Commerce APIs are now the primary attack surface for automated threats, and the volume is accelerating. When AI agents transact on behalf of real customers, the behavioral signals that once separated human shoppers from malicious bots vanish, leaving security teams with no reliable baseline for blocking decisions. Eighty-five percent of commerce companies reported API-related attacks in the last 12 months, and retail absorbs three times the AI bot traffic of any other industry.
In this interview on TFiR, Steve Winterfeld, Advisory CISO at Akamai, covers the key findings from Akamai’s State of the Internet report on Securing the Agentic Storefront: Attacks on Commerce, including agentic shopper threats, API attack vectors, IoT botnet evolution, peak-season defense frameworks, and what a modern bot governance strategy must include.
Guest: Steve Winterfeld, Advisory CISO at Akamai
Show: TFiR
Here is what every security leader, platform engineer, and commerce CISO needs to know.
Technical Deep Dive
Q: What is the agentic storefront and how are AI agents changing how commerce sites are accessed?
Steve Winterfeld, Advisory CISO at Akamai, explains that the agentic storefront describes a shift where AI systems, rather than humans, initiate and complete purchases on behalf of real customers. When a user delegates a task like buying shoes to a tool such as ChatGPT, the AI conducts the research and transacts directly with the retailer through APIs, meaning the store never interacts with the human at all. The retailer loses visibility into browsing behavior, product comparisons, and intent signals, receiving only a synthetic customer at the point of transaction.
“The store is not interacting with me. It’s not seeing what shoes I looked at. All of that is suddenly gone, and now the store is just getting this synthetic customer.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Why is commerce the most heavily targeted industry for automated bot traffic?
Winterfeld points to two compounding factors: commerce is the largest industry transacting with customers online, making it the biggest available target, and it is highly revenue-interactive, meaning attackers can monetize access directly. Akamai data shows commerce receives three times the volume of AI bot traffic compared to the next most targeted industry. The attack surface is further amplified during peak events such as Black Friday, Cyber Monday, and Amazon Prime Day, when retailers deliberately reduce friction to maximize sales velocity, creating exactly the window attackers prefer.
“They’re the most heavily attacked during their most vulnerable time for impacts to revenue.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How significant is the API attack problem in commerce specifically?
According to Winterfeld, the Akamai API Security Impact Study found that 85% of commerce companies reported API-related attacks in the last 12 months. APIs are machine-to-machine interfaces by design, which means they are the primary channel through which agentic shoppers, scrapers, bots, and malicious actors interact with commerce infrastructure. Because revenue generation is increasingly concentrated in these API endpoints, criminal activity follows the same path.
“Go where you can make the most revenue. If they’re making the most money on these APIs, that’s where the criminals are going to go.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What DDoS trends is Akamai observing in retail and commerce?
Winterfeld reports that retail accounts for 84% of all commerce application-layer DDoS attacks. Groups like the Iran-Iraq hacktivist collective 313 are executing multi-vector attacks that combine AI-assisted capabilities with IoT botnets, including a variant Akamai tracks as TurboMirai. These campaigns have pushed attack sizes from gigabyte-scale to terabyte and multi-terabyte volumes, forcing security teams to revisit DDoS mitigation capacity. The classic model where a compromised home appliance joins a botnet targeting a single retailer is now operating at substantially higher scale and sophistication than it was in previous years.
“Your refrigerator is now part of a botnet, and they’re all trying to attack one commerce site at the same time.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What new attack vectors are emerging from AI integration in commerce systems?
Winterfeld identifies several AI-native attack categories beyond traditional DDoS. Token freeloading involves abusing the tokens that grant access to AI capabilities. Logic exploits target decision-making agents, including honoring expired promotional codes, authorizing fraudulent returns, and leaking proprietary inventory data. Attackers are also targeting commerce-facing chatbots and the AI agents that handle processes like credit card approvals. Winterfeld notes that malicious tooling including platforms such as Fraud GPT and Worm GPT now allows low-skill actors to develop attack code with AI assistance, raising the speed and volume of traditional attacks like scraping and credential theft.
“Agentic AI is different than your traditional gen AI in that it makes decisions, and those decision points are now being exploited.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Are traditional threats like scalping, scraping, and credential theft still relevant?
