Automation isn’t slowing down

16%

increase in account sales since Q2, demonstrating the rising profitability of account takeover (ATO).

$275k

a month was earned by a single reseller group, proving that botting isn’t just a hobby, it’s an organized business.

56%

of all events were “basic attacks,” yet their scale and speed still overwhelm traditional defenses. .

A new wave of attacks

Traditional defenses can’t keep up. Kasada’s analysts tracked a surge of automation driven by AI, proxy networks, and human ingenuity, revealing just how adaptable today’s adversaries have become.

A new wave of attacks

Traditional defenses can’t keep up. Kasada’s analysts tracked a surge of automation driven by AI, proxy networks, and human ingenuity, revealing just how adaptable today’s adversaries have become.

Account Takeover Goes Underground

Kasada found marketplaces selling accounts tied to gun retailers and background-check services. With sales up 16% in Q3, ATO is shifting from mass theft to targeted, high-value attacks.

“Legal” Botnets Blur the Line

Proxy networks like DSLRoot pay users to share bandwidth, turning homes into attack infrastructure and hiding malicious traffic behind real IPs.

AI Joins the Adversary Arsenal

Attackers now use AI to analyze data and automate phishing and credential theft. It’s rewriting the rules, forcing defenders to rethink how they detect and respond.

Account Takeover Goes Underground

Kasada found marketplaces selling accounts tied to gun retailers and background-check services. With sales up 16% in Q3, ATO is shifting from mass theft to targeted, high-value attacks.

Online Reselling: Not “If,” but “When”

As more businesses adopt scarcity tactics for sales and product drops, they inevitably attract aggressive resellers. The consequences of online reselling are strategic, hurting businesses long after the initial transaction.

AI Joins the Adversary Arsenal

Attackers now use AI to analyze data and automate phishing and credential theft. It’s rewriting the rules, forcing defenders to rethink how they detect and respond.

From our analysts –
Insights from the front lines

“In Q3, adversaries continued to show a clear preference for proven methods. The infostealer ecosystem remains resilient, with infrastructure disruptions proving only temporary setbacks for well-established operations. The continued proliferation of infostealers highlights that credentials remain a highly profitable and accessible target for cybercriminals.”

Kasada IQ Analyst

“Proxy and hosting providers now enable threat actors through deceptive business tactics that keep them online after takedowns. Their resilience underscores why defenders need to go beyond defensive monitoring and engage in proactive, bespoke defenses.”

Kasada IQ Analyst

About the Data

KasadaIQ provides an inside view into the adversary ecosystem — analyzing millions of automated interactions each quarter across 2,000+ collection points and 23M+ messages from open and closed sources. This intelligence informs our defenses and helps enterprises stay ahead of evolving threats.

Learn more about KasadaIQ

More reports from Kasada

  • pages of Kasada's Q2 2025 Threat report with a button to download to read the report

    Q2 2025 Threat Report

    Discover Q2 2025’s top bot attack trends — scraping, credential stuffing, and fraud tactics — with insights from Kasada’s threat intel team.

  • Midnight blue background with title text "Q1 2025 Threat Report" with an image of Kasada's new Threat Report.

    Q1 2025 Quarterly Threat Report

    Automated threats are growing smarter, faster, and more difficult to detect. Kasada’s Quarterly Threat Report reveals what to watch for and what to do next – powered by millions of real-time signals analyzed through KasadaIQ.

  • Kasada - Account Takeover Attack Trends 2025 - 1200x628 - 1.1 (Animated)

    2025 Account Takeover Attack Trends

    Uncover exclusive insights from Kasada’s infiltration of 22 credential stuffing groups. Dive into the data, emerging trends, and actionable strategies to safeguard your login endpoints in 2025.

Stay ahead of bots

Get access to our monthly intel brief with fresh data, attack trends, and analysis.