47.9 percent of all global e-commerce traffic was generated by AI bots in December 2025. The number comes from Akamai's State of the Internet report released July 15—titled "Securing the Agentic Storefront: Attacks on Commerce"—and it's both a milestone and a warning.
Nearly half of all retail platform traffic isn't consumers browsing. It's automated systems, most running AI models, crawling product pages, testing APIs, and completing transactions. Industry projections spent years describing a future where AI agents do the shopping. That future has structurally arrived. It just arrived in two parallel versions: the legitimate one merchants have been racing to support, and a criminal one that's been scaling quietly for months.
Commerce has become the world's most targeted industry for AI-driven cybercrime—surpassing financial services and healthcare. The weapon deployed against retail is, functionally, the same technology being used to enable legitimate agentic shopping.
The Governance Vacuum
The most striking finding isn't about the attacks themselves. It's about how little retailers know about what's hitting their systems.
More than 90 percent of commerce organizations have placed AI bot activity in "monitor" mode rather than actively managing it. Approximately 75 percent of that traffic passes through retail systems with no restrictions. Only 22 percent of retailers can identify which of their APIs expose sensitive customer data. And 85 percent experienced at least one API-related security incident in the past year.
The implicit logic is understandable: blocking all AI bots risks cutting off legitimate shopping agents—Salesforce Shopper Agents, Google UCP crawlers, Gemini product indexers. Better to watch and wait. The problem is that passive monitoring can't distinguish a legitimate AI agent from a malicious one using the same behavioral signatures.
Three Techniques Defining Agentic Fraud
Signal masking is conceptually simple and operationally devastating. Malicious bots are programmed to replicate human browsing signatures—timing between page interactions, scroll depth, hover pauses before "add to cart." Traditional fraud detection identifies bots by what humans don't do. AI agents are specifically designed to do what humans do. In controlled research, prompt injection attacks on shopping agents achieved success rates between 41 and 86 percent depending on method and configuration.
Agent hijacking targets the new attack surface that agentic commerce infrastructure has created. As AI assistants increasingly hold stored payment credentials and standing purchase authority—through Visa's TAP, Adyen's Agentic suite, ACP and UCP integrations—compromising the agent means inheriting its payment authority. Threat actors are targeting agent-to-merchant communication channels to redirect purchases, trigger unauthorized refunds, or extract credentials without end-user knowledge.
Synthetic identity fraud—what the report calls "Frankenstein" accounts—uses LLMs to assemble fragments of real personal data into identities that pass static pattern-matching. A real name, a real address from a different person, a fabricated credit history. They look internally consistent because they were generated to be. They break only on ground-truth verification, which automated agentic checkout flows rarely perform.
The Numbers
Commerce absorbed approximately 3 trillion Layer 7 DDoS attacks in 2025, with retail accounting for 84 percent of volume. API attacks grew 9 percent year-over-year, with more than 200 billion web application and API attacks recorded across commerce targets over 14 months.
The phishing data is more alarming: between February and April 2026—just eight weeks—daily phishing volume targeting commerce customers more than doubled, rising from 56,600 to 134,600 per day. That's not a linear trend. Something structurally changed in early spring, likely the industrialization of AI-generated phishing campaigns at near-zero marginal cost.
The consequence in an agentic environment is worse than traditional e-commerce. Compromised credentials in 2020 gave attackers access to a stored card. Compromised credentials in 2026 give attackers access to an AI agent with standing purchase authority and potentially multi-merchant access through UCP or ACP integrations.
Pam Lindemoen, CSO at RH-ISAC, offered the sharpest summary: "Loyalty points are the new shadow currency." They sit in a regulatory and detection gap—not money, not tracked with card-level rigor, but increasingly convertible to real purchasing power. An agent routing reward accumulations to attacker-controlled accounts triggers no payment fraud signals. The theft is invisible until the consumer checks their balance.
Bot escalation is global but uneven. North America saw a 7 percent increase; EMEA +16 percent; APAC +63 percent; LATAM +48 percent. APAC's faster infrastructure rollout without equivalent security integration compounds risk precisely where growth is fastest.
The Infrastructure Gap
The industry spent the first half of 2026 building the rails for agentic commerce—protocols, authentication frameworks, verification registries, shopper agents at scale. The Akamai report documents what happens when that build-out proceeds without equivalent security investment.
The most actionable finding: only 35 percent of commerce organizations have implemented true microsegmentation across their API estate. 92 percent use basic network segmentation—which means a compromised checkout API can access loyalty account databases, customer profile stores, and stored credential vaults. That 57-point gap is the lateral movement opportunity that turns a single agent hijacking into a large-scale loss event.
The parallel to early mobile commerce is uncomfortable. When retailers deployed mobile checkout in 2010–2012, the security model borrowed from desktop failed badly for years before mobile-native authentication matured. Agentic commerce is deploying faster than mobile did, against adversaries also using AI, with a security model largely borrowed from API-based web commerce.
What to Do Before Holiday 2026
Four months to Q4. Attack campaigns are already scaling—the spring phishing acceleration confirms adversaries are running their own version of holiday readiness.
Map the full API estate first. Getting from 22 percent to near-100 percent clarity on which APIs expose sensitive data is the necessary prerequisite for everything else. Shadow APIs—deprecated endpoints still live in production—are the primary attack surface exploited in the current wave.
Shift from monitor to govern. With nearly half of all commerce traffic now AI-generated, passive monitoring is no longer a strategy. Intent-based bot categorization with graduated responses—not binary allow/block—is the required upgrade.
Close the microsegmentation gap. True microsegmentation limits blast radius when an agent hijacking or credential abuse incident occurs. This is the single most concrete security investment available before Q4.
Merge cybersecurity and fraud teams. Fraud teams know business logic and normal behavioral patterns; cybersecurity teams know attack vectors and anomaly detection. Agentic fraud operates at the intersection. Separate silos mean slower detection than adversaries require to execute.
The Dual-Use Reality
The Akamai report crystallizes the core challenge: agentic commerce and agentic fraud are built from the same toolkit. LLMs, autonomous agents, behavioral mimicry, API automation—these capabilities don't belong to either side. The difference between a legitimate AI shopping agent and a malicious one is intent, and intent isn't readable from traffic patterns alone.
Retailers who spent 2026 integrating Agentforce, going live on UCP or ACP, and optimizing product feeds for AI discovery now face a parallel obligation: ensuring the systems opened to legitimate agents aren't open by default to the criminal version. Patrick Sullivan, CTO of Security Strategy at Akamai, framed it as "agentic readiness"—not just the ability to transact with AI agents, but the ability to distinguish the ones worth trusting.
Sources
- Akamai Research: Commerce Becomes the Epicenter for AI Bot Attacks and Agentic Fraud in 2026 — GlobeNewswire, July 15, 2026
- Smash and Grab at Scale: Agentic AI Is Reshaping the Threat to Commerce — Akamai Blog
- APAC's AI-Powered Commerce Boom Fuels Surge in Bot and API Attacks — Intelligent CISO, July 16, 2026
- Prompt injection breaks today's AI agents, study warns — CSO Online
- Securing AI Agents: The Defining Cybersecurity Challenge of 2026 — Bessemer Venture Partners