Winterfeld confirms these threats have not disappeared. Scrapers continue to harvest proprietary and customer data, scalping bots still buy high-demand inventory at scale to resell at a premium, and credential theft remains a leading path to account takeover and fraud enablement. What has changed is the speed and sophistication with which these attacks are executed, as AI tooling lowers the barrier and accelerates campaign cycles. The core categorization Winterfeld uses is friends, frenemies, and enemies, though he notes that with agentic traffic, distinguishing between these categories is becoming harder.
“We’re seeing AI increase the sophistication and speed of these attacks. Absolutely.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How should retail security leaders prepare for peak shopping events right now?
Winterfeld outlines a multi-layer preparation framework. The first step is following the customer journey end to end, from landing page to database to inventory to checkout to payment, ensuring visibility and dynamic protection at every step. Security teams should also focus hardened controls on critical functions including APIs, checkout, loyalty programs, and inventory systems. Network segmentation is essential to contain incidents before they become breaches. DDoS capacity must be validated against current peak-volume threats. Bot strategy requires formalization with clear tiers for legitimate, informational, and malicious traffic. Finally, operational readiness during a code freeze requires documented exception, escalation, and crisis processes with executive RACI alignment in place before an event begins.
“If fraud starts to increase, maybe I put a little more friction in there. If it decreases, I don’t. Ultimately I want to prevent it at the incident level, not the major breach level.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is the single most important action security leaders should take based on this report?
Winterfeld’s core recommendation is to treat the digital storefront as a customer relationship rather than a perimeter to block. APIs are the priority and must be protected through discovery, visibility, and automation. The shift from binary blocking to governance is not optional: security teams must build the capability to identify whether a synthetic customer is representing a legitimate user or acting maliciously. Protecting customer experience is the ultimate metric, not traffic volume filtered.
“We have to get away from that blocking and turn to governance.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What did the Retail and Hospitality ISAC contribute to this report and why does it matter?
Winterfeld notes this was the first year Akamai included a guest column from the Retail and Hospitality ISAC, the information sharing organization serving the retail industry. The standout insight from that contribution was the framing that loyalty points are now the new shadow currency. Winterfeld recommends that any organization running a loyalty program reclassify those points at the same data sensitivity level as credit card or financial data, given the volume of criminal activity now targeting loyalty accounts specifically.
“Loyalty points are the new shadow currency. You need to treat those just like you would credit card data or other financial data.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is the biggest mistake retailers are making right now with bot management?
Winterfeld identifies the core mistake as having bot tools without a bot strategy. Most teams still approach bots as a binary human-or-not question and default to blocking, which is no longer viable when a significant portion of automated traffic represents legitimate delegated purchasing by real customers. A modern bot strategy must categorize traffic across at least three tiers: synthetic customers representing real buyers, informational fetchers whose activity may be acceptable, and malicious bots that should be blocked or throttled. Winterfeld argues that CISO and CIO must co-own this strategy going forward.
“They have bot tools, but they don’t have a bot strategy. As we go forward, it’s going to be more and more important to have a joint bot strategy.” — Steve Winterfeld, Advisory CISO, Akamai
Resources & Documentation
- Akamai State of the Internet Reports, Akamai’s ongoing research series covering attack trends, DDoS data, and security insights across industries
- Akamai API Security, API discovery, visibility, and protection platform referenced in the interview
- Akamai Bot Manager, Bot governance and mitigation platform for managing synthetic and automated traffic
- Akamai Retail Security Solutions, Commerce-specific security capabilities covering DDoS, API, and bot protection
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: If you run an E commerce business, you are probably already aware that the customers clicking buy may not even be humans. They could be AI agents shopping and paying on someone else’s behalf. This shift has turned E commerce into one of the most attacked industries online. Old bot defenders cannot tell friends from phone. That is a big problem. Akamai’s new report, Securing the Agentic Storefront breaks down exactly what’s happening and what security leaders need to do. And joining us again is Steve Winterfeld, advisory CISO at Akamai. Steve, it’s great to have you back on the show.
Steve Winterfeld: Good to be here. Thank you.
Swapnil Bhartiya: This is interesting because we all kind of aware of it, but we’re not aware of the scale of this problem. Let’s start there. Can you walk us through this new agentic storefront? Who exactly are these AI shoppers and how are they interacting with commerce site? Then we’ll talk about what threats they pose.
