As retailers, hospitality brands and other sectors across Asia-Pacific (APAC) increase their use of AI-powered shopping, booking and customer experiences, they are becoming a bigger target for bot and cybercrime.
According to Akamai’s latest State of the Internet (SOTI) security report bot activity targeting APAC commerce companies rose by 63 per cent in 2025, which was the highest increase seen by any region around the world.
“APAC’s commerce sector is pivoting quickly toward a more automated and AI-enabled future, as businesses use GenAI chatbots and other AI-powered services to personalise experiences and reduce friction,” said Reuben Koh, Director of Security Technology and Strategy, APJ at Akamai.
“But every chatbot interaction, booking flow and loyalty program integration creates another new digital surface that must be discovered, understood and protected. This is especially important in APAC, where travel and hospitality face heightened exposure from fragmented platforms, popular loyalty programs and seasonal traffic surges.
“Businesses must now implement risk-based defences that are capable of identifying malicious intent hidden within high-volume, legitimate automation, without adding friction to the customer.”
Akamai said that retailers across the region are increasingly using AI-powered bots to personalise shopping experiences and reduce cart abandonment.
Chatbot adoption is growing particularly quickly across APAC as businesses seek to offer more tailored customer service. However, the trend is also making it more difficult to distinguish legitimate automated activity from malicious practices such as data scraping, credential stuffing and API abuse.
As the growth of AI and automation increases in commerce organisations, Akamai says resilience must extend beyond a security function and become a business discipline. This includes:
- Mapping the revenue chain: Continuously identify the APIs that support payments, loyalty programs, checkout, inventory and partner integrations, and understand where sensitive data may be exposed.
- Governing automation by risk: Move beyond blanket ‘allow’ or ‘block’ decisions and adopt a risk-based approach that can distinguish legitimate automation from malicious bot activity.
- Preparing for peak traffic periods: Strengthen surge capacity, test DDoS response plans, monitor for fake storefronts and credential exposure, and bring cybersecurity and fraud teams closer together ahead of major shopping and travel peaks.
Akamai’s SOTI report also stated that while retail remains the main target for cybercrime, travel and hospitality businesses in APAC were more exposed to cyber threats than those in other regions. This was driven by fragmented travel platforms, high levels of digital and mobile adoption, widely used loyalty programs and booking peaks around holidays such as Lunar New Year, Golden Week and Diwali.
Now in its 12th year, Akamai’s SOTI security reports draw on attack data observed across Akamai’s cybersecurity protective infrastructure, which handles a significant portion of global web traffic.
Related
Click Here For The Original Source.
