|
DataDome's Inaugural E-Commerce Holiday Bot & Online Fraud Report Reveals the U.S. as the Top Source of Bot Attacks
Sunday, April 16, 2023
Study finds U.S. generated 10 times the number of bot attacks compared to China, the second highest source during the 2022 holiday season
NEW YORK, Feb. 7, 2023 /PRNewswire/ -- DataDome, the global leader in advanced bot and online fraud management, today released its inaugural "E-Commerce Holiday Bot & Online Fraud Report" which analyzes bot traffic during fraudsters' busiest time of year - the holiday season. The study identifies and quantifies the proliferation of bots, aggregating and analyzing traffic data of more than 110 billion requests made in Q4, 2022 across a range of e-commerce sites DataDome protects.
"During flash sales events such as Black Friday and Cyber Monday, e-commerce platforms typically face at least five times - and sometimes up to 30 times - more bot attacks than on normal days," said Benjamin Fabre, CEO & Co-Founder of DataDome. "As bad bots become more sophisticated and difficult to thwart, staying ahead of them is imperative. This holds true particularly during flash sales and the busy holiday season, when the impact of these attacks is maximized."
DataDome analyzed the website, mobile app and API traffic of e-commerce businesses it protects, across clothing, footwear, ticket, and electronic retail among other companies located in the United States, Europe, Australia, and Asia. Key observations from the report include:
-- The United States was the #1 direct source of bot attacks. The US
generated 10 times the number of bot attacks compared to China, the
second country of origin for the most bot attacks against online
retailers and e-commerce platforms during this period. Attackers tend to
choose IP addresses/proxies located in the same country as the website
they target in order to appear more human and bypass traditional
geo-blocking techniques. Many of the e-commerce sites DataDome protects
are in the US, which helps explain why so many attacks appear to have
originated from the US.
-- E-commerce bots are becoming increasingly sophisticated in their ability
to mimic human behavior and bypass basic security tools. The
availability of high-quality proxies has made it easy for attackers to
leverage IPs from the home location of their target business. And
attackers paid premium prices for ISP proxies, proving both the
increasing ROI of online fraud, especially scalping, around Black Friday
and other limited sales, and the effectiveness of ISP proxies in helping
cybercriminals avoid detection by more basic bot mitigation tools and
web application firewalls (WAFs).
-- 98% of the attacks were from scraping and scalping bots: Numbering in
the billions, scraping bots, considered a gateway automated threat that
often leads to more aggressive and damaging attacks, were used to test
the availability of products and target the limited infrastructure
resources during the busy holiday season. Scalping attacks followed, as
fraudsters tried to snag as much inventory as possible to resell for
profit later.
-- Some industries saw more impact than others: Industries that saw the
most bot traffic include clothing & footwear and electronic
goods--especially hot ticket items, such as gaming consoles and luxury
or limited edition merchandise. The biggest attack DataDome observed in
Q4 2022 targeted a large US retailer with ~66M malicious bot requests in
less than two hours.
"Fraudsters are getting easier access to more sophisticated bots and technology every day. As the ease and ROI of online fraud increase, so do the frequency and intensity of bot attacks," said Antoine Vastel, PhD, Head of Research at DataDome. "Yesterday's basic bot mitigation measures are no match against today's evolving threats--especially bots that use ISP proxies and machine learning to mimic human behavior. Now more than ever, it is critical that retailers protect all endpoints from attacks, as threats target the weakest link in their infrastructures."
The full research report, "E-Commerce Holiday Bot & Online Fraud," is available here. On February 16, 2023 at 12:00p EST, DataDome's Head of Research will host a webinar that dives into the report's findings.
For more information about DataDome's fraud detection and prevention, visit www.datadome.co/.
About DataDome
DataDome's bot and online fraud protection detects and mitigates attacks with unparalleled accuracy and zero compromise. Our machine learning solution analyzes 1 trillion data points per day to adapt to new threats in real time. Our 24/7 SOC experts protect hundreds of high-profile brands worldwide, including Reddit, Patreon, and AngelList. A force multiplier for IT security teams, DataDome is fully transparent, easy to deploy, and frictionless for consumers. In 2022, DataDome was named a Strong Performer in the Forrester Wave: Bot Management and ranked the top G2 Leader in Bot Detection & Mitigation for Fall 2022 and Winter 2023.
View original content to download multimedia:https://www.prnewswire.com/news-releases/datadomes-inaugural-e-commerce-holiday-bot--online-fraud-report-reveals-the-us-as-the-top-source-of-bot-attacks-301740726.html
SOURCE DataDome
|
|
|
|
|
 |
The New Identity Theft Crisis: AI Scams, Child Victims, and Credit Damage Are All Spiking | Jan 22, 2026
|
 |
AllSci Launches Hypothesis Publishing: A Seamless Way to Share, Connect, and Advance Scientific Ideas | Jan 22, 2026
|
 |
Fintech Startup BON Credit Secures $3.5 Million In Funding | Jan 22, 2026
|
 |
Darwin CX Caps a Banner Year with AI Launch, Sold-Out Events, and Industry Book Launch | Jan 22, 2026
|
 |
Nudge Security Unveils Industry's Most Comprehensive AI Security Governance Platform | Jan 22, 2026
|
 |
Canadian Fintech Tuhk Inc., Founded by Ethoca and NuData Security Veterans, Raises US$6 Million Seed Round Led by FINTOP, with Lloyds Banking Group and Capital One Ventures | Jan 22, 2026
|
 |
PayDo Launches Unified Payment Infrastructure Suite for Digital Businesses | Jan 22, 2026
|
 |
IoTeX Publishes MiCA-Compliant Whitepaper for IOTX, Enabling EU-Wide Alignment Under the New Regulatory Framework | Jan 22, 2026
|
 |
TSX Venture Exchange Market Data Now Available Across Over 40 Blockchains via Chainlink | Jan 22, 2026
|
 |
Paxos Selects Mesh To Enable Trusted Crypto Deposits | Jan 22, 2026
|
|
|
|