Bots aren’t new. What they’re doing now is.
Ecommerce bots aren’t new. Every site has always had bots crawling it: search engines, monitoring tools, the odd scraper. That’s old news.
What’s changed is the volume, and who’s driving it. Imperva’s 2026 Bad Bot Report puts automated traffic at 53% of all web traffic last year, ahead of humans for the second year running. 40 points of that are bad bots, up from 37% the year before. AI-powered bot attacks specifically grew 12.5 times year on year. HUMAN Security’s 2026 benchmark shows AI-driven traffic growing around 187% across 2025, eight times faster than human traffic, with agentic traffic (software acting on someone’s behalf) up nearly 80-fold. Cloudflare’s Matthew Prince has gone on record saying bot traffic will overtake human traffic on the open web by 2027.
None of that is abstract. We’re seeing these ecommerce bot attacks play out in a handful of recognisable patterns, and they all point at the same shift: AI hasn’t just added more bots. It’s changed what a bot can do and how hard it is to spot.
The bot attack patterns hitting ecommerce sites
- AI crawlers overloading category pages. Verified, non-malicious bots can still generate enough requests against faceted navigation to take a server down. It isn’t an attack. It has the same effect as one.
- Carding attacks that skip the checkout. Some attacks post straight to a payment provider’s own API, which often sits outside the platform’s normal request validation. The checkout CAPTCHA never gets a look.
- Search APIs scraped for competitive intel. Bots can query a search API directly for pricing and inventory. That traffic is invisible to standard analytics, and rotating IPs keeps it untraceable.
- Geo and IP rotation to dodge blocking. Attacks shift countries or IP ranges mid-campaign, which makes geo-blocking a short-term fix at best.
- Manual fraud that looks automated. A person testing stolen cards by hand still produces a bot-like request pattern. CAPTCHA and Turnstile won’t catch it.
Different attack surfaces, one pattern: the traffic isn’t hitting the front door. It’s going straight for the API, the payment endpoint, the search index, wherever the usual defences aren’t watching.
Bots and AI, not bots or AI
“Bot” and “AI” get used interchangeably, and they’re not the same problem.
Some of what’s landing on ecommerce sites right now is AI making old bot behaviour faster and cheaper to run: card testing that used to take a criminal hours now runs itself, at higher volume, with less skill required. Signifyd’s 2026 State of Fraud Report has card-testing attacks up 175% year on year in the first four months alone.
Some of it is AI creating new categories of traffic that didn’t really exist before: agentic tools genuinely browsing and buying on someone’s behalf, or AI search crawlers indexing your catalogue at a scale no human visitor ever would. Neither of those is malicious. Both can still take your site down if you’re not planning for the load.
And some of it is old-fashioned fraud that just happens to look like a bot because it’s automated at the payment layer. Turnstile and reCAPTCHA are good at spotting automated behaviour. They do nothing for a person manually running stolen cards through an exposed endpoint.
Treating all three as “the bot problem” leads to the wrong fix. A CAPTCHA on your storefront doesn’t touch an API being hit directly. A blanket IP block doesn’t touch a fraudster who rotates countries. And blocking AI crawlers outright might just mean your products stop showing up in the AI search results your customers are increasingly using to find you.
What actually holds up
A few things are worth checking on your own site, whichever of these patterns you’re up against:
- Check the endpoint, not just the page. If your payment provider has its own API routes, find out whether they sit inside your platform’s request validation, or bypass it.
- Watch traffic at the API level. GA4 only sees what loads in a browser. Anything hitting search, payments, or inventory APIs directly won’t show up there.
- Trust behaviour over IP. Missing referer headers and odd request patterns are harder to fake than an IP address is to rotate.
- Split the bot problem from the fraud problem. Automated volume and manual abuse need different tools. One won’t fix the other.
- Loop in your payment provider. 3D Secure and AVS settings live outside your platform and get missed in standard security reviews.
The bit that’s easy to miss
Not every bot showing up on your site is trying to harm it. Some of it is AI search infrastructure that’s going to matter more, not less, as people start finding products through AI assistants instead of Google. Blocking all AI traffic on principle might solve this quarter’s server load and cost you next year’s discoverability.
The sites coping best with this aren’t running the most aggressive blocking rules. They’re the ones who’ve actually gone and looked at which parts of their stack a bot could reach that a human never would.
Most of what’s hitting ecommerce sites right now doesn’t come through the front door. Most of the defences going up are still standing guard there anyway.
This article was written by Ed Bennett, Frontend Developer at JH.

Back before React was even a thing, Ed was messing about in Macromedia Dreamweaver, teaching himself to code long before it was a career. A decade of that has been professional, at JH for five years of it. What’s stayed constant is the appetite for problem solving and getting into the technical weeds, more the how-it’s-built side than the how-it-looks side. He’s picked up a full stack range of skills along the way rather than sticking with what he already knew. Away from the screen, he’s usually gaming or with family, sometimes both.