Steve Winterfeld: And so today what we’re going to do is we’re going to share some insights from the Akamai state of the Internet report. And this one is called Attacks on commerce. And it really is interesting because we see this growth of 0 clicks or the Gentix shopper. And so what we’ve done is, is we’ve looked across all of our security platforms here at Akamai, protecting the edge and the web page, protecting AI instances. And across all that, we’re starting to see some themes. One of these is the storefront for more and more. Commerce is by far in the lead. But finance and so many other industries are interacting over the web through APIs. And so again, an API is a machine to machine designed interface. You know, if, if, if I go to a web page, it should be designed for my eyes. If an API goes to a website, it’s designed for that machine to machine interaction. And so the storefronts are no longer having me come to it, it’s having one of the apps on my phone or really what we’re talking about here for that gentic shopper is let’s say I’m in, I’ll pick a flavor chat GPT and I want to buy a pair of shoes. Well, I’m not going to do my research about the best hiking shoe inside of ChatGPT and then leave it and then go to the store and buy it myself. I’m going to tell ChatGPT to do the research and then to go buy the shoes themselves. And so this has caused a couple things. One, the store is not interacting with me. Sure. It’ll get my credit card. But it’s not seeing all the decisions. It’s not seeing what shoes I looked at. It’s not all of that is suddenly gone. And now the source just getting this synthetic customer. And so, you know, now turning from the shopper to the defender. I used to be able to say, okay, well that’s not a legitimate shopper. That’s not a human. Well, now I can’t do that anymore because we’ve seen this increase in 19% of the these could be legitimate shoppers. And and so I can’t just block these synthetic entities anymore. And so as we’re doing this, I need new controls and need to understand this because again, we’re talking about these APIs interacting. IT and the Akamai API Security Impact Study found that 85% of all the companies responding in commerce said they’d had API related attacks in the last 12 months. So now it’s, you know, again, go where you can make the most revenue. So if you, if, if they’re making the most money on these APIs, you know, that’s where the criminals are going to go. And so that’s kind of what we’re talking about is, is commerce is a leading boat to what you said. Anybody in E commerce, is anybody interacting with customers, healthcare, finance, anybody? It is now becoming a challenge to understand what’s a real person, what’s a synthetic representation of a real person and what’s a malicious activity?
Swapnil Bhartiya: No, that was great. Of course E commerce or commerce is, you know, low hanging fruit. But why is commerce specifically drawing the highest volume of automated bot traffic compared to other industries? What is the reason behind it?
Steve Winterfeld: Yeah, and, and you know, the report is worth reading because there’s a lot of great graphics in there. One of the graphics is to what you just said, three times the volume of, of what Akamai characterizes AI bot traffics over the next most targeted industry. And so commerce is one of the leading industries in interacting with customers online. So you know, they’re, they’re targeted because they’re the largest target and they’re highly revenue interactive. And so, you know, it’s where I can simply make the most money. So, you know, we talk about this, we also talk about peak events. So again, when I was CISO for Nordstrom bank, we have the anniversary sale, a peak event. If you, we all probably bought something on Amazon, you know, Amazon prime days. We have, you know, it used to be Black Friday and then Cyber Monday. Now it’s that whole five day stretch is just One long endurance for people in sales. One long endurance sprint from, you know, Thanksgiving through that following Monday. These peak events for some commerce organizations are, you know, a significant part of their annual revenue. And so they need to minimize friction during these sales. Well, when I hear minimize friction as a cyber criminal, that’s when I want to attack. And so this is another aspect of it. Not only is it the most attacked, but they’re the most heavily attacked during their most vulnerable time for impacts to revenue.
Swapnil Bhartiya: Well, that is true. Now can you also talk about beyond agentic shoppers, what other trends are you seeing like DDoS and other traditional attacks as well?
