Bot Traffic Overtakes Human Traffic in 2024 as AI Agents and Scrapers Surge
The theory of a so-called dead internet has circulated since at least 2014, but recent data shows automated traffic is indeed overtaking human activity. Anti-detect browser company Aurorium examined traffic composition from 2013 onward and concluded that bots now hold a majority share in many segments.
Modern internet traffic consists of human users who create content and drive searches, plus bots divided into good, bad, and gray categories. Good bots include search engine crawlers, uptime monitors, news aggregators, and social media bots. Bad bots range from simple scripts to advanced tools that rotate fingerprints, use proxies, and mimic human mouse movements. Gray bots encompass AI agents and neural crawlers whose long-term value to webmasters remains unclear.
Imperva statistics illustrate the shift. Human traffic stood at 57 percent in 2013, dipped in 2014 due to good-bot indexing, then recovered through 2019 as smartphone adoption and 4G networks brought hundreds of millions of new users from Asia. From 2020 onward, pandemic-driven automation reversed the trend. By 2023 human traffic had fallen to 50.4 percent while malicious bots climbed to 32 percent.
The acceleration continued after generative AI tools lowered the barrier to creating scrapers. In 2024 human traffic dropped below 50 percent for the first time, reaching 49 percent against 51 percent automated. Latest figures show humans at 47 percent and bots at 53 percent, with the majority of bot activity classified as harmful scraping rather than beneficial indexing.
Additional sources align with these findings. Cloudflare reports that automated requests account for 37.5 percent of HTTP traffic, 87 percent of which originates from desktop environments. Akamai analyzed 6.9 billion requests and found 49.3 percent human, 42.1 percent bot-driven, and 65.3 percent of bot traffic tied to malicious scraping.
Within the bad-bot category, gray AI agents represent a fast-growing subset. AI crawlers comprise 85 percent of neural traffic while interactive AI agents account for 15 percent and are expanding at roughly 7 percent per year. These agents already compare prices, read documentation, and complete bookings with minimal human input.
Businesses bear an infrastructure tax from this traffic. A site that once handled 200 daily visitors may now serve 5,000, forcing upgrades to costlier hosting plans even though a large share of requests come from non-converting bots. For a digital property with 100 million monthly views and 30 percent bot traffic, annual server costs attributable to automation can exceed $19,000, excluding expenses for CAPTCHA services.
Site owners face difficult choices about blocking AI crawlers. Aggressive filtering risks losing legitimate mobile users sharing the same carrier-grade NAT addresses. At the same time, media organizations such as BBC and CNN that strictly limit AI access still achieve high citation rates in neural search results, suggesting that voluntary openness may not be required for visibility.
The cumulative data lends increasing weight to the dead-internet hypothesis. Human users are becoming a minority in the network they created, and recommendation systems trained on bot-generated patterns risk producing an increasingly synthetic information environment with no clear reversal in sight.
Related articles
Hashcat Password Cracking: Why Complex Passwords Like Summer2026! Often Fail First
Password cracking tools such as hashcat and John the Ripper exploit predictable human patterns when generating candidates, allowing structured passwords to be recovered faster than truly random strings. The process relies on comparing computed hashes against stored values without needing to reverse the one-way function. Modern password storage uses salted, computationally expensive algorithms including bcrypt, Argon2id, sha512crypt and yescrypt to increase the cost of each guess. Different formats require specific hashcat modes, and parameters such as cost factors or memory settings directly affect cracking speed. WordPress 6.8 introduced bcrypt with SHA-384 preprocessing while older phpass records remain supported. Audits must preserve full hash records, verify modes on test data, and combine dictionaries, rules, masks and statistical models to measure real risk. After testing, organizations should migrate to properly tuned Argon2id and enforce long unique passphrases managed by password managers.
Why HTTP to HTTPS Redirects Fall Short: Risks of Exposed Requests and the Role of HSTS Preload
A simple HTTP to HTTPS redirect satisfies basic audit requirements but leaves the initial request fully exposed in plaintext. The request carries the full path, query parameters, and cookies lacking the Secure flag, allowing observers on open Wi-Fi or compromised routers to read or tamper with traffic before TLS begins. Modern browsers such as Chrome since version 90 attempt HTTPS first, yet legacy clients, explicit http:// links in emails, scripts, and failed HTTPS fallbacks continue to send unprotected requests. HSTS instructs browsers to use HTTPS after the first successful visit, yet the header itself travels over HTTPS and cannot protect the very first connection from a new device or cleared cache. Preloading embeds the rule directly in the browser, eliminating the initial plaintext request entirely, but demands includeSubDomains and a one-year max-age, making the change effectively irreversible for months. The article recommends verifying Secure flags on all cookies, ensuring single-step redirects to the same host, and testing HSTS incrementally before considering preload.
OSINT for the Lazy Part 18: Extracting Value from Wayback Machine Archives for Bug Bounty and Security Research
The article explores passive reconnaissance techniques using web archive tools to uncover forgotten endpoints, configuration files, and sensitive parameters without directly interacting with target systems. It highlights three command-line utilities—waybackurls, gau, and waymore—that query public archives such as Wayback Machine, Common Crawl, AlienVault OTX, and URLScan to retrieve historical URLs. These tools help bug bounty hunters and penetration testers discover old API endpoints, admin panels, backup files, and JavaScript with hardcoded secrets that may still be exploitable. Installation instructions, usage examples, and filtering options are provided for each tool to maximize efficiency and reduce noise in results. The piece emphasizes that all methods remain fully passive, minimizing detection risk while requiring proper authorization before any active testing. Advanced users are advised to combine the tools for broader coverage and deeper analysis of archived responses.
OSINT Investigation Exposes Fraudulent Russian Garlic Investment Scheme Masquerading as Local Production
An in-depth OSINT probe into a Russian agricultural investment project promising 50-70% annual returns from garlic farming has revealed a likely import arbitrage operation sourcing produce from China and Uzbekistan. The project claimed ownership of over 300 hectares of fields, a proprietary seed fund, and guaranteed sales to major retailers including Magnit, Perekrestok, Pyaterochka, and Svetofor, yet public records show minimal profitability and heavy debt. Financial statements from linked cooperatives indicated just 2.2% net margin alongside loans exceeding annual revenue fourfold, pointing to reliance on continuous new investor capital. Registry checks confirmed no financial licenses, no seed-breeding status, and actual cultivated land far below advertised figures. Import declarations and equipment registrations further indicated the operation functions as a repackaging hub for foreign garlic sold under private labels. The parent group has been placed on the Bank of Russia blacklist, with related sites blocked by Roskomnadzor while Telegram channels continue aggressive marketing.