Q2 2025 Threat Report


Discover Q2 2025’s top bot attack trends — scraping, credential stuffing, and fraud tactics — with insights from Kasada’s threat intel team.

Q2 2025

The Bots That Hit Hardest in Q2

Bot attacks are draining profits and overwhelming defenses. The Q2 2025 Threat Report gives security and fraud teams a clear look at the adversaries and bot economy fueling it all.

Read the full Q2 2025 Threat Report

Attackers Start Simple, Then Escalate

55%

Basic Bots — low-skill, high-volume attacks that still overwhelm defenses.

31%

Mid-Level Bots — evasive, stealthier attacks using proxies and headless browsers.

13%

Advanced Bots — adaptive, human-like attacks designed to beat detection.

Three Critical Threats Emerged

Kasada's research identified three dominant attack vectors that are reshaping the cybersecurity landscape in 2025, including scraping, account takeover (ATO), and automated checkout.

AI Scrapers Flooded Sites

Over 120M AI scraper requests detected in Q2 — most from the OpenAI user agent, peaking at 950K/day. These tools bypass robots.txt to repurpose your content without consent.

Account Takeovers Soared

Retail, QSR, and webmail made up ~72% of stolen account sales in Q2. Airline ATO activity spiked 80%, while accommodation sector revenue soared 196%.

Hype Bots Fueled Markups

Bot-powered resale surged as 3,160 Labubu doll checkouts drove markups of +25% to +127% — fueled by just two cook groups.

Who's at Risk

Six key industries were most targeted by bots in Q2 — here's how attackers profited from each.

  • Retail

    Loyalty points & stored payment data targeted.

  • Airlines

    Frequent flyer accounts sold at scale.

  • Gaming

    Bots exploiting limited-release items.

  • Hospitality

    Premium hotel loyalty accounts in demand.

  • QSR

    Mobile order accounts as low-risk, high-volume targets.

  • Real Estate

    Listing data scraped for competitive advantage.

About the Data

Defeats threats 
not your customers

Start deploying today