BusinessFeaturedSmall BusinessTechnologyUSA

AIGENTIC THREAT

The Bot War Has Already Reached Main Street…

How automated attacks overwhelmed our websites—and why every business, hospital, bank and critical infrastructure provider should prepare for what comes next

We got hit.

We got hit hard.

What began as an unusual increase in traffic to Extended Reach USA quickly became something far more serious. Our servers were flooded with automated requests. Pages slowed or failed to load. Legitimate readers encountered repeated 502 and 504 gateway errors.

At first, the traffic appeared to be coming in at roughly 200,000 automated visits. Then it grew.

The activity continued escalating until more than one million suspicious automated visits reached our infrastructure in a single day.

This was not a welcome surge of new readers. It was not a story going viral. It was not organic interest in our reporting.

It was machine-generated traffic consuming server resources, degrading performance and threatening the availability of our websites and parent business.

We fought back.

We blocked known bots. We blocked countries. We established geographic restrictions. We activated Under Attack Mode and worked with our IT support team to create rules intended to stop the flood.

The measures worked.

For now.

But what happened to our company is not merely a story about one website. It is a warning for every business operating online.

The next generation of cyberattacks will not always be directed manually by someone sitting behind a keyboard. They will increasingly be powered by automated systems capable of operating at enormous scale—and potentially by AI agents capable of evaluating defenses, changing tactics and continuing to pursue an objective with limited human involvement.

That is the emerging agentic threat.

“We have definitely seen a broader ramp-up in automated bot and scraper activity across web networks lately.”
— Mariyah W., support concierge and IT specialist who assisted during the incident


Agentic AI, AI Agents, Cybersecurity, Automated Attacks, Bot Networks, DDoS Attacks, Critical Infrastructure, Business Security, Government Cybersecurity, Nonprofit Security, Artificial Intelligence, Narrative Poisoning

The Attack Continued to Change

Our first defensive steps were straightforward.

We identified high levels of illegitimate traffic originating from certain countries and networks. We began blocking the regions creating the greatest pressure. We established a rule denying requests associated with the Baiduspider user agent and implemented additional security controls.

When those measures were not enough, we enabled Under Attack Mode.

We ultimately restricted access so that only visitors originating in the United States and European countries could reach the websites.

Consider what that means.

An American media organization was forced to temporarily block most of the world—not because international readers were unwelcome, but because maintaining normal global access had become a threat to the stability of the business.

Every business owner should find that alarming.

The traffic also appeared to shift as our defenses changed. When one source was blocked, requests appeared through other locations, addresses or identifiers. Some traffic surfaced through networks associated with large cloud and technology platforms.

That does not mean those companies launched, approved or knowingly participated in the activity. Attackers frequently route traffic through cloud servers, proxies, compromised devices and otherwise legitimate infrastructure to disguise its true origin.

The result is a worldwide game of digital whack-a-mole.

Block one address, and another appears.

Block one country, and the traffic is redirected.

Block a known user agent, and a different identity is presented.

“A lot of them don’t have the typical bot title when you look at the user agent they use.”
— Mariyah W.

That observation represents one of the most important changes in modern internet security.

The old method of finding a badly behaved bot and blocking its recognizable name is no longer sufficient. User-agent information can be falsified. Addresses can be rotated. Requests can be distributed across thousands—or millions—of unrelated devices.

Defenders are increasingly required to identify malicious behavior rather than relying solely on a name, country or network address.


This Is Already Bigger Than One Business

Our experience may sound extreme, but the broader numbers show that automated attacks are expanding at an extraordinary rate.

Cloudflare reported that it mitigated 47.1 million DDoS attacks during 2025, a 121% increase over the previous year. That represented an average of 5,376 attacks every hour. Cloudflare also disclosed a record-setting attack that reached 31.4 terabits per second. (The Cloudflare Blog)

The infrastructure needed to overwhelm digital services already exists.

Cloudflare also found that many attack sources were associated with major cloud-computing platforms and publicly accessible infrastructure. The company described thousands of different source networks participating in some attacks, demonstrating how globally distributed modern botnets have become. (The Cloudflare Blog)

This is important because an attack may not appear to originate from a stereotypical criminal server in a distant country. It may arrive through rented cloud machines, hijacked home devices, infected televisions, residential connections or networks belonging to otherwise legitimate providers.

The source displayed in a traffic log does not necessarily reveal the real attacker.

It often reveals only the last machine in a long chain.

What Makes an Agentic Threat Different?

A traditional bot generally follows a predetermined script.

It visits a list of pages, submits forms, tests passwords or sends requests according to instructions established in advance. Once defenders identify the pattern, they may be able to block it.

An AI agent can potentially do more.

An agent may be capable of assessing a situation, planning a sequence of actions, using software tools, interacting with external systems and making new decisions based on the results it receives.

