We used to know exactly what an automated threat looked like in ecommerce. It was a bot attack: Repetitive, clumsy and following a fixed script. But as AI agents become mainstream, figuring out what to block and what to approve is getting harder.
With the right tools and strategies, you can tell the difference between legitimate automation and a traditional bot or AI agent being used for fraud — and protect revenue without turning away good customers. Let’s dig in.
TL;DR
- Traditional bots follow fixed scripts to complete a single defined task. AI agents pursue broader goals, reasoning through context and adjusting actions as conditions shift.
- Fraudsters now use AI tooling to run attacks that are 4.5 times more profitable (Source: Interpol), pushing North American fraud pressure up 33% in early 2026 versus 2025 (Source: Signifyd data).
- Common bot attacks include price scraping, inventory hoarding, credential stuffing and checkout abuse, including probing discounts or gift cards, at scale.
- AI agents made by bad actors can vary transaction amounts, device signals and timing based on prior outcomes, so fraud attempts avoid the repetitive fingerprints typical of bot attacks.
- Signifyd data found that AI-driven card-testing incidents jumped 175% between Jan. — April 2026 compared to the same stretch in 2025.
- A 2026 LexisNexis study found that every dollar retailers lose directly to fraud actually costs U.S. retailers about $5.13 once chargebacks, operations costs and product losses included.
- To combat automated threats in ecommerce, merchants should combine infrastructure-level bot filtering with AI-driven decisioning that weighs identity, device, payment and behavior signals together across the full customer journey.
The state of automated threats in 2026
Automation has long played a legitimate role in ecommerce, from order-status bots and stock alerts to fraud screening and customer support. What’s changing is the level of autonomy involved. Shoppers are handing more shopping tasks to AI agents that can compare products, make decisions and act on their behalf.
Fraudsters are using the same advances to make attacks more adaptive, convincing and 4.5 times more lucrative than conventional ones. And it shows: AI-assisted techniques increased North American fraud pressure 33% from Jan. – April 2026 compared with the same period in 2025, according to Signifyd’s 2026 State of Fraud report.
To reverse this trend — without blocking legitimate AI shopping assistants on accident — brands like yours need a framework for what you’re actually dealing with. It starts with separating traditional bots from modern AI.
Bots vs. AI agents in ecommerce at a glance
The central difference is autonomy: Traditional bots execute predefined tasks, while AI agents work toward broader goals.
| Traditional bots | AI agents | |
|---|---|---|
| Primary function | Execute a predefined task | Pursue a broader goal |
| Decision-making | Match inputs to fixed rules and repeat until conditions change | Interpret context, weigh options and adjust based on outcomes |
| Behavior over time | Repetitive and predictable — may repeat, fail or stop when conditions change | Variable and context-aware — adjusts based on changing conditions and outcomes |
| Ecommerce use cases | Order-status chatbots, shipping alerts, stock notifications and ticket routing | Shopping assistance, customer service, merchandising, fraud operations and post-purchase support |
| Fraud threats | Price scraping, inventory hoarding, credential stuffing and checkout abuse | Adaptive account takeover fraud, synthetic identity fraud, card testing, promo abuse and post-purchase fraud |
What is a bot?
In ecommerce, a bot is automated software designed to complete a predefined task by following programmed instructions.

What are examples of helpful bots?
Rule-based chatbots are one of the most familiar examples. They answer common questions when the request matches a predefined workflow.
A chatbot may be able to answer “Where’s my order?” by retrieving tracking information. But if the customer asks for a discount because the order arrived seven days late, the bot may not have a programmed response. Instead, they may route the request to a human or hit a dead end.
Bots can also send shipping updates, trigger stock alerts and route support tickets based on keywords or other predefined conditions.
What are common bot attacks in ecommerce?
Fraudsters use bots to automate repetitive attacks at a volume and speed that would be difficult to achieve manually.
- Price scraping bots crawl product pages at high volume to harvest pricing data for competitor tools, resellers or marketplaces. They can inflate traffic numbers without contributing genuine purchase intent.
- Inventory bots target limited-availability products — like drops and event tickets — and attempt to buy or reserve inventory immediately.
- Credential stuffing bots test stolen username and password combinations against login pages. Once fraudsters gain access, they may target loyalty points, gift cards, stored payment methods and saved addresses.
- Checkout abuse bots probe discount fields, test gift card balances and exploit promotional logic at scale. They may also use repeated low-value transactions to identify valid stolen payment credentials.
What is an AI agent?
In ecommerce, an AI agent is software that interprets goals, reasons through next steps and takes action across a workflow. It can adjust its approach as conditions change.

What are some helpful AI agent examples?
Common use cases include:
- Shopping assistant agents compare products by size, price, reviews, availability and delivery speed before recommending or, when authorized, purchasing an item.
- Customer experience agents answer questions, retrieve account or order information, make permitted changes and route more complex cases.
- Merchandising agents analyze product performance, inventory and demand to recommend promotions, restocking or markdowns.
- Fraud operations agents evaluate account, identity, device, payment and behavioral signals to support fraud decisions.
- Post-purchase agents handle tracking, delivery issues, returns, exchanges, refunds and warranty claims.
How are AI agents used for fraud?
Fraudsters can use AI agents to make familiar ecommerce attacks more adaptive. Fraud markets already offer stolen credentials, payment-card lists, device-spoofing services and synthetic identity kits. Agentic tooling adds a reasoning layer, allowing attacks to change timing, device attributes, transaction details or claims based on previous outcomes.
Emerging and potential uses include:
- Card-testing attacks: An agent could change transaction amounts, cards or merchant combinations based on which attempts are approved or declined. Signifyd data shows AI-driven card-testing attacks increased 175% from January through April 2026 compared with the same period in 2025.
