2026 Bot Threats to the Marketing Stack: A Threat Map
Bots no longer just click ads. In 2026 they fill in lead forms, trigger conversion pixels, pump SMS verification codes, scrape pricing pages and route themselves through real home internet connections so they look like your best prospects. This threat map walks through the main bot threats to the marketing stack, layer by layer, using the latest research available as of May 2026, and ends with a prioritized checklist for auditing your own setup.
Why bot threats look different in 2026
The baseline has shifted. According to Thales's 2026 Bad Bot Report announcement, automated traffic made up more than 53% of all web traffic in 2025, up from 51% the year before, leaving humans at 47%. Help Net Security's summary of the same report breaks that down further: bad bots alone accounted for 40% of traffic, with benign automation at 13%.
The speed of change is the bigger story. Thales reports that daily AI-enabled bot attacks it blocked rose from 2 million to 25 million in a single year, a 12.5x increase. Tim Chang, Global VP and GM of Application Security at Thales, framed the problem this way: "The challenge is no longer identifying bots. It's understanding what the bot, agent, or automation is doing."
For marketers, that means the question is no longer "is some of my traffic fake?" It is "which parts of my stack are being fed fake signals, and what decisions am I making on top of them?"
Mapping bot threats to the marketing stack, layer by layer
Each layer of a typical marketing stack has its own failure mode. The damage compounds because the layers feed each other: a fake click becomes a fake session, a fake lead, a fake conversion and, eventually, a bad budget decision.
Paid clicks and invalid traffic
In Google Ads' definition of invalid traffic, invalid traffic (IVT) is traffic that doesn't represent genuine interest in your business, including bots, accidental clicks and fraudulent placements. Platforms filter some of it and issue credits where they detect it, but advertisers only see what the platform chooses to report.
The scale is large. Juniper Research's ad fraud study estimated that 22% of online ad spend, or $84 billion, was lost to fraud in 2023, and projected losses above $170 billion a year by 2028. More recently, DoubleVerify's May 2026 global study found connected TV (CTV) fraud schemes up 140% year over year, with fraud rates around 9% on unprotected campaigns versus under 1% on protected ones. One direct deal for a consumer healthcare brand saw 34% bot impressions. Direct deals do not guarantee clean traffic.
Lead forms and CRM
Form spam used to be obvious gibberish. Today's form bots submit plausible names, real-looking business emails and valid phone numbers, often copied from breached data. The cost shows up downstream: sales development reps chase ghosts, CRM records get polluted, and lead scoring models learn from junk.
Sign-up flows are a favorite target. Arkose Labs' Q4 2025 report found fake account creation represented 46% of all fraudulent activity it observed, and called sign-up flows the weakest security point across the nine industries it analyzed.
Analytics and attribution
Bots that run JavaScript fire your analytics tags exactly like a person would. According to Google's documentation on known bot exclusion, Google Analytics 4 automatically excludes known bots and spiders using Google research and the IAB's International Spiders and Bots List, but you cannot see how much was excluded, and the filter only covers bots that identify themselves or are already known. Everything else lands in your reports as engaged sessions, referral traffic or direct visits.
Akamai's November 2025 research on AI bots reported AI bot activity up 300% over the previous year and warned that billions of bot requests distort operational data. When attribution models assign credit to channels based on those sessions, you end up rewarding the channels that deliver the most bots.
Pixels and conversion APIs
This is the quietest threat on the map. Ad platforms optimize bidding toward the conversions you send them through browser pixels and server-side conversion APIs. If bots complete a form or a sign-up and that event is reported as a conversion, the algorithm learns that those "users" are valuable and goes looking for more of them.
The result is a feedback loop: poisoned optimization signals pull spend toward the placements, audiences and geographies where bots live. We cover how AI agents amplify this in our look at agentic AI risks for paid media.
Email and SMS sign-ups
Any form that sends a text message is a potential revenue source for fraudsters. Twilio's explainer on SMS pumping fraud describes how attackers abuse a phone number field to trigger one-time passcodes or download links to number ranges they profit from through revenue sharing with mobile operators. You pay for every message.
The trend is up. Arkose Labs reported a 67% surge in SMS toll fraud malicious traffic in Q3 2025, and a shift toward fewer but larger attacks, with average attack size in the gig economy up 300%. Email sign-up bombing follows the same logic at lower cost per message but higher cost to your sender reputation.
Ecommerce: scalping, credential stuffing and carding
Thales's 2026 Bad Bot Report overview names retail as the primary target for AI-driven bot activity, particularly where pricing is dynamic or inventory is limited. That covers scalping of limited drops, price scraping and inventory hoarding. Financial services still absorbs the most attacks overall, 24% of volume and 46% of account takeover (ATO) incidents.
