Radware’s 2025 E-commerce Bot Threat Report reveals critical shift in online retail traffic and cybersecurity threats
Radware® (NASDAQ: RDWR), a global leader in application security and delivery solutions for multi-cloud environments, has released its latest 2025 E-commerce Bot Threat Report, revealing a landmark shift in the online retail landscape: automated bots now account for 57% of e-commerce website traffic.
For the first time, non-DDoS generating bots — both good and malicious — have overtaken human shoppers in driving traffic, signalling a significant new challenge for online retailers and e-commerce providers.
“Bad bots are no longer just based on simple scripts—they’re sophisticated, AI-enhanced agents capable of outsmarting traditional defences,” said Ron Meyran, Vice President of Cyber Threat Intelligence at Radware. “E-commerce providers and online retailers that rely on conventional security measures will find themselves increasingly exposed, not just during the holidays but year-round.”
The report draws on real-world attack data observed during the 2024 holiday shopping season, highlighting the growing complexity of bot threats and the evolving defensive strategies businesses will need to deploy throughout 2025 and beyond.
Key findings
Rise of AI-driven bots
Bad bots made up 31% of total internet traffic during the 2024 holiday period, with nearly 60% of that malicious traffic deploying advanced behavioural techniques to evade traditional, signature-based detection. Techniques such as rotating IPs and identities, distributed attacks, CAPTCHA farm services, and other sophisticated anomalies now demand more accurate, AI-powered detection mechanisms that minimise false positives.
Spike in mobile-focused attacks
Malicious bot traffic targeting mobile platforms surged by 160% between the 2023 and 2024 holiday seasons. This trend reflects a fundamental shift in attacker focus, driven by the vulnerabilities inherent to mobile platforms. Techniques including mobile emulators, mobile-specific proxies, and headless browsers with mobile user-agent strings have become increasingly prevalent, underlining the urgent need for mobile-first security strategies.
Use of distributed infrastructures and residential proxies
The proportion of attack traffic originating from ISP networks increased by 32% year-on-year. Attackers are increasingly using residential proxy services to blend in with legitimate user traffic and evade geo-based and IP-based blocking techniques. This trend presents heightened challenges for security teams, particularly those without advanced, multi-layered protection frameworks.
Escalation of multi-vector attacks
Coordinated campaigns are now combining bot attacks with web application exploits, business logic attacks, and API-based threats. The complexity of these attacks demands a fully integrated application security strategy — one that leverages up-to-date threat intelligence and cross-correlates indicators across multiple security modules to identify and mitigate threats more effectively.
Looking ahead
As online shopping continues to grow, so too does the sophistication of threats targeting e-commerce platforms. Retailers will need to embrace smarter, AI-driven security strategies that can adapt to rapidly evolving attack patterns without compromising the user experience.
The 2025 E-commerce Bot Threat Report serves as a timely wake-up call for businesses to re-evaluate their cybersecurity posture, ensuring that protection measures are robust enough to meet the challenges of the increasingly automated and hostile digital landscape.
For more information, visit Radware’s website.