Steve Winterfeld: So as you know, Akamai does a lot around DDoS protection and so we have a ton of insights, regional insights, industry insights, but within commerce, retail accounted for 84% of all commerce application layered DDoS attacks. And so you know, there are groups out there like the Iran Iraq Hackivist Group 313 that have been really focused on some of this stuff doing multi vector approach combining AI assisted Mirai Internet of things botnet, we’re calling it TurboMirai. And there are variants of this that have, have really peaked the old, you know, gigabyte to terabyte to multiple terabyte size attacks. And so that’s requiring CSOs to go relook their defensive capabilities with these new peak capabilities of all Internet of things. So you know, this is the classic, you know, your refrigerator is now part of a botnet which is just a collection of different systems and they’re all trying to attack one commerce site at the same time. And we talked a little bit about there, that there’s AI capabilities being added in here. I haven’t seen a ton of these in the wilds. We talk about things like Project Glasswing, if you’ve heard about that, where they’re just stacking up all these vulnerabilities. I haven’t seen a ton of those vulnerabilities be operationalized. So a lot of them were real vulnerabilities, but they haven’t been used in the wild by cybercriminals or activists to cause damage or disruption. And so we think about this, but as AI gets in here, there’s this new vulnerability areas. A lot of us, when you go there’s a chatbot there, can I help you? Well, they’re attacking those chat bots. If there’s agents, like let’s say you go in and you want to get a credit card from your, from your shopping store. A lot of that may now be handled by AI agents to make those decisions. Because again, agentic AI is different than your traditional gen AI in that it makes decisions. And then tokens. Tokens are those capabilities that let you leverage all this. In fact, we have a section on our malware talking about token freeloading. So, you know, all of this is now logic exploits honoring expired promotional codes, authorizing fraudulent returns, leaking proprietary inventory data. There’s a lot of different types of attacks happening out here with this new AI capabilities beyond just those traditional ddos. And then we do a malware deep dive. You know, we talk about those traditional things. Credential theft leading to account takeover, fraud, enablement, persistent access. And Akamai is a common vulnerability, exposures, numbering authority. So we do a lot of this kind of research, but we talk in detail about some of this capability out there and what you should be looking for within your logs and within your protective organizations today.
Swapnil Bhartiya: You and I have talked a lot about, you know, the holidays, scalping and, you know, phishing and how, I mean, some of these bad actors, no officers are very creative people. You know, the way they come out, I wish they were on our side, not on the opposite side. But what is happening to some of those traditional attacks and threats, which may not be as malicious, but they have their own, you know, of course, malicious intent as well.
Steve Winterfeld: So I will say one thing that, you know, looking at, at things like Project Glasswing, the speed and volume is changing, you know, the, the sophistication of. Of somebody being able to do this. You can now go rent these capabilities. You can go on AI and, and have AI help you develop code. There are sites out there, fraud GPT or worm GPT that, that are malicious in nature. And so do we still see scrapers coming in to harvest information, proprietary information, customer information? Absolutely. You know, we. Again, something we protect against, we track that, we talk about that. Am I worried as a CSO about the traffic cost of all these? You know, we just talked about buying shoes through AI. All that volume of traffic is now AI systems, which I’m getting no insights from. So that, you know that traditional. You and I have talked about. Friends are shoppers. Frenemies are people that are informing shoppers. So if again, somebody’s saying, hey, you know, you can buy shoes over here, then that’s helpful. And then enemies. So friends, frenemies and enemies. Getting a little harder to tell. Those apartments. You know, one thing I worry about as. As again when I was back at Nordstrom is customer experience. And so again, if there’s a new tennis Shoe coming out. I want everybody to be able to buy one, but I don’t want one bot to buy all my inventory and then resell them at a higher price, scalping them basically. And so all these are protections we continue have to do. And we’re seeing AI increase the sophistication, sophistication and speed of these kind of attacks. Absolutely.
Swapnil Bhartiya: Thank you. Now, when you look at all these emerging threats, of course, nowadays every month or every other month you see a big major shopping event. How should retail companies be preparing right now before the whole shopping season arrives here?
