Akamai: APAC Commerce Bot Attacks Surged 63% in 2025

Bot activity targeting Asia Pacific’s commerce sector rose 63% in 2025, the fastest increase of any region globally, as retailers, travel platforms and hospitality brands race to adopt AI-powered shopping and booking experiences.

That is according to Akamai‘s latest State of the Internet security report, Securing the Agentic Storefront: Attacks on Commerce. From July to December 2025, commerce accounted for 38% of all AI bot traffic observed across industries in APAC, the report found, underscoring the pace at which the region’s commerce sector is embracing automation.

APAC commerce becomes a bigger target

Retailers across the region are pivoting toward agentic commerce, using bots to hyperpersonalise shopping experiences and reduce cart abandonment, while chatbot growth is especially fast as businesses compete on customer experience. Akamai said this is making it harder to distinguish legitimate automation from malicious bots, scraping, credential stuffing and API abuse.

While retail remained the primary target, travel and hospitality faced greater exposure in APAC compared with other regions, driven by fragmented travel platforms, high digital and mobile adoption, popular loyalty programmes and seasonal booking peaks around holidays such as Lunar New Year, Golden Week and Diwali. Travel accounted for 22% of commerce web attacks in the region, with APIs targeted in 25% of attacks against the sector.

Commerce businesses in APAC also faced rising application-layer DDoS pressure, with Layer 7 DDoS attacks increasing 39%, from 260 billion to 361 billion events, in 2025. Among API-targeted Layer 7 DDoS attacks, retail accounted for 51%, followed by hospitality (28%) and travel (21%).

“APAC’s commerce sector is pivoting quickly toward a more automated and AI-enabled future, as businesses use GenAI chatbots and other AI-powered services to personalize experiences and reduce friction. But every chatbot interaction, booking flow and loyalty program integration creates another new digital surface that must be discovered, understood and protected,” said Reuben Koh, Director of Security Technology and Strategy, APJ at Akamai.

From blocking bots to managing risk

Akamai said the challenge for businesses has shifted from simply blocking bots to distinguishing automated activity that helps customers and drives revenue from activity that scrapes data, abuses APIs or enables fraud. The company recommends three priorities as commerce organisations embrace AI and automation:

  • Mapping the revenue chain: continuously identifying the APIs supporting payments, loyalty programmes, checkout, inventory and partner integrations, and understanding where sensitive data may be exposed.
  • Governing automation by risk: moving beyond blanket allow-or-block decisions toward a risk-based approach that distinguishes legitimate automation from malicious bot activity.
  • Preparing for peak traffic periods: strengthening surge capacity, testing DDoS response plans, monitoring for fake storefronts and credential exposure, and aligning cybersecurity and fraud teams ahead of major shopping and travel peaks.

Now in its 12th year, Akamai’s State of the Internet security reports draw on attack data observed across the company’s cybersecurity protective infrastructure, which handles a significant share of global web traffic.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading