THALES
Thales, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, today announced the release of the 2024 Imperva Bad Bot Report, a global analysis of automated bot traffic across the internet. Nearly half (49.6%) of all internet traffic came from bots in 2023—a 2% increase over the previous year, and the highest level Imperva has reported since it began monitoring automated traffic in 2013.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240416225637/en/
©Thales
For the fifth consecutive year, the proportion of web traffic associated with bad bots grew to 32% in 2023, up from 30.2% in 2022, while traffic from human users decreased to 50.4%. Automated traffic is costing organizations billions (USD) annually due to attacks on websites, APIs, and applications.
“Bots are one of the most pervasive and growing threats facing every industry,” says Nanhi Singh, General Manager, Application Security at Imperva, a Thales company. “From simple web scraping to malicious account takeover, spam, and denial of service, bots negatively impact an organization’s bottom line by degrading online services and requiring more investment in infrastructure and customer support. Organizations must proactively address the threat of bad bots as attackers sharpen their focus on API-related abuses that can lead to account compromise or data exfiltration.”
Key trends identified in the 2024 Imperva Bad Bot Report include:
- Global average of bad bot traffic reached 32%: Ireland (71%), Germany (67.5%), and Mexico (42.8%), saw the highest levels of bad bot traffic in 2023. The US also saw a slightly higher ratio of bad bot traffic at 35.4% compared to 2022 (32.1%).
- Growing use of generative AI connected to the rise in simple bots: Rapid adoption of generative AI and large language models (LLMs) resulted in the volume of simple bots increasing to 39.6% in 2023, up from 33.4% in 2022. The technology uses web scraping bots and automated crawlers to feed training models, while enabling nontechnical users to write automated scripts for their own use.
- Account takeover is a persistent business risk: Account takeover (ATO) attacks increased 10% in 2023, compared to the same period in the prior year. Notably, 44% of all ATO attacks targeted API endpoints, compared to 35% in 2022. Of all login attempts across the internet, 11% were associated with account takeover. The industries that saw the highest volume of ATO attacks in 2023 were Financial Services (36.8%), Travel (11.5%), and Business Services (8%).
- APIs are a popular vector for attack: Automated threats caused a significant 30% of API attacks in 2023. Among them, 17% were bad bots exploiting business logic vulnerabilities—a flaw within the API’s design and implementation that allows attackers to manipulate legitimate functionality and gain access to sensitive data or user accounts. Cybercriminals use automated bots to find and exploit APIs, which act as a direct pathway to sensitive data, making them a prime target for business logic abuse.
- Every industry has a bot problem: For a second consecutive year, Gaming (57.2%) saw the largest proportion of bad bot traffic. Meanwhile, Retail (24.4%), Travel (20.7%), and Financial Services (15.7%) experienced the highest volume of bot attacks. The proportion of advanced bad bots, those that closely mimic human behavior and evade defenses, was highest on Law & Government (75.8%), Entertainment (70.8%), and Financial Services (67.1%) websites.
- Bad bot traffic originating from residential ISPs grows to 25.8%: Early bad bot evasion techniques relied on masquerading as a user agent (browser) commonly used by legitimate human users. Bad bots masquerading as mobile user agents accounted for 44.8% of all bad bot traffic in the past year, up from 28.1% just five years ago. Sophisticated actors combine mobile user agents with the use of residential or mobile ISPs. Residential proxies allow bot operators to evade detection by making it appear as if the origin of the traffic is a legitimate, ISP-assigned residential IP address.
“Automated bots will soon surpass the proportion of internet traffic coming from humans, changing the way that organizations approach building and protecting their websites and applications,” continued Singh. “As more AI-enabled tools are introduced, bots will become omnipresent. Organizations must invest in bot management and API security tools to manage the threat from malicious, automated traffic.”
Additional Information:
- Download a copy of the 2024 Imperva Bad Bot Report for additional insights.
- See how Imperva Advanced Bot Protection, API Security, and Client-Side Protection can protect websites, mobile applications, and APIs from automated attacks and fraud without affecting the flow of business-critical traffic.
- Read the Imperva Blog for the latest product and solution news, and threat intelligence from Imperva Threat Research.
About Thales
Thales (Euronext Paris: HO) is a global leader in advanced technologies within three domains: Defence & Security, Aeronautics & Space, and Digital Identity & Security. It develops products and solutions that help make the world safer, greener and more inclusive.
The Group invests close to €4 billion a year in Research & Development, particularly in key areas such as quantum technologies, Edge computing, 6G and cybersecurity.
Thales has 81,000* employees in 68 countries. In 2023, the Group generated sales of €18.4 billion.
