Sunday, June 7, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Application Security Security Bloggers Network 

Home » Cybersecurity » Application Security » US Websites Targeted by 40% of the Bad Bot Traffic Worldwide

SBN

US Websites Targeted by 40% of the Bad Bot Traffic Worldwide

by Bruce Lynch on August 2, 2022

Bad bot attacks are often the first indicator of fraudulent activity targeting your website. This activity may be over-the-top, like validating stolen user credentials and credit card information to later be sold on the dark web or scraping proprietary data to gain a competitive advantage. Bot attacks may also be executed for stealthier activities like surveilling applications and APIs in an attempt to discover vulnerabilities or weak security. Online fraud from automated bot attacks is a clear threat to your business and presents a significant risk to your customers, business partners, and employees.

Account takeover (ATO) fraud is a hallmark goal of bad bot attacks. ATO fraud can result in customers being unable to access their online accounts and having sensitive personal information stolen from them. Bad bots mask themselves and attempt to interact with applications in the same way a legitimate user would, which makes them more difficult to detect and stop. They facilitate high-speed abuse, misuse, and attacks on your websites, mobile apps, and APIs. They enable bot operators, attackers, unsavory competitors, and fraudsters to carry out a staggering array of malicious activities against your digital assets.

These activities include web scraping, competitive data mining, personal and financial data harvesting, brute-force login, digital ad fraud, denial of service, denial of inventory, spam, transaction fraud, and more.

Bad bot attacks and the loss and pain they inflict are a worldwide scourge. To be sure, some countries are affected more than others. In this post, we’ll reveal the proportion of bad bot traffic for several nation states, tell you which countries are most frequently targeted, and offer recommendations on how to make your organization a hard target for bad bots – particularly if you live in a highly-targeted nation.

Here’s what the Imperva Threat Research team uncovered about the impact of bad bots on nation states:

Germany and Singapore endure the highest proportion of bad bot traffic

Examining the proportion of bad bot traffic by country reveals that several nations exceeded the global average of 27.7%. Germany and Singapore saw almost 40% of traffic originate from bad bots. The United States was also higher than the global average, with 29.1% bad bot traffic.

Bad Bot Proportion by Country

The United States and Australia were the most targeted countries

The United States was the leading target of bad bots in 2021 (43.1%), a slight increase over 2020 (37.2%). Australia was the second most attacked country by bad bots, targeted by 6.8% of all bad bot traffic. It was closely followed by the United Kingdom (6.7%) and China (5.2%).

Make your organization a hard target for bad bots and online fraud

Bad Bot Most Targeted Country

 

Every site is targeted for different reasons, and usually, by different methods, no answer will be effective for every organization. However, you can take proactive steps to address the problem today. If you are in one of the more heavily affected countries, you should start immediately. Here are eight recommendations for improving bad bot activity detection and automated fraud detection:

1. Better Risk Identification.
Stopping bot traffic begins with identifying potential risks to your website marketing, and eCommerce campaigns bring more bots. For example – launching a limited quantity, high-demand product. Whether it is a highly sought-after pair of sneakers, a new generation gaming console, or a limited-edition collectors’ item, announce a date and time for a coveted product launch, and bots will be there to get their hands on it first. Make sure that you are prepared to handle the high volume of traffic that is going to include a high ratio of evasive bots trying to scoop up the products and deny your customers access.

Improved understanding of the ways your site could become a target is key to a successful bot management strategy. Some website functionalities are highly exploitable by bad bots. Adding login functionality creates the opportunity for credential stuffing and credential cracking attacks. Adding a checkout form increases the chances of credit card fraud (carding/card cracking). Adding gift card functionality invites bots to commit fraud. Make sure that these pages have extra security measures and a more strict ruleset.

2. Reduce Vulnerability.
Protect exposed APIs and mobile apps — not just on your website — and share blocking information between systems. Protecting your website is only part of the solution; don’t forget about the other paths that lead to your web applications and data.

3. Threat Reduction.
Many of the bot tools and scripts contain user-agent strings with browser outdated versions. In contrast, humans are forced to auto-update their browsers to newer versions.

4. Proxy Services Threat Reduction.
Bad bots increasingly use proxy services to hide their attacks. Attackers do this to appear as human users by rotating bulk IP services in their requests. Not allowing access from bulk IP data centers will decrease the likelihood of botnet traffic. Examples of bot providers include Host Europe GMBH, Dedibox SAS, Digital Ocean, OVH SAS & Choopa, and LLC.

