I joined Arkose Labs six months ago because the company’s mission to make the digital world safe for everyone resonated with me. But at the time, I didn’t have a full appreciation for the threat landscape – its quick shifts, motivations behind attacks, and the disturbing downstream effects that jolt enterprises and traumatize consumers.
All of that crystallized when I had the opportunity to work on our latest quarterly report, “Breaking (Bad) Bots: Bot Abuse Analysis and other Fraud Benchmarks.”
This research is distinct from other published cyberattack reports in that it analyzes, over time, adversaries' execution of attacks using malicious bots and fraud farms. And the impact on enterprises is substantial. Our threat researchers observed a 121% increase in total attacks (from bots and fraud farms) in Q2 over Q1 2023 on our customer base, which is made up of the biggest B2C companies in the world.
The harm is downright disturbing for consumers. The latest FBI IC3 report shows U.S. consumers reported losing nearly $3 billion to online account-related schemes. (That figure is likely much larger if you add in unreported losses.)
I’ve concluded that today bots are the most dangerous, invasive species for enterprise websites and apps because much of the traffic enterprises experience isn’t even a real person. Just how alarming is the proliferation of these bots? Read on for some key report findings.
[resource_post_by_id id="31085"]
The Escalation of Bot Attacks
The sheer volume of bot risks can overwhelm enterprises’ defenses. The sophistication and velocity of bot attacks requires a highly performant and specialized defense strategy that many companies are still trying to figure out. And the disproportionate share of traffic from bots wastes resources and distorts sites’ revenue-generating activities and business metrics. To wit, malicious bot attacks escalated 167% in Q2 over Q1 2023. But not all bots are the same. We categorize bots into two different types:- Intelligent bots, which are capable of complex, context-aware interactions
- Basic bots, which are limited and perform simple, repetitive tasks
A Diverse Range of Threats
Adversaries use bots to perpetrate a wide variety of attack types, like fake account creations, website scraping, manipulation of account management/customer support, including password resets, and account takeovers, including credential stuffing. The Breaking (Bad) Bots analysis uncovered that most intelligent bots are used to conduct fake account creation attacks (68%), followed by scraping (16%). It also exposed the most attacked industries by bot-led incursions (% increase from Q1 to Q2):- travel and hospitality (1,515%)
- streaming media (334%)
- social media (216%)
- financial services (156%)
World-Class Bot Defense
A critical aspect of how enterprises can block bots, immediately and permanently, uses adversaries’ own weight against them. Here are a few ways that Arkose Labs blocks bots for some of the biggest companies in the world, leveraging the philosophy that by increasing adversaries’ effort-to-attack ratio, the bad actors will move to less-protected targets.- Proactive Defense: Enterprises detecting and mitigating attacks before they can wreak havoc have a competitive edge. By using passive authentication, like device intelligence and behavioral biometrics, enterprises detect and stop bots while creating a delightful experience for genuine consumers.
- Adaptive Response: Distinguishing suspicious traffic from legitimate user behavior requires finesse, not just crude blocking tools that throw the good out with the bad. Our approach is differentiated because of its dynamic interdiction that traps bots without sacrificing legitimate consumer experience. Our CAPTCHA challenges become progressively harder for suspicious and/or malicious traffic, while at the same time are easy for good consumers to solve, if consumers even see them in the first place. Every time an adversary fails to solve a CAPTCHA, their cost to attack increases.
- Actionable Data: We’re in the trenches daily with our customers. To help them tune their internal security models, we provide more than 125 risk signals to drive precise, transparent decisioning. This data is a valuable input to downstream risk and fraud prevention tools.
- Guaranteed Impact: Not only does Arkose Labs provide enterprises a 24/7/365 customer SOC and world-class care with industry-best service, as rated by G2, but also we back up the efficacy of our technology with industry-first warranties that add in an additional layer of confidence for companies working with us.



