Site navigation

Bots Now Behind 94% of Fraudulent Logins, Warns Cloudflare

Tom Quinn

,

AI cybercrime
“Threat actors are constantly changing tactics, finding new vulnerabilities to exploit and ways to overwhelm their victims,” said Blake Darché, Cloudforce One.

The barrier to entry for sophisticated cybercrime has collapsed, Cloudflare has warned, with nation-state actors and first-time cybercriminals alike leveraging AI, conducting DDoS attacks of unprecedented magnitude, and finding ways of logging in, rather than breaking in, to secure networks.

Detailing the tactics and trends behind the 230 billion threats blocked on average each day, the 2026 Cloudflare Threat Report found that threat actors are now abusing LLMs to map networks in real-time, develop new exploits, and create hyper-realistic deepfakes. 

In one notorious supply chain attack, Cloudflare’s threat research team, Cloudforce One, tracked a threat actor who leveraged AI to identify the location of high-value data and compromise hundreds of high-volume SaaS applications that allow multiple organisations to share resources, while others were observed infiltrating payroll systems and tricking software into trusting them.

North Korean operatives, meanwhile, were seen using AI-generated deepfakes and fraudulent IDs to bypass hiring filters, embedding state-sponsored workers directly into Western corporate payrolls, masking their true location using US-based “laptop farms.”

Other state-sponsored actors, specifically the Chinese-linked groups Salt Typhoon and Linen Typhoon, have shifted focus to North America’s critical infrastructure, targeting telecoms, government entities, and IT services with persistent pre-positioning, the act of installing code on a network or system of a rival state to allow for future attacks.

Once a nuisance, bots have also emerged as a core security threat, with Cloudflare estimating they now make up around 30% of all HTTP traffic. The study found that 94% of all fraudulent login attempts originate with bots, with attackers using tools like Selenium and Puppeteer to mimic human mouse movements and scrolling, allowing their creations to bypass traditional security measures aimed at credential stuffing.


Recommended


Added to all that bad news, the report found that modern DDoS attacks are now well beyond human response capabilities, and have become powerful weapons used more than 47 million times last year.

Cloudflare found that large-scale botnets like Aisuru are evolving into nation-state level threats capable of taking down entire countries’ networks using record-breaking attacks reaching 31.4 Tbps with autonomous strikes that peak in seconds, placing an extreme resource tax on local infrastructure.

“Threat actors are constantly changing tactics, finding new vulnerabilities to exploit and ways to overwhelm their victims. To avoid being caught off guard, organisations must shift from a reactive posture to one fueled by real-time, actionable intelligence,” said Blake Darché, head of threat intelligence with Cloudforce One at Cloudflare. 

“This report is a North Star for understanding the scale of attacks and how threat actor aggression and techniques are shifting. The message to defenders is simple: lead with intelligence or risk falling behind in a race where the stakes have never been higher.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data