Financial services industry hit hardest by bad bots, making up almost half of overall website traffic; Russia origin of most blocked attacks

REDWOOD SHORES, Calif. – April 21, 2020 – Imperva, Inc., the cybersecurity leader championing the fight to secure data and applications wherever they reside, today released its annual report titled: “2020 Bad Bot Report: The Bad Bots Strike Back.” The report investigates the automation that wreaks havoc on websites and mobile apps. The findings revealed bad bot traffic has increased compared to previous years, comprising almost one quarter (24.1%) of all website traffic and most heavily impacting the financial services industry. The report is based on 2019 data collected from Imperva’s global network including hundreds of billions of bad bot requests anonymized across thousands of domains.

Key Findings from the 2020 Bad Bot Report:

  • Bad bot traffic rises to highest levels ever. In 2019, bad bot traffic comprised 24.1% of all website traffic, rising 18.1% from the year prior. Good bot traffic consisted of 13.1% of traffic—a 25.1% decrease from 2018—while 62.8% of all website traffic came from humans.
  • Financial services industry hit hardest by bad bots. Every industry has a unique bot problem ranging from account takeover attacks and credential stuffing to content and price scraping. The top 5 industries with the most bad bot traffic include financial services (47.7%), education (45.7%), IT and services (45.1%), marketplaces (39.8%), and government (37.5%).
  • Moderate to sophisticated bad bots make up almost three quarters of bad bot traffic. Advanced persistent bots (APBs) continue to plague websites and often avoid detection by cycling through random IP addresses, entering through anonymous proxies, changing their identities, and mimicking human behavior. In 2019, 73.7% of bad bot traffic was APBs.
  • More than half of bad bots claim to be Google Chrome. Continuing to follow browser popularity trends, bad bots impersonated the Chrome browser 55.4% of the time. The use of data centers reduced again in 2019, accounting for 70% of bad bot traffic—down from 73.6% in 2018.
  • For the third year in a row, the most blocked country is Russia. In 2019, 21.1% of country blocks were Russia, followed closely by China at 19%. Despite this, with most bad bot traffic emanating from data centers, the United States remains the “bad bot superpower” with 45.9% of attacks coming from the country.

“We closely monitor how malicious bots iterate to evade detection and commit a wide range of attacks, and this year’s findings have revealed the next evolution: Bad Bots as-a-Service,” said Kunal Anand, CTO at Imperva. “Bad Bots as-a-Service is an attempt by bot operators to legitimize their role and appeal to organizations facing increased pressure to stay ahead of competition. It’s critical that businesses spanning all industries learn which threats are most pervasive in their field and take the necessary steps to protect themselves.”

Bad bots interact with applications in the same way a legitimate user would, making them harder to detect and prevent. They enable high-speed abuse, misuse, and attacks on websites, mobile apps, and APIs. They allow bot operators, attackers, unsavory competitors, and fraudsters to perform a wide array of malicious activities. Such activities include web scraping, competitive data mining, personal and financial data harvesting, brute-force login, digital ad fraud, spam, transaction fraud, and more. Produced by the Imperva Research Labs, a premier research organization for security analysis, vulnerability discovery, and compliance expertise, the 2020 Bad Bot Report underscores the increasing pervasiveness of bad bots, revealing that no industry is safe from malicious bot activity.

To download a full copy of Imperva’s report, visit: https://www.imperva.com/resources/resource-library/reports/2020-Bad-Bot-Report

To ask questions and learn more, register for the upcoming webinar covering the 2020 Bad Bot Report taking place on Tuesday, May 5, at 10:00 a.m. PT / 1:00 p.m. ET.

About Imperva
Imperva is an analyst-recognized, cybersecurity leader on a mission to protect customers’ digital assets by accurately detecting and effectively blocking incoming threats, and empowering customers to manage critical risks, so they do not have to choose between innovating for their customers and protecting what matters most. At Imperva, we tirelessly defend our customer’s business as it grows, giving them clarity for today and confidence for tomorrow. Learn more at www.imperva.com, our blog, or Twitter.