Automated traffic classification is breaking down. AI tools are compressing the skill gap between casual threat actors and sophisticated operators, and the volume of AI-generated traffic, both legitimate and malicious, is outpacing the visibility most security teams have into their own infrastructure. Retail and e-commerce environments are absorbing the impact directly, from data scraping to inventory scalping at scale.
In this interview on TFiR, Steve Winterfeld, Advisory CISO at Akamai, covers how AI is accelerating traditional bot-based attack vectors, why the friend-frenemy-enemy classification model is under pressure, and what security teams need to understand about the evolving threat landscape around scraping, scalping, and malicious AI tooling.
Guest: Steve Winterfeld, Advisory CISO at Akamai
Show: TFiR
Here is what every security practitioner and CISO needs to know.
Technical Deep Dive
Q: How is AI changing the speed and sophistication of traditional attacks like scraping and scalping?
Steve Winterfeld, Advisory CISO at Akamai, points to initiatives like Project Glasswing as evidence that AI is materially increasing the speed and volume of automated attacks. Threat actors can now rent attack capabilities rather than building them, and AI coding assistance lowers the barrier for developing malicious tooling. Scrapers targeting proprietary and customer data remain active and are becoming faster and more scalable as AI is layered into the attack chain.
“The speed and volume is changing, the sophistication of somebody being able to do this. You can now go rent these capabilities.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What are FraudGPT and WormGPT and why do they matter to enterprise security teams?
FraudGPT and WormGPT are publicly accessible AI tools built specifically for malicious purposes, enabling attackers to generate phishing content, develop exploit code, and automate attack workflows without deep technical expertise. Winterfeld identifies these platforms as a structural shift in the threat landscape because they commoditize capabilities that previously required significant skill investment. Their existence means the baseline sophistication of lower-tier threat actors is rising continuously.
“There are sites out there, FraudGPT or WormGPT, that are malicious in nature.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is the friend-frenemy-enemy bot classification model and why is it getting harder to apply?
Winterfeld describes a three-tier framework for categorizing automated traffic: friends are bots that drive direct value such as shoppers completing purchases, frenemies are bots that inform shoppers such as price comparison engines, and enemies are bots with clear malicious intent such as scrapers and scalpers. The challenge is that AI-generated traffic is blurring the behavioral signals that distinguish these categories, making it harder for security teams to apply policy without blocking legitimate volume or allowing harmful traffic through.
“Friends, frenemies, and enemies are getting a little harder to tell apart.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Why is AI-driven shopping traffic a security and operational problem even when it is not malicious?
Winterfeld flags that the volume of traffic generated by AI shopping agents creates a visibility gap for security and operations teams. Unlike human browsing sessions, AI agent traffic yields no behavioral insights and generates cost without providing signal. As AI-assisted purchasing becomes mainstream, the proportion of traffic that security teams can meaningfully analyze or act on shrinks, weakening threat detection baselines and increasing infrastructure cost without a corresponding increase in revenue attribution.
“All that volume of traffic is now AI systems, which I’m getting no insights from.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How does scalping affect retail operations and what does bot-driven inventory depletion look like in practice?
Winterfeld uses his experience at Nordstrom to illustrate the business impact of scalping bots: a single bot can sweep available inventory of a high-demand item before genuine customers can complete a purchase, and that inventory is then resold at a markup. The outcome is a direct hit to customer experience, brand trust, and revenue, with the retailer absorbing the operational cost while the scalper captures the margin. Protecting against this requires bot mitigation that can distinguish purchasing intent at the session level under high-volume conditions.
“I don’t want one bot to buy all my inventory and then resell them at a higher price, scalping them, basically.” — Steve Winterfeld, Advisory CISO, Akamai
Resources & Documentation
- Akamai Bot Manager, Akamai’s platform for classifying and mitigating automated bot traffic across web and API surfaces
- Project Glasswing, Akamai research initiative tracking AI-driven changes in attack speed and volume (reference Akamai threat research for current publications)
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: You and I have talked a lot about, you know, the whole scalping and, you know, phishing and how, I mean, some of these bad actors, no officers, are very creative people. You know, the way they come out, I wish they were on our side, not on the opposite side. But what is happening to some of those traditional attacks and threats, which may not be as malicious, but they have their own, you know, of course, malicious intent as well.
Steve Winterfeld: So I will say one thing that, you know, looking at things like Project Glasswing, the speed and volume is changing, you know, the sophistication of somebody being able to do this. You can now go rent these capabilities. You can go on AI and have AI help you develop code. There are sites out there, fraud GPT or worm GPT that are malicious in nature. And so do we still see scrapers coming in to harvest information, proprietary information, customer information? Absolutely. You know, we. Again, something we protect against. We track that, we talk about that. Am I worried as a CSO about the traffic cost of all these? You know, we just talked about buying shoes through AI. All that volume of traffic is now AI systems, which I’m getting no insights from. So that, you know that traditional you and I have talked about. Friends are shoppers. Frenemies are people that are informing shoppers. So if again, somebody’s saying, hey, you know, you can buy shoes over here, then that’s helpful. And then enemies. So friends, frenemies and enemies getting a little harder to tell those apart. You know, one thing I worry about as again when I was back at Nordstrom, is customer experience. And so again, if there’s a new tennis shoe coming out, I want everybody to be able to buy one. But I don’t want one bot to buy all my inventory and then resell them at a higher price, scalping them, basically. And so all these are protections we continue have to do. And we’re seeing AI increase the sophistication and speed of these kind of attacks. Absolutely.