- Account takeover: An agent could test compromised credentials at scale while varying login timing, device signals and behavior to avoid producing the repetitive patterns associated with traditional credential stuffing.
- Synthetic identity fraud: An agent could spin up and manage fake customer profiles, varying account activity before attempting higher-value fraud.
- Promo and loyalty abuse: An agent could identify and exploit combinations of promo codes, referral offers or loyalty rewards across multiple accounts.
- Post-purchase abuse: An agent could generate fabricated damage photos, doctored receipts or false refund claims, then adjust the story and evidence based on what receives approval.
Are AI agents harder than bots to detect for fraud?
Yes, in many cases. Traditional bot traffic often has recognizable signatures: High-volume requests, repeated actions, thin device fingerprints, suspicious IP clustering and unnatural request timing.
A legitimate shopping agent can compare products quickly, visit fewer pages and complete a purchase with less exploration than a human customer. Those behaviors may trigger controls designed to treat speed and automation as signs of fraud.
Fraudulent agents create the opposite problem. An agent can adjust its timing, rotate device signals or change transaction details based on what gets declined. Instead of producing the repetitive, uniform pattern associated with a traditional bot attack, each attempt may be slightly different — and each failure can inform the next one.
That creates two risks for ecommerce merchants:
- Legitimate agent-assisted purchases may be declined because the system treats efficiency as a red flag
- Fraudulent activity may slip through because it appears less repetitive and more human than a standard bot attack
The costs of misreading automated traffic
- False declines reduce immediate revenue and lifetime value: Signifyd research shows 27% of wrongly turned-away customers never return.
- Fraud carries broader costs: A 2026 LexisNexis study estimates approximately $5.13 total cost to U.S. retail and ecommerce businesses per $1 of direct fraud loss.
Example: For a merchant processing 15,000 monthly orders at a $60 average order value, a 0.5% false-decline rate would reject 75 legitimate orders and cost $4,500 in immediate revenue each month, or $54,000 annually. Based on the 27% figure, roughly 20 of those customers may never return.
If that same merchant incurs $2,250 (.25%) in direct fraud losses each month, the total cost could reach approximately $11,543 after chargebacks, operational expenses and other associated costs are included. Over a year, that amounts to roughly $138,510 in total fraud-related losses.
How can ecommerce brands protect against malicious automation?
Malicious automation requires an automated defense: Infrastructure-level bot controls, AI-powered decisioning and enough context to distinguish high-risk activity from legitimate customers and authorized shopping agents.
Filter obvious automation at the infrastructure layer
- Use rate limiting, web application firewall rules, device and browser fingerprinting and CDN-level bot management — calibrated to attack-scale behavior — to stop high-volume scraping, credential stuffing and other obvious automated attacks.
How Signifyd helps: Signifyd’s Commerce Protection Platform evaluates device, IP, behavioral, account and transaction signals once activity reaches the login or order flow.
Evaluate connected signals
- Avoid making decisions based on one behavior, like session speed, a new device or an address change.
- Evaluate identity, account, device, payment, behavioral and order signals together to identify trusted activity as accurately as you identify fraud.
How Signifyd helps: Signifyd’s AI-powered decisioning evaluates these signals together and compares them with patterns observed across merchants in the Signifyd Commerce Network, helping distinguish legitimate activity from meaningful fraud risk.
Verify account control and authorization
- Look beyond valid credentials and familiar payment information.
- Review recent password resets, new devices, changed shipping details, unusual order values and other signs that control of the account may have shifted.
How Signifyd helps: Signifyd connects account-access activity with downstream transaction behavior, helping you identify when someone is using trusted credentials in ways that don’t match the customer’s established history.
Extend fraud protection across the end-to-end customer journey
- Connect fraud controls across account creation and login, checkout, fulfillment, chargebacks, returns and refunds.
- Evaluate new activity using what’s already known about the customer, account and original transaction.
How Signifyd helps: The Commerce Protection Platform includes Account Protection, Guaranteed Fraud Protection and post-purchase solutions like Returns Insights and Instant Refunds.
Watch for adaptive patterns
- Look for low-and-slow probing, small changes after failed attempts and combinations of activity that don’t individually trigger a rule.
- Review confirmed fraud, chargebacks, approved orders and identified false declines regularly. Use those outcomes to update thresholds, rules and model-performance reviews.
How Signifyd helps: Signifyd uses link analysis and Commerce Network intelligence to connect activity across transactions, accounts and identities, helping you identify adaptive fraud even when individual attempts appear unrelated.
Measure whether your controls are blocking good activity
- Track your ecommerce false decline rate alongside approval rate, chargeback rate and manual review rate.
- Review declined-order samples, successful retries and customer complaints to identify legitimate activity that your fraud controls misclassified.
- Use those findings to adjust rules, thresholds and review workflows while preserving controls against malicious automation.
- Give affected customers a clear recovery path, like rapid escalation, secure reverification or instructions for resubmitting the order.
How Signifyd helps: Signifyd evaluates more than 1,000 features and thousands of underlying data elements to reduce reliance on blunt rules and isolated signals. Guaranteed Fraud Protection also shifts liability for approved fraudulent orders to Signifyd, allowing merchants to approve more legitimate orders without taking on more fraud risk.
Get ahead of malicious automation
Bots and AI agents will keep showing up in your traffic, your login flow and your checkout. And, increasingly, so will the fraud that hides inside both. The merchants who protect revenue best won’t be the ones blocking all automation; they’ll be the ones with the context to tell bad bots from good bots and legitimate agents from fraudulent ones, order by order.
See the full picture of how AI is reshaping ecommerce fraud — read Signifyd’s 2026 State of Fraud Report for the complete data, regional breakdowns and case studies.