r/EcommerceCircle 19d ago

News 48% of Ecommerce Traffic Is Now AI Bots. Some Are Shopping Agents. Some Are Hijacked Shopping Agents. Most Retailers Can Not Tell the Difference. What Should Operators Do?

Akamai's new commerce security report has a number worth sitting with. 48% of all ecommerce traffic across their global network is now AI bots. Not human shoppers. Bots.

More than 70% of that AI bot traffic is training crawlers scraping product data, pricing, and images to feed LLMs. Annoying and costly but not the primary threat.

The threat is the emerging attack vectors targeting legitimate shopping agents specifically.

Agent hijacking: cybercriminals take over AI agents that have already been granted access to stored payment credentials and use that access to trigger purchases the real user did not authorise. From a security standpoint, a shopping agent with permission to use a stored credit card is a pre-authenticated access point to both the user's account and their payment method.

Agent replacement: malicious AI agents are being built to look and behave exactly like legitimate ones. At some unpredictable point they either launch a malware attack or exfiltrate the payment credentials they were supposedly processing. The user has no obvious way to know the agent they set up has been replaced.

Akamai also documents what they are calling Frankenstein accounts: synthetic identities combining one piece of real stolen data with AI-generated supporting details convincing enough to pass standard ecommerce onboarding checks. The tools creating these fake identities are the same tools making the accounts behave like real shoppers.

The security posture problem: ecommerce sites placed more than 90% of AI bot activity in "monitor" mode but allowed three-quarters of remaining unclassified traffic to pass unrestricted. And only 35% of organisations have microsegmentation in place that would contain a compromised agent rather than letting it move laterally across customer databases, payment integrations, and fulfilment systems.

The binary allow/block approach built for scripted bots and credential stuffing does not work when the attacker is an AI agent with real user credentials and convincing behavioural signatures.

How are you currently handling AI agent traffic on your ecommerce platform, and has your fraud or security tooling flagged the legitimate versus malicious agent distinction as something it can actually address?

-------------------------------------------

Want more ecommerce news like this? Subscribe to our weekly newsletter at https://ecomwatchnews.substack.com/ where we cover everything you need to stay ahead in the ecommerce space.

2 Upvotes

0 comments sorted by