Real-world consequences. Modern bot attacks exploit legitimate interfaces and standard business processes. As a result, they often appear to be ordinary user activity until the financial damage becomes apparent. Case file 01 Attack detected User API Authentication Customer account Automated login attempts Enquiries high Behaviour Anomaly Destination Accounts 01 Financial services provider Authentication API The attack did not come via the website. A financial services provider was the target of a large-scale account takeover attack via its authentication API. The bots used standard login functions and automatically tested stolen login credentials. Each individual request initially appeared legitimate. It was only the behaviour across multiple sessions that revealed the attack. Business impact Hacked customer accounts put assets, customer data and trust in digital services at risk. Case file 02 Costs are rising Verification •••••• Resend code SMS SMS SMS SMS Cost trends +300,000 USD Duration 20 days Methode SMS Pumping Damage Costs 02 Health insurer 300,000 USD A legitimate text message service turned out to be a money trap. An international health insurer lost around USD 300,000 in the space of just 20 days as a result of an automated SMS pumping attack. Bots triggered a massive number of paid verification messages . The feature worked correctly from a technical point of view, but was abused on a scale for which it was never intended. Business impact The attack resulted in direct costs without any systems having to be compromised or traditional security vulnerabilities having to be exploited. Modern bot attacks are not just an IT problem. They are a business risk. Reality Check How well do you know your digital infrastructure? Modern bot attacks are often almost indistinguishable from legitimate access attempts. The key question is therefore not just whether bots are active, but whether you can identify what they are doing within your digital processes. 01 Website-Traffic Do you know what proportion of your website traffic actually comes from people? Analysed 02 API activity Who monitors your APIs for unauthorised or automated access? Analysed 03 Business processes Can bots manipulate your business processes without triggering an alarm? Analysed 04 Automation Which automated access attempts are desirable and which pose a risk? Analysed 05 AI-powered attacks How well prepared are you for intelligent and adaptive bot attacks? Analysed Hidden risks arise where there is a lack of transparency. 2026 Edition Data base Global Analysis Latest Format PDF The full report 2026 Thales Bad Bot Report. Bad Bots in the Agentic Age The report brings together the latest market data, real-world attack scenarios and specific, practical recommendations for action. It shows how artificial intelligence, APIs and automated attacks are transforming businesses, and what measures are needed today to effectively protect applications, digital interfaces and business processes. 53 % Bot-Traffic 40 % Bad Bots 27 % API attacks 21 % Business Logic Abuse 12,5× more AI attacks 17,2 Bio. blocked requests Download the report now → Fill in the form and download the full report. The invisible threat begins where traditional security measures end. 2026 Thales Bad Bot Report Download the report Enter your contact details and you’ll then be given access to the full report. Download Thales Bad Bot Report EN "*" indicates required fields CompanyThis field is for validation purposes and should be left unchanged.Name* First name Surname Email* Direct contact Contact the Thales team. Our Thales team is here to support you with sales enquiries, pre-sales matters and planned marketing activities. E-Mail [email protected] Telefon +41 41 799 01 04 Get in touch now → Your points of contact Here for you personally. Whether it’s a quote, a project idea or a technical enquiry: when you contact us, you’ll speak directly to the people who support Thales’s business in Switzerland. 01 Inside Sales René Schmidig E-Mail [email protected] Telefon +41 41 799 01 04 02 Inside Sales Sonia Palomino E-Mail [email protected] Telefon +41 41 799 01 04 03 Inside Sales Stefanie Elmiger E-Mail [email protected] Telefon +41 41 799 01 04 A good security strategy starts with a face-to-face conversation. Thales Switzerland How can we help you? Send us your enquiry. The Thales team at Infinigate Switzerland will get in touch with you directly. Kontakt zum Thales-Team EN "*" indicates required fields FacebookThis field is for validation purposes and should be left unchanged.Name*Email* Company*PhoneHow can we help?Privacy Policy* I acknowledge that Infinigate will contact me strictly in accordance with the provisions of the Privacy Policy.
01 53% The Invisible Majority Bots now generate more internet traffic than humans. Automated systems have become the new normal. For businesses, it is therefore becoming increasingly difficult to identify who is actually using their websites, portals and digital services. Bots 53 % People 47 %
02 40% Almost one in two internet connections comes from a bad bot Automated attacks have long been part of everyday life. They collect data, scrape prices, test login credentials and manipulate digital processes. In doing so, their activities increasingly resemble legitimate user behaviour. Critical automation detected
03 27% The invisible back door More than one in four bot attacks are directed specifically at APIs. Modern bots bypass the visible website and access the digital processes behind it directly. This is precisely where authentication, orders, payments and core business functions come together. API anomaly detected
04 21% Legitimate procedures. Manipulated results. 21 per cent of all automated attacks target business logic. Attackers do not necessarily look for a traditional security vulnerability. They exploit standard processes such as login, booking, shopping basket or payment, and alter the outcome. Process deviation detected
05 12,5× AI is accelerating the threat AI-powered bot attacks have increased by a factor of 12.5 within a year. Artificial intelligence helps bots to constantly adapt their behaviour, circumvent security measures and imitate legitimate users even more convincingly . Accelerated attack pattern
06 17,2 trillions Real attacks. Real data. That is how many bot requests Thales blocked in 2025 alone. The findings in the report are not based on theoretical assumptions, but on actual internet traffic from a wide variety of sectors and regions. Global analysis active
Case file 01 Attack detected User API Authentication Customer account Automated login attempts Enquiries high Behaviour Anomaly Destination Accounts 01 Financial services provider Authentication API The attack did not come via the website. A financial services provider was the target of a large-scale account takeover attack via its authentication API. The bots used standard login functions and automatically tested stolen login credentials. Each individual request initially appeared legitimate. It was only the behaviour across multiple sessions that revealed the attack. Business impact Hacked customer accounts put assets, customer data and trust in digital services at risk.
Case file 02 Costs are rising Verification •••••• Resend code SMS SMS SMS SMS Cost trends +300,000 USD Duration 20 days Methode SMS Pumping Damage Costs 02 Health insurer 300,000 USD A legitimate text message service turned out to be a money trap. An international health insurer lost around USD 300,000 in the space of just 20 days as a result of an automated SMS pumping attack. Bots triggered a massive number of paid verification messages . The feature worked correctly from a technical point of view, but was abused on a scale for which it was never intended. Business impact The attack resulted in direct costs without any systems having to be compromised or traditional security vulnerabilities having to be exploited.
01 Website-Traffic Do you know what proportion of your website traffic actually comes from people? Analysed
03 Business processes Can bots manipulate your business processes without triggering an alarm? Analysed
Direct contact Contact the Thales team. Our Thales team is here to support you with sales enquiries, pre-sales matters and planned marketing activities. E-Mail [email protected] Telefon +41 41 799 01 04 Get in touch now →