Commerce was the industry that received the most automated activity and the most signals associated with AI bots on the Akamai network during 2025. The new report Securing the Agentic Storefront places the sector at the center of a combination of automated tracking, API abuse, account fraud, phishing, and distributed denial-of-service attacks at the application layer.
The key points of digital commerce attacks in 30 seconds
- Commerce accounted for 48% of AI bot detections between July and December 2025.
- Model training crawlers represented 71% of that activity.
- Web attacks targeting APIs increased by 9% year-over-year and surpassed those focused on traditional applications.
- Akamai recorded nearly 3 trillion Layer 7 DDoS alerts against the sector, though these figures do not equate to successful incidents.
The report requires careful reading. It does not suggest that nearly half of all digital store traffic comes from AI agents. The 48% indicates that retail companies accumulated almost half of the rule activations Akamai uses to classify AI bots across all analyzed industries. These bots remain a small part of the overall automated volume.
It is also important to interpret attack figures correctly. Akamai counts alerts generated by its web application firewall, its bot management systems, and its DDoS mitigation tools. An alert may correspond to a malicious request being blocked and does not demonstrate that the attacker successfully compromised the application, stole information, or disrupted the service. The methodology of the report explicitly clarifies this.
Legitimate and malicious bots are starting to look too similar
Automated traffic against commerce grew 19% during 2025 and exceeded 17 trillion detections. Retail accounted for 61% of the activity, compared to 34% in the travel sector and 5% in hospitality.
Part of this traffic performs legitimate functions. Search engines crawl catalogs to list products in results, comparison tools check prices and availability, and new shopping assistants seek information to recommend items or complete transactions on behalf of individuals.
The problem is that the same capabilities can be used to scrape catalogs, monitor prices, hoard inventory, test stolen credentials, or overload an application.
Between July and December 2025, crawlers used for data collection aimed at model training accounted for 71% of classified AI bots in commerce. Fetchers, which retrieve content requested by assistants and services, reached 14.8%, while AI search crawlers made up another 13.6%.
| Type of AI Bot | Share in commerce detections |
|---|---|
| Training crawlers | 71.0% |
| Content fetchers | 14.8% |
| AI search crawlers | 13.6% |
| Other agents and categories | Less than 1% |
OpenAI led detections attributed to specific operators with 37%, followed by ByteDance with 28%, Anthropic with 18%, Meta with 14%, and Perplexity with 1%. These figures describe crawling volume and do not imply malicious activities by these companies.
Stores are facing a tough decision. Blocking any automation might reduce abuse but could also exclude their products from shopping assistant results. Allowing it without limits facilitates mass crawling, distorts metrics, and consumes infrastructure.
Most have opted to observe before acting. Over 90% of activity classified as AI bots was under monitoring policies. Once that category was excluded from analysis, retail companies allowed approximately three-quarters of the remaining traffic to pass unimpeded.
Akamai considers the binary allow-or-block model exhausted. The alternative involves classifying automation based on identity, behavior, commercial utility, and risk. A verified crawler from a search engine should not be treated the same as a bot rotating IP addresses, imitating browsers, and querying thousands of inventory pages in minutes.
The challenge will grow with agentic commerce. An authorized assistant can browse, compare prices, and use payment credentials on behalf of its owner. If a criminal hijacks that agent, they inherit a relationship that the commerce systems already considered legitimate.
The guest column in the report also warns against the use of models to create synthetic identities. These profiles mix real data with fabricated elements and persist for months to appear normal before being used in fraud. This is an assessment from specialists at the Retail & Hospitality Information Sharing and Analysis Center, not directly measured telemetry from Akamai.
APIs become the new surface of the store
The visible web no longer contains all the logic of an e-commerce platform on its own. Catalogs, mobile applications, inventory, payments, promotions, loyalty programs, and logistics providers communicate via APIs.
Web attacks targeting these interfaces increased by 9% between Q4 2024 and the same period in 2025. During that quarter, alerts against APIs outnumbered those aimed at traditional web applications.
Over the two-year period analyzed, APIs accounted for 49% of observed web attacks in commerce. Retail accumulated 58% of alerts against these endpoints, followed by hospitality with 33%, and travel with 9%.
The issue is not limited to code vulnerabilities. Interfaces can function exactly as designed and still be abused through:
- Automated inventory and price queries.
