Analysis of the HUMAN Enterprise Bot Fraud Benchmark Report 2023 ↗ for advertisers who are tired of paying for thin air.
When bots became smarter than people
In the world of digital marketing, there is an unspoken axiom: the advertising budget is a sacred cow that must be milked carefully and wisely. But what if, right now, while you are reading this text, tens of thousands of automated scripts are methodically and relentlessly draining your advertising budget, imitating the actions of live users with such precision that even advanced analytics systems cannot distinguish a human from a machine?
The answer to this question is provided by HUMAN Enterprise Bot Fraud Benchmark Report 2023, whose platform verifies the human nature of more than 20 trillion digital interactions every week and has collected data capable of causing cold sweat even in the most hardened marketers.
Bots today are not the primitive click farms of the past decade. They are high-tech software systems that imitate human behavior, rotate IP addresses, and hide among legitimate users to remain unnoticed. Many modern botnets are created through malware delivery, turning the devices of unsuspecting users into relays for automated attacks on businesses.
One bad bot can cause trouble, but a million bad bots deployed through a sophisticated botnet can wreak real chaos and cause material damage. And this damage, as the report shows, is growing rapidly.
Key numbers that change the game
Before we dive into the detailed analysis, here is the year-over-year dynamics that should force you to immediately rethink your protection approaches.
People are leaving the internet, and bots are coming into it with redoubled force. Advertisers pay more and more for impressions and clicks, while there are fewer real people behind the screens. A paradox? No, a systemic problem.
Overall traffic dynamics: when less is not better
The HUMAN report shows that overall web traffic in 2022 decreased significantly compared to the peak pandemic year of 2021. People returned to the offline world, and that is natural. However, bot traffic patterns show a completely different dynamic.
If legitimate traffic declined, malicious bot traffic grew by 102%. Even when people spent less time online, bad bots continued to attack digital organizations in even greater numbers. This means that the share of bots in total traffic did not just persist—it grew dramatically. If before we could console ourselves with the thought that «bots are just noise,» now this «noise» has become the dominant part of the orchestra. And it is not playing in your favor.
Attack seasonality: why October is scarier than Friday the 13th
One of the most alarming findings of the report concerns the seasonality of bot attacks. It was traditionally believed that the peak of fraudulent activity occurs on Black Friday and Cyber Monday—days when advertising budgets are inflated to the skies and conversions should break records. The reality turned out to be far more cynical.
Peak bot attack day in 2022: October 25. On that day, malicious traffic was 199% above the annual average. And this is no coincidence.
«The holiday shopping season, as expected, remained a period of high bot traffic, but attacks actually peaked in October, long before traditional sales such as Black Friday and Cyber Monday. This is because cybercriminals launch automated carding and credential-stuffing attacks to test usernames, passwords, and card numbers ahead of major sales. Thus, they can be ready with verified accounts and credit cards to commit fraud on the busiest sales days.»
— Gil Bar Yaakov, data security researcher at HUMAN
In other words, fraudsters prepare for your holiday in advance. They test stolen data in October so that in November they can freely empty your advertising budgets and your customers' wallets.
Another interesting fact: Thursday is the most active day for bot attacks. Thursdays show 22% more malicious traffic than Sundays—the most «bot-free» days. Cybercriminals also have their working days and weekends.
Geography of evil and attacking devices
Almost 70% of the world's malicious traffic «originates» from the US. But the report's authors make an important caveat: cybercriminals almost always use proxy servers. When we look at traffic to applications outside the US, the share of American traffic drops below 50%. And when it comes to applications inside the US, it rises to 75%.
Attackers use American proxy servers when they want to attack American targets, and vice versa. Geographic filtering by IP addresses has long ceased to be an effective method of protection.
As for devices, the lion's share of automated attacks occurs on desktop. Liel Strauch, director of cybersecurity at HUMAN, explains this by the fact that web architecture on desktop is simpler for attackers to understand, and device attributes are easier to fake. This is especially important for ad fraud, where bots need to interact with complex JavaScript chains linking sites to monetization partners. Protecting desktop traffic should be an absolute priority.
Three main threats: ATO, carding, and scraping
Account takeover (ATO)
Attackers gain access to accounts through stolen data. This allows them to make fraudulent purchases, steal bonus points, write fake reviews, and send spam. On average, 48% of all login attempts were malicious. Every second login on your site could be an attack.
Carding
Bots test stolen credit cards by making small purchases. Verified cards are used for expensive purchases or gift cards, which are then resold. Fraudulent purchase attempts accounted for 11% of all attempts. Every ninth checkout could be fake.
Data scraping
Bots continuously scan websites to capture prices, content, and inventory data. Competitors use this to gain an advantage, and republished stolen content critically hits the SEO ranking of the original site.
Lifecycle of a digital attack
Attackers do not just attack chaotically—they go through stages where one attack feeds another. Malicious bots participate in 77% of all digital attacks. Point protection no longer works.
1. Preparation
PII leaks, digital skimming, malware, phishing, data collection, web scraping.
2. Testing
Brute force, credential stuffing, carding, gift card cracking.
3. Execution
Account takeover, fake account creation, inventory hoarding, scalping.
4. Exploitation
Account abuse, PII theft, promo abuse, fraud.
What to do?
The HUMAN report offers practical recommendations. End-to-end protection must be implemented throughout the entire user journey.
Basic hygiene measures
- Strong passwords and HTTPS
- Regular software updates and vulnerability scanning
- Proper access controls
- Implementing CSP and CORS policies
Specialized protection
- Rate limiting
- Intelligent fingerprinting
- Real-time behavioral analysis
- Advanced machine learning algorithms
In addition, it is necessary to constantly increase the cost of attacks for fraudsters (computational tasks, honeypots, deceptive content) and perform continuous monitoring of the client side and user activity after login.
Why HaltClick is not just another antibot
In a world where bots are getting smarter, advertisers need protection that works ahead of the curve. HaltClick is a specialized solution built on understanding the mechanisms described in the HUMAN report.
We know that standard methods—IP blocking and simple captchas—no longer work against bots that imitate humans. That's why we offer comprehensive protection:
- Analyzes the behavior of each user in real time.
- Uses machine learning to identify the most sophisticated bots.
- Protects against threats: scraping (or parsing—the process of automatically extracting data from websites using bots or scripts) and click fraud in Direct and Google Ads.
- Does not create barriers for real users (no annoying captchas).
Time to act
The HUMAN Enterprise Bot Fraud Benchmark Report 2023 is not just a set of numbers. It is a warning, a wake-up call that should rouse every advertiser.
The world has changed. Bots are no longer «just noise.» They are an organized, technologically equipped threat that daily drains billions of dollars from advertising budgets around the world. The question is no longer «should you protect yourself?» The question is «how quickly will you start protecting yourself?».
Every day without protection is money going to fraudsters, data leaking to competitors, and a reputation being destroyed under bot attacks. HaltClick offers not just «another antibot,» but a comprehensive system built on understanding real threats.
In a world where 48% of logins are attacks and 11% of purchases are fraud, protection is not an option—it is a necessity.