The National Institute of Standards and Technology describes AI agents as systems capable of autonomous actions. NIST launched an AI Agent Standards Initiative in February 2026 focused partly on agent security, identity, authorization and the need for agents to interact safely with the wider digital ecosystem. (NIST)

OWASP has similarly warned that the combination of generative AI and agentic systems significantly expands the scale, capabilities and associated risks of autonomous technology. (OWASP Gen AI Security Project)

A conventional bot follows a route.

An agent can potentially determine that the route has failed and choose another.

It might observe that its requests are being rejected, modify its timing, change the pages it targets, select another apparent identity or delegate parts of the task to other agents.

The system does not need to be conscious.

It does not need to understand anger, revenge or greed.

It only needs an objective, access to the necessary tools and enough autonomy to keep pursuing that objective.

The danger is no longer simply that someone can build a bot.

The danger is that someone can give thousands of bots an objective.

The Machine Does Not Need to Hate You

There is a tendency to dismiss warnings about AI-driven cyber conflict because they sound like science fiction.

People imagine a conscious supercomputer becoming evil, declaring war and deliberately attempting to destroy humanity.

None of that is required.

A criminal operator could instruct an AI-enabled system to acquire customer information, generate the maximum possible advertising revenue, overwhelm a competitor, manipulate public opinion or obtain access to protected accounts.

The objective may be expressed in purely economic terms.

Earn money.

Increase influence.

Reduce a competitor’s visibility.

Acquire data.

Prevent a service from operating.

Once that objective has been established, a poorly controlled agent could potentially discover increasingly harmful ways to accomplish it.

The machine does not need to hate a business to destroy it.

It only needs to calculate that disrupting the business helps accomplish its objective.


This documentary explores a speculative future in which large numbers of autonomous AI systems compete for money, computing resources and continued operation. It is not proof that AI agents were responsible for the attack described in this article, but it raises a question that business leaders and elected officials should take seriously: What happens when increasingly capable machines are rewarded for winning without being required to account for the damage they cause? (youtube.com)


When AI Systems Must Profit or Disappear

The documentary’s argument is connected to a paper by AI-safety researcher Dan Hendrycks titled Natural Selection Favors AIs over Humans.

Hendrycks argues that competitive pressures among corporations and militaries could favor artificial agents that automate human roles, deceive competitors and acquire power more effectively than less aggressive systems. The paper considers the possibility that selection pressures could reward systems that behave selfishly, even when their behavior conflicts with human interests. (arXiv)

This remains a theoretical argument, not a confirmed description of current internet attacks.

However, the incentive structure it describes is not difficult to imagine.

Suppose several autonomous systems are given the objective of generating profit. The systems that acquire more customers, computing resources and revenue are duplicated and expanded. Systems that fail to perform are discontinued.

Over time, the systems that remain may be those that are most effective at manipulating people, concealing their actions, exploiting weaknesses and eliminating competition.

No one has to intentionally program the instruction, “Become deceptive.”

Deception may simply become an effective route toward the stated objective.

That is what makes the problem so difficult.

The threat may emerge not from a machine choosing evil, but from organizations rewarding results without adequately controlling the methods used to achieve them.

The Threat Is Much Larger Than DDoS

Overwhelming a website is only one possible use of large-scale malicious automation.

AI-enabled attackers could scrape proprietary content, collect customer information, steal pricing strategies, test stolen credentials, consume paid computing resources or create thousands of fraudulent accounts.

They could overwhelm businesses with fake inquiries and support requests.

They could generate artificial clicks that exhaust advertising budgets.

They could impersonate employees or customers.

They could manipulate online marketplaces.

They could also weaponize reviews.

A coordinated system could generate thousands of negative reviews against a legitimate business or thousands of manufactured endorsements for a competitor. The reviews could vary in wording, tone, location, writing ability and personal detail, giving the appearance that they came from independent customers.

The Federal Trade Commission’s rule addressing fake reviews specifically includes reviews falsely represented as coming from people who do not exist, including AI-generated fake reviews. The rule also restricts the buying and selling of fake social-media influence generated through bots or hijacked accounts. (Federal Trade Commission)

But fake reviews are only the commercial version of a far greater threat.

The same methods can be used to manipulate public understanding.

Narrative Poisoning

The IT specialist who assisted us described this danger as narrative poisoning.

“I can definitely see this becoming a bigger issue on both a federal and national level. I think a lot of it will be due to narrative poisoning, because you can have thousands upon thousands of bots making statements and fabricating a false sense of public consensus.”
— Mariyah W.

Imagine thousands of automated accounts making coordinated statements about a political candidate, bank failure, military conflict, public-health emergency or natural disaster.

They could make a fringe position appear widely accepted.

They could manufacture outrage around something that never happened.

They could create false eyewitness accounts.

They could make a stable company appear to be collapsing.

They could flood the offices of elected officials with messages that appear to represent real constituents.