For marketers, the pain is indirect but real. Credential stuffing drives account lockouts and support tickets, carding (testing stolen cards with small purchases) triggers chargebacks, and scalpers turn a successful launch campaign into a customer service problem.
Content scraping and AI crawlers
Your blog, pricing pages and product catalog are being read at scale. Cloudflare's 2025 Radar Year in Review found AI bots, excluding Googlebot, generated 4.2% of HTML requests, and that AI "user action" crawling, where assistants visit pages on behalf of a user, grew more than 15x in 2025. Not all of this is hostile, which is exactly why it needs to be classified rather than blanket-blocked. Our guide to good and bad agentic AI traffic explains how to tell the difference.
Why bots are harder to spot: residential proxies and AI solvers
Two shifts explain why classic defenses such as IP blocklists and CAPTCHAs are losing ground.
Residential proxies make bots look like households
Residential proxy networks route bot traffic through real consumer devices, so requests arrive from home broadband and mobile IP addresses rather than data centers. In January 2026, Google moved to disrupt IPIDEA, which The Hacker News described as one of the world's largest residential proxy networks. IPIDEA recruited devices through monetization SDKs embedded in third-party apps, "earn from your bandwidth" apps and malware preinstalled on off-brand Android TV boxes, and more than 550 threat groups used it.
The same device supply chain feeds ad fraud directly. HUMAN's BADBOX 2.0 disclosure from March 2025 described more than a million infected off-brand devices used for programmatic ad fraud, click fraud, residential proxy services and fake account creation. Thales now notes that IP reputation and user-agent checks alone are insufficient, because attackers pair residential IPs with legitimate browser fingerprints.
AI bots solve CAPTCHAs
Researchers at ETH Zurich showed in their paper Breaking reCAPTCHAv2 that fine-tuned object detection models could solve 100% of reCAPTCHAv2 image challenges, compared with 68% to 71% in earlier work. They also found the system leans heavily on cookies and browsing history to decide who is human. A CAPTCHA adds friction for real prospects while doing less and less to stop determined bots.
Audit your stack: a prioritized checklist
Start with the layers where bad data costs you money directly, then work outward. A practical order:
- Check which conversions you send to ad platforms. List every pixel and conversion API event. Stop sending raw form submits as optimization events if you cannot verify they come from real people; send qualified or verified events instead.
- Lock down SMS and OTP endpoints. Restrict destination countries to the markets you actually serve, rate-limit sends per session and number, and review your provider's fraud guard settings, as Twilio's toll fraud prevention guide recommends.
- Measure invalid traffic by channel and campaign. Compare sessions, form fills and qualified leads per source. A channel with high volume and near-zero downstream quality is a red flag.
- Classify residential proxy and out-of-geo traffic. Traffic from consumer IPs outside your target markets, or from known proxy ranges, deserves separate reporting before it reaches your attribution model.
- Clean the CRM. Tag leads by traffic quality at capture time, suppress obvious fakes from nurture and scoring, and give sales a way to flag junk back to marketing.
- Review placements and direct deals. Pull placement reports, exclude outliers and ask partners for IVT reporting, including on CTV and direct buys.
- Decide your AI crawler policy. Separate search, AI training and user-action agents, then choose what to allow, limit or block per section of the site.
- Retire CAPTCHA as your only gate. Layer behavioral and network signals so real visitors are not punished for bots' behavior.
Where Ðeny fits
Ðeny is built for the marketing side of this problem. Ðeny Bot Shield classifies and blocks traffic in real time from a one-line script. The Ðeny Intelligence Hub sorts visitors into Clean, Good Bot, Residential Proxy, IVT, Out-of-Geo and AI Agent, gives each site a Traffic Health Score from A to F with AI summaries, and shows a UTM Breakdown so you can see which channels deliver real people. Attribution & History stitches sessions across devices, and persistent UTM attribution keeps source data attached to leads. You can explore each of these on the Ðeny features overview.
Conclusion
In 2026, bots touch every layer of the marketing stack, and the layers amplify each other. Fake clicks become fake leads, fake leads become training data for bidding algorithms, and residential proxies plus AI-driven solvers make the whole chain harder to see. The fix starts with visibility: know what share of each channel is real before you optimize anything.
If you want to see how your own traffic breaks down by channel, request a Ðeny demo and we will walk through it with you.
Start protecting your funnel today
Put Ðeny to work from day one, and your boss will thank you.