5. Evaluate Traffic.
Evaluating traffic for bots can be difficult without clear indicators of the traffic type. Bot traffic can be associated with high bounce rates or low conversion rates. Another strong indication of bots is unexplained traffic spikes or high requests to a particular URL. Bots focusing on a specific event could explain the dramatic increase to a particular endpoint. Determine if there’s a clear source from the increased traffic levels. Such examples can be seen in an IP, ISP, or URL receiving more than average traffic levels.

6. Monitor Traffic.
On login pages, define your failed login attempt baseline, then monitor for anomalies or spikes. Set up alerts so you’re automatically notified if any occur. Advanced “low and slow” attacks don’t trigger user or session-level alerts, so be sure to set global thresholds. On checkout and gift card validation pages, an increase in failures, or even traffic, can be a signal of carding attacks or that bots such as GiftGhostBot are attempting to steal gift card balances.

7. Awareness.
Stay aware of data breaches and leaks occurring around the world. The ease of buying credential dumps from breaches and renting bot infrastructure to automate an attack has made this a very real risk. Bots will often use newly compromised credentials for stuffing attacks and ATO, as they are more likely to still be active, increasing the probability of compromising user accounts on your site.

8. Evaluate Bot Protection solutions.
In early bot attack days, you could protect your site with a few tweaks and configurations to block bad bots. The data explored throughout this report shows that these days are long gone. Today’s bad actors are using bots for their ease of use and effectiveness. The tools used are constantly evolving, bot traffic patterns are difficult to detect, and their sources can shift frequently. In advanced bots, we are seeing attacks mimicking human behavior like never before. For these reasons, hackers widely choose bots to target your site, as their incentives are high with low risk. Today, it’s almost impossible to keep up with all of the threats on your own. Your defenses need to evolve as fast as the threats, and you need dedicated support from a team of experts.

Where to learn more

The 9th Annual Imperva Bad Bot Report is based on data collected from the Imperva global network throughout 2021. The data is composed of hundreds of billions of blocked bad bot requests, anonymized over thousands of domains. This report delivers meaningful information and guidance about the nature and impact of these automated threats. Download it here.

The post US Websites Targeted by 40% of the Bad Bot Traffic Worldwide appeared first on Blog.

*** This is a Security Bloggers Network syndicated blog from Blog authored by Bruce Lynch. Read the original post at: https://www.imperva.com/blog/us-websites-targeted-by-40-of-the-bad-bot-traffic-worldwide/

August 2, 2022August 2, 2022 Bruce Lynch account takeover, advanced bot protection, Application Security, ATO, bad bots, Digest
  • ← Risk Assessment: The Crucial Element Of A Successful Security Implementation Program
  • Get to Know Jimmy Tsang, Pondurance VP of Marketing →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Toxic Flows: When Your Agent Skill Becomes a Supply Chain Attack
The Cost of Exposure: Managing the Operational Risks of Executive Security Incidents
The Future of Agentic Software Delivery: Unifying Source & Binaries
35 Million Lines, Zero Build-Breakers: How Adyen Scaled DevSecOps
Zero Trust for Agentic AI: Managing Non‑Human Identities at Scale

Podcast

Listen to all of our podcasts

Secure by Design

4 days ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

2 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

2 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

3 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

4 weeks ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models
AI-Powered Computer Worm Reveals New Cybersecurity Threat
Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds
Is It Time For A U.S. Cyber Force?
Health Entities and Ransomware — HHS Adopts a “Blame the Victim” Strategy. Let’s See if It Works.
Imperva Customers Protected Against CVE-2026-49975 (HTTP/2 Bomb) DoS
Cybersecurity Trends 2026
OpenAI Codex Supply Chain Attack Exposes Growing Risks in AI Development Environments
The June 2026 AI Executive Order: What federal agencies need to know and how Tenable can help
New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds
Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security Featured Incident Response Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds

June 4, 2026 Jeffrey Burt | 3 days ago 0
Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models
Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security Endpoint Featured Governance, Risk & Compliance Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence 

Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models

June 3, 2026 Jeffrey Burt | 4 days ago 0
Sumo Logic Brings SIEM Platform to AWS European Sovereign Cloud
Cloud Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Sumo Logic Brings SIEM Platform to AWS European Sovereign Cloud

June 2, 2026 Michael Vizard | Jun 02 0

Security Humor

Randall Munroe’s XKCD 'Types of Board Game'

Randall Munroe’s XKCD ‘Types of Board Game’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The State of Cloud Native Security 2020
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.