Asia Pacific’s rapid adoption of AI-driven commerce is attracting a wave of automated cyberattacks, with bot activity targeting the region’s retail, travel and hospitality sectors surging 63% in 2025—the highest increase of any region globally.
According to Akamai’s latest State of the Internet (SOTI) security report, commerce accounted for 38% of all AI bot traffic observed across industries in APAC from July to December 2025, underscoring the growing intersection between innovation and exposure.
As businesses race to personalise shopping, booking and customer experiences using generative AI chatbots and agentic automation, they are also expanding the digital surface available to malicious actors.
The report, titled Securing the Agentic Storefront: Attacks on Commerce, highlights how legitimate automation is increasingly difficult to distinguish from credential stuffing, scraping and API abuse.
“APAC’s commerce sector is pivoting quickly toward a more automated and AI-enabled future, as businesses use GenAI chatbots and other AI-powered services to personalize experiences and reduce friction,” said Reuben Koh, director of security technology and strategy, APJ at Akamai.
“But every chatbot interaction, booking flow and loyalty program integration creates another new digital surface that must be discovered, understood and protected.” Reuben Koh
Travel and hospitality firms face heightened risk due to fragmented platforms, popular loyalty programmes and seasonal traffic peaks around regional holidays such as Lunar New Year, Golden Week and Diwali. APIs—critical for connecting payments, inventory, logistics and booking systems—are becoming primary attack vectors. In APAC, travel accounted for 22% of commerce web attacks, with APIs targeted in 25% of those incidents.
Layer 7 DDoS attacks against commerce businesses also rose 39% year-on-year, from 260 billion to 361 billion events in 2025. Among API-targeted Layer 7 DDoS attacks, retail represented 51%, followed by hospitality (28%) and travel (21%).
Akamai’s findings align with broader regional trends. CDNetworks’ 2026 WAAP report noted that AI is “industrialising” automated attacks, with over 15 billion malicious API requests blocked per month on average in 2025.
Similarly, Akamai’s 2026 API Security Impact Study for APAC found that 81% of organisations experienced an API security incident in the past 12 months, with AI-linked APIs now the most common attack vector in the region.
To build resilience, Akamai recommends that commerce organisations map their revenue chains to identify exposed APIs, govern automation using risk-based controls rather than blanket allow-or-block rules, and strengthen surge capacity ahead of peak traffic periods.
“As commerce organizations continue to embrace AI and automation, resilience must extend beyond a security function and become a business discipline,” Koh added.









