Skip to content
Information Technology, RetailOnline Retail

Radware Finds 57% of Online Shopping Traffic Now Bots, Not Buyers

Radware 2 mins read

New 2025 E-commerce Bot Threat Report details rise in bot attacks, emerging threat vectors, and shifting defence strategies.

 

Radware® (NASDAQ: RDWR), a global leader in application security and delivery solutions for multi-cloud environments, today released its“2025 E-commerce Bot Threat Report.” The report found that automated bots—good and bad bots— accounted for 57% of e-commerce website traffic during the 2024 holiday season. It marks the first time that automated, non-DDoS generating bots drove more traffic than human shoppers, signalling a critical shift in the cybersecurity landscape for e-commerce providers and online retailers.

“Bad bots are no longer just based on simple scripts—they’re sophisticated, AI-enhanced agents capable of outsmarting traditional defences,” said Ron Meyran, vice president of cyber threat intelligence at Radware. “E-commerce providers and online retailers that rely on conventional security measures will find themselves increasingly exposed, not just during the holidays but year-round.”

The report highlights major bot attack trends and real-world attack data observed during the 2024 online holiday shopping season. In addition, it offers insights into the distributed, multi- vector attacks e-commerce providers and retailers can expect to battle this year.

Key findings and insights

AI-generated bots with human-like behaviour gain dominance: According to the report, bad bots made up 31% of total internet traffic during the last holiday season. Nearly 60% of the malicious traffic employed advanced behavioural techniques to evade traditional, signature-based detection. Combating these bots requires accurate AI-powered detection of attack patterns, including rotating IPs and identities, distributed attacks, CAPTCHA farm services, and other advanced anomalies,without causing false positives.

 

Mobile-focused attacks surge: Malicious bot traffic directed at mobile platforms rose 160% between the 2023 and 2024 holiday shopping seasons, representing a fundamental shift in attacker focus. Security strategies need to be shored up and tailored for vulnerable mobile platforms and attackers using more sophisticated techniques, including mobile emulators, mobile-specific proxies, and headless browsers with mobile user-agent strings.

 

Attacks leveraging distributed infrastructures and  residential proxy networks increase:

The proportion of holiday attack traffic originating from and blending in with ISP networks increased 32% between 2023 and 2024. Attackers are leveraging wider network and residential proxy services to evade rate-limiting, geo-based, and IP-based blocking mechanisms, creating even greater mitigation challenges for security teams working without advanced, multi-layered protections.

 

Coordinated multi-vector attack campaigns escalate: To maximise their success, attackers are targeting applications by combining bot attacks with web application vulnerability exploits, business logic attacks, and API-focused attacks. Protecting already burdened security systems requires an integrated application security strategy that uses the latest threat intelligence and cross-correlates security threats across security modules.

Radware’s complete bot report can be downloaded here.

 

More from this category

  • Business Company News, RetailOnline Retail
  • 17/12/2025
  • 07:30
The Sensory Specialist

Enough Recalls: The Safety Testing Gap Putting Our Children at Risk

Key Facts: Australia has no blanket requirement for mandatory pre-market safety testing for many children’s products labelled “3+”, unless a specific hazard standard applies (such as button batteries or magnets). Mandatory safety standards primarily apply to toys for children up to and including 36 months, and to products with identified risks such as button batteries or magnets. In 2024–25, the ACCC published 248 product recalls, many involving consumer goods that posed potential hazards to children. Recent recalls have included asbestos-contaminated children’s sand products and popular retail toys recalled due to serious choking risks. Consumer safety advocates and industry experts are…

  • Information Technology
  • 17/12/2025
  • 01:10
OMP

Eastman, AstraZeneca, Kraft Heinz, and P&G Recognized with OMP Supply Chain Awards

MIAMI, FLORIDA / ACCESS Newswire / December 16, 2025 / AstraZeneca, Eastman, Kraft Heinz, and P&G have been recognized for their outstanding contribution at…

  • Contains:
  • Information Technology
  • 16/12/2025
  • 17:41
Market Logic Software, GmbH

New APAC Partnership with Matter Brings Market Logic Software’s Always-On Insights Solutions to Local Brand and Experience Leaders

BERLIN, DE / ACCESS Newswire / December 16, 2025 / Market Logic Software, the market-leading SaaS provider of insight management solutions, has announced a…

  • Contains:

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.