* These figures exclude the ground transportation business, which is being divested
PLEASE VISIT
Cloud Protection & Licensing Solutions | Thales Group
Cybersecurity Solutions | Thales Group
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240416225637/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
OMRON Releases the “Medium-Term Roadmap SF 2nd Stage”8.11.2025 07:00:00 CET | Press release
OMRON (TOKYO: 6645) has announced its “Medium-Term Roadmap Shaping the Future 2nd Stage (“SF 2nd Stage”),” covering from FY2026 to FY2030, on November 7, 2025 (JST). This Roadmap presents the Group’s vision and growth strategies through 2030, which are disclosed on our corporate website. Overview of the “Medium-Term Roadmap SF 2nd Stage” Since April 2024, OMRON has been implementing a Structural Reform Program “NEXT 2025” aimed at rebuilding our foundation for profitability and growth. With the completion of this Program in September 2025, we have shifted into a growth phase and formulated a new Roadmap looking ahead to 2030. This Roadmap identifies Business Portfolio Restructuring as a core strategy. We have defined Thirteen Focus Businesses to drive the Group’s future growth. By accelerating our selection and concentration efforts, we aim to build a “distinctive” business portfolio that maximizes overall Group growth. Furthermore, to maximize the growth potential of our Focus Busines
26th UN Tourism General Assembly kicks off in Riyadh7.11.2025 22:13:00 CET | Press release
UN Tourism marks 50 years of global cooperation as leaders from across the industry gather to shape the future of tourism. His Excellency Ahmed Al Khateeb, Minister of Tourism – “The Kingdom will play an integral part in ensuring one of the world’s most powerful generators of jobs and GDP grows in harmony with the Sustainable Development Goals.” UN Tourism Secretary-General ZurabPololikashvili – “The UN Tourism General Assembly brings together tourism leaders from across the world to set the agenda and build a more innovative and inclusive sector. From Riyadh, we will set the agenda for tourism for the years ahead.” The 26th session of the UN Tourism General Assembly opened today in Riyadh, marking a historic first for the Gulf Cooperation Council (GCC) region and the largest Assembly since UN Tourism was founded 50 years ago. Around 160 delegations from member states including ministers, senior officials, and leaders from across industry and civil society are coming together to celebr
Xsolla Partners With Deloitte Turkiye and Lorien Accelerator as Category Sponsor for Gaming Awards at Fast 50 Türkiye 2025 Program7.11.2025 19:11:00 CET | Press release
Celebrating Turkey’s Gaming Industry with High-Impact Sponsorship and Industry Panel Xsolla, a leading global video game commerce company that helps developers launch, grow, and monetize their games, is proud to announce its sponsorship of the Gaming Awards segment at the Deloitte Technology Fast 50 Türkiye 2025 Program, organized in collaboration with Lorien Accelerator. The event will take place on December 10, 2025, and will recognize Turkey’s top high-growth companies across various industries, with a special focus on the dynamic gaming sector. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251107671030/en/ Graphic: Xsolla As the Gaming Awards category sponsor, Xsolla will receive significant brand exposure through prominent logo placements across all event materials, including digital platforms, official event signage, and other promotional materials. In addition to this visibility, Xsolla’s participation includes an ex
Takeda Presents New Data Showing Mezagitamab (TAK-079) Sustained Effect on Kidney Function 18 Months After Treatment in Primary IgA Nephropathy7.11.2025 17:00:00 CET | Press release
− Phase 1b, Open-Label Study Follow Up Shows Stable Kidney Function (eGFR) in Patients Treated with Investigational Mezagitamab Through Week 96 – 18 Months After Last Dose1− Rapid Reductions in Proteinuria and Serum Gd-IgA1 Levels Were Sustained Through Week 961− No Serious Adverse Events or Opportunistic Infections Were Observed Through Week 961− Takeda Initiated Pivotal Phase 3 Clinical Trials Evaluating Mezagitamab in Primary IgA Nephropathy and Immune Thrombocytopenia with Patient Enrollment Ongoing Takeda (TSE:4502/NYSE:TAK) today announced new interim data from the Phase 1b, open-label, proof-of-concept study of subcutaneous mezagitamab (TAK-079), an anti-CD38 monoclonal antibody with disease-modifying potential, in primary immunoglobulin A (IgA) nephropathy. Data from the study showed that kidney function (eGFR) remained stable in patients with IgA nephropathy through Week 96 – up to 18 months after the last mezagitamab dose.1 The results were presented at the American Society o
Oremus Corporate Services Expands into Europe with Launch in Finland7.11.2025 16:23:00 CET | Press release
CEO, Lalit Ananth Chawla, to Attend Slush 2025 in Helsinki Oremus Corporate Services Private Limited, a multinational Finance and Accounting Advisory firm having its offices in the USA, India and the UK, has announced the extension of its services to Finland, marking the company’s foray into the European market. With over two decades of expertise in accounting, payroll, tax compliance, and advisory services, Oremus has earned trust as a technology-driven finance partner serving clients across geographies. Oremus is an ISAE 3402, ISO 27001, GDPR & DPDP Compliant Company, adhering to International Quality and Security Standards. “Finland isn’t just a new market for us — it’s the gateway to meaningful, growth-driven partnerships across Europe”. said Lalit Ananth Chawla, CEO of Oremus. Having established a strong reputation for delivering reliable Accounting and Advisory solutions to scale-ups and growing businesses, we seek to collaborate with like-minded firms and investors to build a tr
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
