Commerce has become the main target for AI bot attacks, and the scale of the problem has stopped being an issue only for the largest sales platforms.[1][2] For companies that run online sales, B2B systems, ordering portals, and API integrations, this means looking at security not only through the lens of classic vulnerabilities, but also through automation and traffic generated by agents.[1][3]
Why this topic matters
Akamai reported that in 2025 commerce organizations were hit by more than 17 trillion bots, and by the end of December 2025 nearly 47.9% of traffic in that sector already came from AI bots.[1][2] The report also shows that API-layer attacks grew 9% between Q4 2024 and Q4 2025, which signals a clear attacker shift toward business logic, integrations, and data, not only the classic web application surface.[2][4]
For owners of online stores, ordering platforms, partner extranets, and self-service systems the conclusion is simple: the attack surface grows along with process automation.[3][4] The more forms, endpoints, integrations, and intermediate layers, the easier it becomes to abuse scraping, enumeration, account takeover, promotion testing, or to overload services with application traffic.[3][5]
What agentic commerce is
Agentic commerce is a model in which AI agents perform part of the purchasing actions on behalf of the user — searching for products, comparing terms, initiating transactions, or pulling data from commerce systems.[3][6] The same trend that improves customer convenience and increases automation also creates new opportunities for criminals, because malicious bots can mimic legitimate agents and operate at scale.[1][7]
Akamai launched its Agentic Security Framework in June 2026 for AI-driven interactions and commerce, developed with partners such as Visa, Experian, Skyfire, and TollBit.[6][7][8] The mere existence of such a framework shows that the market has stopped treating AI agents as a curiosity and started treating them as a new class of identity, traffic, and operational risk.[7][6]
Which risks are growing the fastest
The biggest problem today is not only that there are more bots, but that they increasingly imitate legitimate business traffic.[3][9] In practice this translates into higher risk of price scraping, stock hoarding, promotional abuse, API probing, transactional fraud, and costly infrastructure load.[3][5][9]
The Akamai report also shows that commerce was targeted by Layer 7 DDoS attacks nearly 3 trillion times in 2025, with the retail vertical absorbing 84% of that volume within commerce.[5][4] This also matters for manufacturing and distribution companies, because more and more of them expose ordering portals, price lists, product catalogs, and after-sales systems to customers and partners over the web and APIs.[3][4]
What companies should do
Akamai recommends first mapping the entire revenue chain and inventorying APIs, including shadow APIs that often remain outside standard security oversight.[1][3] The second step is moving away from a simple allow-or-block model toward evaluating automation by intent, business value, and risk level.[1][3]
Another recommendation is to limit blast radius through real microsegmentation, because according to Akamai 92% of organizations use basic network segmentation, but only 35% have implemented true microsegmentation.[1][10] It is also important to combine security with fraud control, so that teams respond to behavioral anomalies, session hijacks, and account abuse within a single operational model.[1][3]
What this means for CHORS.NET
For CHORS.NET this trend opens a very concrete service area: exposure screening, vulnerability review, attack surface analysis, and risk assessment related to bot traffic and API integrations in B2B and e-commerce environments.[1][4] This model is especially important for companies that do not think of themselves as "e-commerce", but run customer portals, ordering forms, partner systems, marketplace feeds, or automated connections between ERP, CRM, and the web layer.[3][4]
From an E-E-A-T standpoint it is worth highlighting the author\u2019s operational and technical experience, and the practical approach to identifying risks before they become business incidents. Marcin Białczyk, CHORS.NET, focuses on the company\u2019s external visibility on the internet, vulnerability analysis, and recommendations that operations, IT, and business owners can actually implement.[4][1]
Practical takeaway
If a company grows online sales, self-service channels, APIs, or AI-agent-based solutions, security must cover not only application vulnerabilities but also control of automation and business abuse.[1][3] In 2026 the question is no longer whether AI bots will hit commerce, but whether the organization can distinguish valuable traffic from harmful traffic and respond appropriately.[1][9]
Sources
- Akamai — Commerce Becomes the Epicenter for AI Bot Attacks and Agentic Fraud in 2026
- GlobeNewswire — Akamai Research: Commerce Becomes the Epicenter for AI Bot Attacks
- ITBrief UK — Akamai warns commerce is top target for AI bot attacks
- StockTitan — Akamai: Commerce Faced Nearly 3 Trillion Layer 7 DDoS Attacks in 2025
- TechJournal — AI bots account for nearly half of all commerce traffic: Akamai
- Akamai — Unveils Agentic Security Framework to Power Trusted AI-Driven Interactions and Commerce
- Nasdaq — Akamai Unveils Agentic Security Framework
- Fifth Row — How Agent-Driven Commerce Is Reshaping Risk: Inside Akamai Framework
- Softprom — Akamai SOTI 2026: Commerce Faces AI Bot Attacks and Agentic Fraud
- Akamai — Segmentation Impact Study 2025 (PDF, microsegmentation 92%/35%)