Steve Winterfeld: So, you know, I think the first is as a ciso, I want to follow the customer’s journey. And as I understand, you know, they come in here, they see this page, this page goes to this database, this database goes to this inventory system, this inventory systems, goes to this checkout, you know, to save that inventory, to hold it aside. This checkout goes to this purchase system. I want to make sure all those steps are protected and there are 25 more steps in that one purchase I didn’t talk about. And so I want to make sure I have visibility and the ability to dynamically protect that. You know, if fraud starts to increase, maybe I put a little bit more friction in there. If it decreases, I don’t ultimately, you know, I also want to put some mitigations in there because someone is going to get through and I want to prevent it at the incident, not the major breach level. And so I want things like segmentation in there to minimize the impact. And finally, you know, got to go back to the basics, what we Talked about earlier, DDoS. I want to make sure my capabilities during this peak event are able to handle that volume and move the DDoS aside so it’s not impacting customer experience. The next thing is I want to focus on critical functions, you know, APIs, the checkout capability, loyalty programs, you know, inventory systems. By protecting those critical systems with more security than others, then I’m, I’m guaranteeing a, a more dynamically survivable, resilient capability. I want to know, I want to map the revenue chain. What are the Crown Jewels? What third party systems are critical? How am I doing IDs and, and those IDs include now all these agentic IDs, all these, you know, actors that are taking, you know, active part in making decisions within my systems. I need to have visibility and situational awareness around them. We started with this and it’s probably, it’s deeper in the list, but it’s one of the most Important things. I need a good bot strategy. I need to know, you know, how I’m reviewing credentials, bad bot mitigation, API versus, you know, synthetic customers. I need, I can’t just block anymore. I need to manage this. You know, obviously operations are big during these peak events. There’s a freeze. Nothing should change. So if I need to change something for security, do I have clear process for freeze, exception and escalation? Do I have a crisis process that’s been exercised? So when something starts to go wrong or we quickly mitigate and, you know, that means executive alignment for a raci, you know, responsible, accountable, consultant and informed, making sure we know who can give these exceptions and who’s involved in that crisis. You know, it’s a more detailed list in the report, but, but at a high level, those are kind of those critical things that we should all have on our prep sheet for a major event.
Swapnil Bhartiya: One thing that you and I talk about is that these reports are only good if people actually read them and act on them. What is the one thing you would want security leaders to walk away with and actually do with these insights that you have shared? And they should also go and read the report as well.
Steve Winterfeld: So going back to the fact that we are becoming managers of a Digital storefront, the APIs are a priority. We need to protect them through discovery, visibility, and automation. But that storefront is our customer. So we have to get away from that blocking and turn to governance. And we have to have good indicators of when a synthetic customer is representing a real customer and when it’s potentially malicious, because ultimately we have to protect our customer experience.
Swapnil Bhartiya: Can you talk about what other insights were there in terms of local retail hospitality?
Steve Winterfeld: So, you know, this first year we had a guest column by the retail and hospitality isac, the information sharing organization that all the revenue, all the retailers belong to. And so essentially, I loved the CISO’s comment that loyalty points are the new shadow currency. So for those companies that have loyalty programs, I really think you need to change your attitude, if you haven’t already, and treat those just like you would credit card data or other financial data, because we’re seeing more and more cyber criminals go after this.
Swapnil Bhartiya: Can you also talk about what are the, some of the biggest mistakes that you see retailers are making right now when it comes to managing all this bot traffic and why they should go and read this report?
Steve Winterfeld: I think part of the problem is they, they hear bots and traditionally are thinking as bots as negative things. You know, going back to, you know, all these different types of bots out there. There are training bots out there that are using my resources to train their AI. There are fetcher bots that are coming to get the information to buy shoes. There are malicious bots out there. And so a lot of us are still stuck because I find myself falling into the trap of when I think about bots, bots are something that I try to say, is it human yes or no? And then binary decision block them. And now I need to say, you know, is this bot part of a synthetic customer? Is it somebody fetching something that I want? Is it somebody training on my site that I want to minimize because I don’t want to pay for those cycles? So I think it’s. They don’t have a bot strategy. They have bot tools, but they don’t, you know. And as we go forward, it’s going to be more and more important to have kind of a working with the CIO and the CISO to have a joint bot strategy.
Swapnil Bhartiya: Steve, once again, thank you so much for joining me and sharing these insights on agentic commerce security. Thank you for your insights and for those who are watching, if you want to dig deeper, please check out Akamai’s new report, securing the agentic storefront and and everything else that the team is working on. Once again, thank you and I look forward to chat with you against you.
Steve Winterfeld: Thanks everybody. I appreciate you spending the time with us. We have a lot of other SOTI reports out there. Feel free to come. I’m very proud of our blogs and some of our other research and please reach out to me or through our website to Akamai and happy to help you guys secure your commerce in other areas.





