News

Akamai SOTI 2026: Commerce Faces AI Bot Attacks and Agentic Fraud

News | 20.07.2026

Commerce has become the most targeted industry for cybercriminals as autonomous AI agents blur the line between legitimate customers and attackers.

The rapid rise of agentic commerce and autonomous AI tools has fundamentally changed the threat landscape. According to Akamai's latest State of the Internet (SOTI) security report, Securing the Agentic Storefront: Attacks on Commerce, nearly half of all commerce traffic on Akamai's global network now consists of AI bots. For CISOs and security leaders, this means the traditional customer identity model is being replaced by AI agents acting on behalf of humans, creating unprecedented visibility and control challenges.

What was announced

Akamai (NASDAQ: AKAM) released its 12th annual SOTI Security report, revealing that as of December 2025, 47.9% of all commerce traffic across its global network consists of AI bots. The industry faces relentless application-layer (Layer 7) DDoS activity, malicious web exploits, and a narrowing gap between traditional application attacks and API-targeted exploits.

We are securing a digital frontier where the customer is increasingly an AI agent operating on behalf of the human user. This report reveals how and why security leaders must embrace agentic readiness, to architect sites that welcome legitimate AI while aggressively shutting down malicious bots

Patrick Sullivan, CTO of Security Strategy at Akamai

Key findings include the rise of agentic commerce fraud, where autonomous AI shopping agents mimic human microbehaviors and threat actors hijack legitimate AI assistants to abuse stored payment credentials. LLMs are also being used to create synthetic identity fraud with Frankenstein accounts that bypass static defenses.

Why this matters

For CIOs, CISOs, IT directors, and procurement leaders, the report signals a strategic shift. Commerce was targeted by Layer 7 DDoS attacks nearly 3 trillion times in 2025, with retail bearing 84% of that volume. Web attacks targeting APIs rose 9% year over year, and 85% of commerce respondents experienced at least one API-related incident in the past year, yet only 22% know which APIs expose sensitive data.

Regional trends further illustrate the scale: bot activity surged 63% in APAC and 48% in LATAM, while North America led AI bot activity with 33 billion counts. Between November 2025 and April 2026, malware represented 56.5% of endpoint threat activity, and average daily phishing volume jumped from 56,600 in February to 134,600 in April.

Technical details

  • AI bot traffic: 47.9% of all commerce traffic globally as of December 2025.
  • Top AI bot sources: OpenAI, ByteDance, and Anthropic account for the majority of AI bot triggers, with training crawlers representing over 70%.
  • API risk: 85% of commerce organizations reported API-related incidents; only 22% have visibility into APIs exposing sensitive data.
  • Layer 7 DDoS: Nearly 3 trillion attacks in 2025, with retail absorbing 84% of the volume.
  • Endpoint threats: Malware at 56.5%, phishing at 37.6% of observed activity between November 2025 and April 2026.
  • Microsegmentation gap: 92% of organizations use basic network segmentation, but only 35% have implemented true microsegmentation.

Softprom and Akamai

Softprom is the official distributor of Akamai. Organizations seeking to secure their agentic storefronts, govern AI bot automation, and mitigate Layer 7 DDoS and API risks can access Akamai solutions through Softprom's expert team.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.