- Mass login attempts.
- Use of stolen credit cards for small payments.
- Exfiltration from loyalty programs.
- Exceeding promotion or refund limits.
- Accessing outdated endpoints no longer controlled by the company.
- Unauthorized use of paid AI services by the business.
This last case appears in the report as AI token freeloading. An attacker sends their own workloads to a chatbot or public endpoint, forcing the company to incur inference costs. Beyond economic costs, these queries can degrade service for legitimate customers.
A separate Akamai survey found that 85% of sector participants experienced at least one API-related incident in the past twelve months. 77.7% believed they had a complete inventory, but only 22.3% of that group knew which endpoints exposed sensitive information. The problem isn’t just unknown APIs, but unaware of the type of data circulating through the ones that are registered.
Layer 7 DDoS attacks add further pressure. Akamai recorded nearly 3 trillion alerts against commerce in 2025, with 31% directed at APIs. Retail accounted for 84% of the volume, travel 10%, and hospitality around 5%.
Unlike volumetric attacks that try to saturate bandwidth, Layer 7 operations can send seemingly valid HTTP requests against costly functions. Checking inventory, starting a purchase, or computing a promotion can consume databases and application servers with far less traffic.
Peaks coincided with Q4 and major shopping periods. Attackers can hide their requests among legitimate customer traffic, just when an outage causes greater economic damage.
Phishing, malware, and fraud form an interconnected chain
The investigation also notes an industrialization of credential theft. Between November 2025 and April 2026, malware accounted for 56.5% of endpoint activity detected in the sector. Phishing made up 37.6%, and command-and-control infrastructure communications 5.9%.
The average daily phishing activity grew from around 56,600 detections in February to 121,500 in March, and 134,600 in April.
The goal rarely ends with the first click. Stolen credentials fuel account takeovers, fraudulent purchases, points theft, delivery address changes, and password reuse across services.
Akamai describes an increasingly repeatable chain:
Phishing → execution → loader → command and control → persistence
Among observed malware families are remote access tools such as AsyncRAT and GoatRAT, along with infrastructure reused to maintain communication with compromised devices.
Commerce offers several quick monetization avenues. Loyalty accounts can hold redeemable points; customer profiles may store payment methods; compromised accounts can be used for purchases or to test access across other platforms.
Thus, the report recommends integrating cybersecurity with fraud prevention teams. A security operations center can detect malware, while the fraud team monitors purchase patterns. Working separately, each only sees part of the story.
Priorities include maintaining a continuous API inventory, classifying bots by intent, employing risk-based multi-factor authentication, and automatically freezing accounts when suspicious point depletion or chained purchases are detected.
Microsegmentation is another recommended measure. Although 92% of surveyed organizations use some form of network segmentation, only 35% have advanced toward detailed separation of applications and workloads. The goal is to prevent a valid credential or token from allowing movement from a public-facing app to internal databases and systems.
For security leaders, business campaigns should be treated as tests of business continuity. Before a major promotion, it is advisable to verify DDoS protections, review API limits, rehearse crisis procedures, and validate integrations with payment providers, logistics, and cloud services.
The agentic store does not eliminate the human customer. It adds new intermediaries that can operate at higher speed and scale. The challenge will be allowing legitimate assistants to discover and purchase products without granting the same level of trust to automation that aims to extract data, hijack accounts, or use APIs as fraud tools.
Frequently Asked Questions
Does 48% of all commerce traffic come from AI bots?
No. Commerce accounted for 48% of rule activations associated with AI bots across all analyzed industries. AI bots continue to represent a small part of the total automated traffic observed by Akamai.
What type of AI bot appears most frequently?
Data collection crawlers aimed at training models, making up 71% of AI bot detections in the sector.
Why are APIs increasingly targeted?
Because they connect payments, inventory, mobile apps, loyalty programs, and providers. This concentration of functions and data makes APIs useful vectors for fraud, data extraction, and DDoS attacks.
Do Akamai’s figures represent successful attacks?
Not necessarily. They are alerts and requests detected by security tools. The methodology clarifies they do not indicate that the attacker successfully compromised the system on their own.
Sources:
- Akamai, report Securing the Agentic Storefront: Attacks on Commerce, State of the Internet/Security, volume 12, issue 3, 2026.

