Skip to content
Smash and Grab at Scale: Agentic AI Is Reshaping the Threat to Commerce

Smash and Grab at Scale: Agentic AI Is Reshaping the Threat to Commerce

Akamai • July 15, 2026

Agentic AI is transforming online commerce — and the threats faced by the industry. As interactions between brands and consumers become increasingly automated, distinguishing legitimate customer traffic from malicious exploitation is more complex — and more critical — than ever before.

In the three years since our State of the Internet (SOTI) Security report last examined the commerce sector, the rise of AI-driven shopping tools, autonomous agents, and agentic commerce has fundamentally transformed the environment — enhancing customer experiences on one hand and fueling an explosion in malicious activity on the other, from application-layer DDoS attacks to AI bots to sophisticated new phishing techniques.

We explore this critical trend in the new SOTI Security report, Securing the Agentic Storefront: Attacks on Commerce .

This report explores how this transformation has reshaped the threat landscape — and how commerce organizations can take steps to protect their digital storefronts.

The report begins with guest columns from two expert observers of commerce sector security:

The SOTI report is based on the latest analysis of commerce industry trends and is packed with critical findings, including:

Commerce remains the most heavily targeted industry for AI bot activity. We observed a 19% year-over-year increase in 2025, dominated by the retail vertical, and Akamai researchers expect this trend to continue.

While bots and web crawlers can be helpful by connecting customers to ecommerce sites, the ability of AI bots to imitate customer interactions creates the potential for abuse.

The data also indicates a surge in browser impersonators. These automated bots mimic legitimate web browsers in order to evade detection during scraping, enabling them to conduct fraud or DDoS attacks.

Having the ability to flag specific types of AI bots is crucial for determining their impact on website performance and their potential for malicious intent.

Sophisticated hacktivists are using bots to conduct multi-vector attacks on commerce. In one such case, a prominent Iran-aligned hacktivist group known as the 313 Team has been combining AI-assisted, Mirai-derived Internet of Things (IoT) botnets, browser impersonation, and complex DDoS attacks to target ecommerce APIs.

This heightens the need for enhanced mitigation techniques, including edge rate control and IP reputation checking, edge caching (where possible), and a robust bot management solution .

As commerce organizations deploy intelligent interfaces to streamline service and automate workflows, attackers are aggressively exploiting these systems in three ways:

Commerce organizations faced relentless attacks on both applications and APIs, with more than 200 billion attacks recorded between 2024 and 2025 — making it the most targeted industry during that period.

Attacks on APIs increased 9% year over year between Q4 2024 and Q4 2025, underscoring attackers’ shift toward APIs as preferred initial entry points.

The commerce industry’s inherently complex infrastructure — relying heavily on web applications, APIs, and third-party systems — creates an attack surface that is challenging to defend. The report delves into specific vulnerabilities, including the Jupiter X Core WordPress plug-in and the WooCommerce WordPress plug-in .

Our research reveals that commerce is the most targeted industry for Layer 7 DDoS activity. The sector experienced nearly three trillion DDoS attacks in 2025, with 31% of those targeting APIs; 84% of this DDoS activity targeted the retail vertical.

Retailers face elevated DDoS risks due to their massive ecommerce scale and surging financial stakes during peak shopping periods. Outages are frequently caused by DDoS attacks that flood APIs by using HTTP botnets to overwhelm app servers and block legitimate traffic.

This SOTI Security report also examines regional trends, finding that the Asia-Pacific region experienced the greatest increase in Layer 7 DDoS attacks: 39% between 2024 and 2025.

Cybercriminals are leveraging agentic AI to mount sophisticated attacks like supply chain poisoning. Other tactics include fake retail sites and spoofed login portals to harvest customer credentials.

To defend against these tactics, CISOs and SecOps teams must take a multidimensional approach to security.

The focus should be on resilience — and on building commerce environments that can absorb disruption, govern trusted automation, contain fraud, and maintain customer confidence under sustained pressure.

Download the new SOTI Security report: Securing the Agentic Storefront: Attacks on Commerce.

Extracted Entities

Domains (1)

Industries (1)

Malware (1)

Platforms (1)