Report by Thales

2025 Imperva Bad Bot Report

11 FINDINGSPublished Apr 15, 2025
View Original Report →

Key Findings

In the Retail sector, bad bots made up 59% of their traffic.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
BotAutomated traffic

Malicious bots now account for 37% of all internet traffic, a significant increase from 32% in 2023.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
Malicious botsAutomated traffic

Financial services, healthcare, and e-commerce are the most affected sectors by sophisticated bot attacks targeting APIs

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
APIBot attackBot

Computing & IT accounted for 17% of all ATO incidents.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
ATO

Telecoms and ISPs accounted for 18% of all ATO incidents.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
ATO

In the Travel sector, bad bots made up 41% of their traffic in 2024. There was a decline in advanced bot attacks targeting the travel industry (41% in 2024, down from 61% in 2023) and a sharp increase in simple bot attacks (52% in 2024, up from 34% in 2023).

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
BotAutomated traffic

The travel sector topped the list for bot attacks overall, accounting for 27% of all bot attacks in 2024, up from 21% in 2023.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
Bot attack

44% of advanced bot traffic targeted APIs.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
BotAPIs

ByteSpider Bot was responsible for 54% of all AI-enabled attacks. Other significant contributors include AppleBot at 26%, ClaudeBot at 13%, and ChatGPT User Bot at 6%.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
ByteSpider BotAI attack

The financial services sector was the most targeted industry for account takeover (ATO) attacks, accounting for 22% of all incidents.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
ATO

Automated traffic surpassed human activity, accounting for 51% of all web traffic. This is the first time in a decade that automated traffic has exceeded human activity. This occurred in 2024.

Thales2025 Imperva Bad Bot Report·Apr 15, 2025
Automated trafficBot