New Akamai research shows commerce made up 38 percent of APAC’s AI bot traffic last year, with travel and hospitality bearing extra exposure.
Australian small business owners have spent the past couple of years leaning into AI, chatbots that answer customer questions at midnight, booking engines that personalise a stay before a guest even checks in, loyalty apps that remember what someone ordered last time. It’s been good for conversions. It’s also been good for the people trying to break in.
Bot traffic up 63pct
New research from cybersecurity firm Akamai, published in its State of the Internet report Securing the Agentic Storefront: Attacks on Commerce, found bot activity targeting commerce companies across Asia Pacific rose 63 percent in 2025, the largest increase recorded in any region worldwide. Between July and December 2025 alone, commerce accounted for 38 percent of all AI bot traffic Akamai observed across every industry it tracks in the region.
The report points to a specific cause: retailers across APAC are shifting toward what the industry calls “agentic commerce”, using bots to personalise shopping experiences and cut down on abandoned carts. That shift is real and it’s working. The problem is that the same automation that makes a storefront feel smart also makes it harder to tell a genuine customer-service bot from a scraper, a credential-stuffing attempt, or an API being quietly abused.
“APAC’s commerce sector is pivoting quickly toward a more automated and AI-enabled future, as businesses use GenAI chatbots and other AI-powered services to personalise experiences and reduce friction,” said Reuben Koh, Director of Security Technology and Strategy, APJ at Akamai. “But every chatbot interaction, booking flow and loyalty program integration creates another new digital surface that must be discovered, understood and protected. This is especially important in APAC, where travel and hospitality face heightened exposure from fragmented platforms, popular loyalty programs and seasonal traffic surges. Businesses must now implement risk-based defences that are capable of identifying malicious intent hidden within high-volume, legitimate automation, without adding friction to the customer.”
Travel and hospitality exposed
Retail remains the biggest target overall, but Akamai found travel and hospitality businesses in APAC copped disproportionately more exposure than their counterparts in other regions. The report puts that down to fragmented booking platforms, high mobile adoption, popular loyalty schemes, and seasonal spikes around regional holidays like Lunar New Year and Golden Week, the local equivalent of Boxing Day sales hitting several times a year.
Travel accounted for 22 percent of all commerce web attacks in the region, and APIs, the behind-the-scenes connections linking payments, loyalty points, inventory and booking systems, were targeted in a quarter of the attacks against travel businesses specifically. Application-layer DDoS attacks, the kind that flood a site or app until it buckles, rose 39 percent across APAC commerce in 2025, climbing from 260 billion to 361 billion recorded events. Of the API-targeted DDoS attacks, retail copped 51 percent, hospitality 28 percent, and travel 21 percent.
The local picture
Akamai’s figures are regional, not Australia-specific, so it’s worth putting them next to what’s actually being reported here. The Australian Signals Directorate’s Annual Cyber Threat Report 2024–25 found small businesses paid an average of $56,600 per cybercrime report last financial year, up 14 percent on the year before. Medium businesses fared worse, with average losses jumping 55 percent to $97,200.
The same report draws on the Australian Institute of Criminology’s 2024 Cybercrime Survey, which found SME owners experience significantly higher rates of cybercrime than other victims, and when they’re hit, they tend to lose more money than most. Twenty two percent of SME owners surveyed said their business had been affected by cybercrime in 2024. Denial-of-service incidents reported to the ACSC also jumped more than 280 percent over the year, a trend that lines up closely with what Akamai is seeing on the commerce side specifically.
None of this means every SME chatbot is under siege. It does mean the attack surface most small operators are building, often through third-party plugins, booking widgets and payment integrations, is exactly the kind of surface both Akamai and ASD are flagging as increasingly exposed. Dynamic Business recently reported that AI-driven fraud is rising sharply in Australia too, with scam losses up 28 percent in the first four months of 2025 alone.
What SMEs can do
Akamai’s advice isn’t really about locking everything down, it’s about knowing what needs protecting in the first place. The report recommends three things businesses of any size can start with:
Map the revenue chain. Know which APIs handle payments, loyalty points, checkout, inventory and partner integrations, and understand where customer data might be exposed along the way.
Stop treating automation as all-or-nothing. Move away from blunt “allow everything” or “block everything” settings and toward tools that can tell the difference between a legitimate customer bot and a malicious one.
Plan for peak periods. Before a big sale, a holiday rush or a seasonal booking surge, stress-test your systems, watch for fake versions of your storefront, and make sure whoever handles your cybersecurity and fraud response are talking to each other, not working in separate silos.
For a small or medium operator without a dedicated IT security team, that can sound like a lot. It doesn’t have to be tackled all at once. Dynamic Business’s recent rundown of the cybersecurity threats businesses face in 2026 is a reasonable place to start figuring out which of these actually apply to your setup first.
Akamai’s report is now in its 12th year and draws on attack data collected across its own global security infrastructure, which the company says handles a significant share of the world’s web traffic.
Read the full report here.
Keep up to date with our stories on LinkedIn, Twitter, Facebook and Instagram.
