The findings come from Statistica, which paints a sobering image of the damage malicious bots can do to businesses or web services.
A study from Akamai looked into this discussion in more depth, conducting a comprehensive study of over 300 global IT and security decision makers, of which 97% had over 1,000 employees. The study, From Bad Bots to Malicious Scripts: The Effectiveness of Specialized Defenses looked to help understand the role specialised third-party solutions play in the digital realm.
In the report, four main categories of attacks were discussed among participants, these were malicious bots, account takeovers (ATO), script risks, and audience hijacking.
Malicious bots were prevalent across all industries in the report. These bots are automated computer programs that can carry out a number of attacks such as malware distribution, DDoS attacks, web scraping and more actions which are designed to disrupt service and steal data.
A recent report from Data Dome found that two thirds of UK websites are unprotected against simple bot attacks, revealing how exposed businesses are to these automated threats that make up 30% of all internet traffic.
Another prevalent threat is ATO attacks, which 79% of respondents said their business had fallen prey to in the past year. ATO attacks happen when threat actors take control of a legitimate user account for nefarious purposes. This could happen through a number of ways such as phishing, brute force attacks, or social engineering.
Once credentials are stolen, the cyber-criminals can steal sensitive information, conduct fraudulent transactions, and a number of other criminal activities.
Another significant tool in a hackers arsenal were script risks, which targeted around eight in ten organisations in the survey. This risk stems from vulnerabilities in the script of the organisation’s website or web application.
Recommended reading
- NCSC Releases New Tool to Scan for Malware Vulnerabilities
- Digital Vision for Scotland: Adapting to a Global Digital Economy
- AI Bots Can Beat Captcha Tests Better than Humans Now
Potential script risks include data exfiltration, malicious extensions with harmful actions, or exploit vulnerabilities in the content management system.
The last category observed in the survey was audience hijacking which affected over a quarter (26%) of the surveyed leaders. This cyberattack is where cybercriminals divert web traffic for their own gain. The biggest dangers from this attack were cart abandonment and affiliate fraud, both of which have economic implications for the organisation.
In the European region, 92% of respondents were aware of it, but only 13% have been directly affected, showing the considerable steps security vendors have taken in this domain.





