Beneath the surface

What you see is only
half the truth.

Bots analyse prices, take over customer accounts, attack APIs and manipulate business processes. Often without anyone even noticing.

New attack patterns identified

With artificial intelligence, bots are becoming smarter, faster and harder to detect. They navigate websites, customer portals and apps just like real visitors, or access the underlying APIs directly.

The key question is no longer whether bots are active. Rather, it is which forms of automation are legitimate and which ones are harmful to your business.

Traffic Analysed
API activity Recognised
Identity Unknown
The figures speak for themselves

The new reality
in six figures.

Bots are no longer a marginal phenomenon. They shape internet traffic, attack APIs, manipulate business processes and, thanks to artificial intelligence, are evolving faster than traditional defence mechanisms.

01
53%

The Invisible Majority

Bots now generate more internet traffic than humans.

Automated systems have become the new normal. For businesses, it is therefore becoming increasingly difficult to identify who is actually using their websites, portals and digital services.

Bots 53 % People 47 %
Abstract visualisation of bot and human internet traffic
02
40%

Almost one in two internet connections comes from a bad bot

Automated attacks have long been part of everyday life.

They collect data, scrape prices, test login credentials and manipulate digital processes. In doing so, their activities increasingly resemble legitimate user behaviour.

Critical automation detected
Data stream containing detected malicious bot traffic
03
27%

The invisible back door

More than one in four bot attacks are directed specifically at APIs.

Modern bots bypass the visible website and access the digital processes behind it directly. This is precisely where authentication, orders, payments and core business functions come together.

API anomaly detected
API-Netzwerk mit auffälligem automatisiertem Zugriff
04
21%

Legitimate procedures. Manipulated results.

21 per cent of all automated attacks target business logic.

Attackers do not necessarily look for a traditional security vulnerability. They exploit standard processes such as login, booking, shopping basket or payment, and alter the outcome.

Process deviation detected
Manipulierter digitaler Geschäftsprozess mit umgangenem Zahlungsschritt
05
12,5×

AI is accelerating the threat

AI-powered bot attacks have increased by a factor of 12.5 within a year.

Artificial intelligence helps bots to constantly adapt their behaviour, circumvent security measures and imitate legitimate users even more convincingly .

Accelerated attack pattern
Abstrakte KI-Silhouette mit stark beschleunigten Datenströmen
06
17,2
trillions

Real attacks. Real data.

That is how many bot requests Thales blocked in 2025 alone.

The findings in the report are not based on theoretical assumptions, but on actual internet traffic from a wide variety of sectors and regions.

Global analysis active
Globale Karte mit weltweit blockierten Bot-Anfragen
Real-life attack scenarios

Invisible attacks.
Real-world consequences.

Modern bot attacks exploit legitimate interfaces and standard business processes. As a result, they often appear to be ordinary user activity until the financial damage becomes apparent.

01 Financial services provider
Authentication API

The attack did not come via the website.

A financial services provider was the target of a large-scale account takeover attack via its authentication API.

The bots used standard login functions and automatically tested stolen login credentials. Each individual request initially appeared legitimate. It was only the behaviour across multiple sessions that revealed the attack.

Business impact

Hacked customer accounts put assets, customer data and trust in digital services at risk.

02 Health insurer
300,000 USD

A legitimate text message service turned out to be a money trap.

An international health insurer lost around USD 300,000 in the space of just 20 days as a result of an automated SMS pumping attack.

Bots triggered a massive number of paid verification messages . The feature worked correctly from a technical point of view, but was abused on a scale for which it was never intended.

Business impact

The attack resulted in direct costs without any systems having to be compromised or traditional security vulnerabilities having to be exploited.

Modern bot attacks are not just an IT problem. They are a business risk.

Reality Check

How well do you know
your digital infrastructure?

Modern bot attacks are often almost indistinguishable from legitimate access attempts. The key question is therefore not just whether bots are active, but whether you can identify what they are doing within your digital processes.

01

Website-Traffic

Do you know what proportion of your website traffic actually comes from people?

Analysed
02

API activity

Who monitors your APIs for unauthorised or automated access?

Analysed
03

Business processes

Can bots manipulate your business processes without triggering an alarm?

Analysed
04

Automation

Which automated access attempts are desirable and which pose a risk?

Analysed
05

AI-powered attacks

How well prepared are you for intelligent and adaptive bot attacks?

Analysed

Hidden risks arise where there is a lack of transparency.

Cover des 2026 Thales Bad Bot Report
2026 Edition
The full report

2026 Thales
Bad Bot Report.

Bad Bots in the Agentic Age

The report brings together the latest market data, real-world attack scenarios and specific, practical recommendations for action.

It shows how artificial intelligence, APIs and automated attacks are transforming businesses, and what measures are needed today to effectively protect applications, digital interfaces and business processes.

53 % Bot-Traffic
40 % Bad Bots
27 % API attacks
21 % Business Logic Abuse
12,5× more AI attacks
17,2 Bio. blocked requests

Fill in the form and download the full report.

The invisible threat begins where traditional security measures end.

Your points of contact

Here for you personally.

Whether it’s a quote, a project idea or a technical enquiry: when you contact us, you’ll speak directly to the people who support Thales’s business in Switzerland.

A good security strategy starts with a face-to-face conversation.