The report highlights consumer-focused sectors as the prime targets for cybercriminals, with limited defences against malicious bots
DataDome’s 2024 Global Bot Security Report, released today, reveals a critical lack of protection on global websites, with more than 65 per cent vulnerable to simple bot attacks and 95 per cent of advanced bot attacks going undetected. The report, based on an analysis of over 14,000 websites by DataDome Advanced Threat Research (DDATR), exposes a significant cybersecurity gap, particularly within consumer-facing sectors.
E-commerce & Luxury Sectors at High Risk
The report highlights consumer-focused sectors as the prime targets for cybercriminals, with limited defences against malicious bots. The luxury and e-commerce sectors were identified as particularly vulnerable, with only 5 per cent of luxury brand websites and 10 per cent of e-commerce sites adequately protected from bot attacks. This leaves a substantial security gap as the holiday shopping season approaches—a period when online retail activity and corresponding cyber threats peak.
Media websites also showed weak bot protection, with only 6 per cent having robust safeguards in place. The remaining 94 per cent remain exposed to risks including ad fraud, content scraping, and DDoS attacks. The proliferation of malicious bot activity, which is inexpensive to set up and deploy, is particularly concerning as it is used to automate and amplify online fraud.
“Consumer-centric industries are highly vulnerable to malicious bot activity and face increased risks of financial loss, data breaches, and reputational damage,” said Antoine Vastel, Vice President of Research at DataDome. “As our research reveals, the low barriers for creating and deploying bad bots have made them a favoured tool for fraudsters seeking to exploit high-traffic websites. Needless to say, the need for robust, multi-layered bot protection has never been more urgent.”
Advanced Bot Threats Outpacing Traditional Security Measures
The last year has seen an increase in both basic and advanced bot-driven attacks, outpacing conventional defences. Advanced bots, particularly those powered by artificial intelligence, evade traditional CAPTCHAs through real-time bot farms, managing to bypass detection in over 95 per cent of cases. These sophisticated bots can impersonate legitimate users, spreading disinformation and circumventing user verification processes with high accuracy.
A notable example took place in July 2024, when the U.S. Department of Justice dismantled a large-scale Russian propaganda operation that used a “bot farm” to bypass a user verification system on X (formerly Twitter) and spread false information in the United States. This incident underscores the risks associated with bot-driven political interference, particularly as the 2024 U.S. presidential election season gains momentum.
“We’re seeing a surge in genAI-augmented media, which can be used for nefarious political influence,” Vastel added. “Social media platforms and media websites are being targeted by bad actors looking to spread political disinformation. Given that this is an election year, we strongly advise media websites to reassess the risks associated with malicious web traffic.”
Technological Advancements Complicate Bot Defence
The evolution of automated browsers, proxy usage, and AI-driven anti-detection frameworks has made it increasingly challenging for companies to guard against bot threats. Even among websites with some form of bot protection, nearly 45 per cent were penetrated by bots, with simple fake Chrome bots proving particularly difficult to detect. This leaves businesses exposed to a range of risks, including layer 7 DDoS attacks and account fraud.
Europe & North America Lag In Bot Defence
Regionally, Europe is the least protected against bot threats, with 68 per cent of websites lacking defences and only 8 per cent fully protected. North America is not far behind, with 64 per cent of websites unprotected and only 9 per cent fully safeguarded. This indicates a pressing need for stronger, more comprehensive bot security strategies in these regions.
DataDome’s 2024 Global Bot Security Report serves as a call to action, emphasising the need for advanced threat monitoring and multi-layered bot protection. As cybercriminals continue to refine their methods, protecting high-traffic websites from bot-driven fraud will require constant vigilance and innovation.