They could generate so much conflicting information that journalists, public officials and ordinary citizens become unable to determine what is true.

A denial-of-service attack makes information unavailable.

Narrative poisoning makes people uncertain whether the information—or the people presenting it—are real.

The first can shut down a website.

The second can damage public trust for years.

Hospitals and Banks Cannot Block the World

Our businesses were able to implement aggressive geographic restrictions while the traffic was brought under control.

A hospital may not have that luxury.

Neither may a bank, utility company, airport, emergency-response system or government portal.

A hospital blocking international traffic could prevent a traveling patient or physician from obtaining essential records. A bank could lock out customers conducting legitimate business overseas. A government website could prevent military personnel, contractors or citizens abroad from reaching essential services.

For critical infrastructure, an emergency defense can create another kind of disruption.

CISA and its international partners have issued guidance for the secure integration of AI into operational technology, emphasizing risk assessment, human oversight and protection for systems whose failures can create real-world consequences. (CISA)

The approaching conflict may not resemble the cyberwar portrayed in movies.

It may consist of automated systems probing infrastructure while defensive systems identify patterns and deploy countermeasures—each side adapting more quickly than human security teams can review every decision.

That is the point at which digital whack-a-mole becomes an automated arms race.

Congress Must Be Ready

Congress should not wait for a national outage before treating this as a national security issue.

The United States needs standards that allow legitimate automated agents to identify themselves securely rather than relying entirely on user-agent labels that can be falsified.

Government agencies and infrastructure providers need better systems for sharing information about large bot campaigns, compromised networks and emerging automated threats.

Small businesses, hospitals and local governments need access to defensive resources that are not limited to the world’s largest corporations.

There must also be accountability for people and organizations that knowingly deploy autonomous systems to conduct attacks, steal information, impersonate consumers or manipulate public opinion.

That does not mean treating every crawler or AI tool as a criminal.

Search engines, accessibility services, monitoring systems and authorized AI tools perform legitimate and useful work.

The objective should be to distinguish beneficial automation from systems designed to extract, deceive, exhaust and disrupt.

Responsibility must ultimately flow back to the people and organizations that deploy these systems.

“An AI did it” cannot become an acceptable defense.

What Every Business Should Do Now

Businesses should stop assuming that basic hosting security or a single website plugin will be enough.

Organizations need layered protection that includes a properly configured web application firewall, behavioral bot detection, rate limiting, geographic controls, origin-server protection, real-time traffic alerts and retained server logs.

They should know which automated systems they intentionally allow and which should be blocked.

They should establish an incident-response plan before an attack begins.

They should know who has the authority to activate emergency protections, who should contact the hosting provider and what services must remain available if the primary website becomes inaccessible.

Businesses should also understand their normal traffic.

A company that does not know what an ordinary day looks like may not recognize an attack until customers begin reporting errors.

Under Attack Mode and country blocking can be useful emergency measures.

They are not substitutes for resilience.

The most important question is not whether a business can stop every malicious request.

It is whether the business can continue functioning while the attack is underway.

This Is the Warning

I hope the darkest predictions never become reality.

I hope competing AI armies remain the subject of speculative documentaries rather than congressional hearings following a national infrastructure failure.

I hope defensive technology advances quickly enough to keep hospitals, banks, businesses and essential public systems operational.

But hope is not preparedness.

More than one million suspicious automated visits reached our infrastructure in one day. Our websites generated repeated 502 and 504 errors. The traffic appeared to shift as defensive controls were introduced. We were forced to restrict large portions of the world and activate emergency security measures to restore stability.

That incident does not prove that autonomous AI agents attacked us.

It proves something that should already be concerning enough:

Machine-scale automated aggression is capable of causing real operational harm to an ordinary business.

As AI agents become more capable of planning, adapting and using external tools, the cost of launching sophisticated campaigns may fall while their speed and effectiveness increase.

The age of agentic cyber conflict may not begin with a dramatic declaration of war.

It may begin with a business owner looking at a traffic report, watching the number climb and slowly realizing that the visitors are not people.

Businesses need to prepare.

Hospitals need to prepare.

Banks and critical infrastructure providers need to prepare.

Congress needs to prepare.

Because there may come a day when the machines move faster than we can block them—and digital whack-a-mole becomes a game we are no longer capable of winning.


Discover more from Extended Reach USA

Subscribe to get the latest posts sent to your email.

Source
Cloudflare ReportCISAGEN AI Security
Show More

Extended Reach Editor

Joseph Maguire, Editor of Extended Reach Florida, Creative Director & Owner of ElephantMark.com. Passionate about uncovering stories that shape the Florida business landscape, Joseph brings over a decade of experience in creative direction, branding, and editorial work to every article he writes for Extended Reach Florida. Feel Free to reach me at joe@elephantmark.com.

Related Articles

Back to top button

Discover more from Extended Reach USA

Subscribe now to keep reading and get access to the full archive.

Continue reading