Bot

A bot is software that performs tasks automatically, without a person driving each action. Most are benign — search crawlers, chat assistants, monitoring scripts. In fraud and identity work the term almost always means the other kind: automated traffic used to test credentials, open accounts at scale, or exhaust an offer before real customers reach it.

General meaning Software that acts automatically, without per-action human input
Benign examples Search crawlers, chat assistants, monitoring and backup scripts
Malicious examples Credential stuffing, account creation, card testing, scalping, scraping, promo abuse
Credential stuffing Replaying breached username and password pairs at scale
Card testing Small transactions run to find which stolen card numbers still work
Common infrastructure Headless browsers, automation frameworks, residential proxy networks
Detection signals Device and browser inconsistency, timing regularity, velocity, network reputation
Newest variant Agentic AI acting on a real user’s behalf — automated but legitimate
Why blocking is hard Not all automation is hostile, and hostile automation imitates humans

How it works

Malicious bots are worth separating by what they are trying to achieve, because the defenses differ.

Credential stuffing bots replay username and password pairs stolen from unrelated breaches, at rates no human could manage. Nothing is cracked — password reuse does the work. Success rates are low per attempt and the volume makes it profitable anyway.

Account creation bots open accounts in bulk, for promotional abuse, marketplace seller fraud, or to build inventory for resale. This is where identity verification changes the economics most directly, because each account suddenly requires a genuine document and a real face rather than an email address.

Card testing bots run small transactions against stolen card numbers to find which are still live, typically on merchants with low-value payment forms and weak rate limiting.

Scraping and scalping bots harvest content or buy limited inventory faster than people can.

The infrastructure has converged. Serious operations use headless browsers that render pages like real ones, automation frameworks that produce human-like mouse paths and typing rhythms, and residential proxy networks that borrow IP addresses from real consumer connections. Simple signals — user agent strings, datacenter IP ranges, missing browser features — catch the careless and nothing else.

The category is also shifting. Agentic AI systems now act on behalf of genuine users, which produces traffic that is automated and legitimate at the same time. Blanket bot blocking increasingly catches real customers whose assistant is doing the clicking.

Why it matters for identity verification

Bot defense and identity verification solve the same problem at different points, and the ordering matters.

Bot detection asks whether this session is automated. Identity verification asks whether there is a real, specific person behind it. The first is a probabilistic judgment about behavior that a well-built bot can imitate. The second demands an artifact automation cannot manufacture — a genuine government document matched to a live face.

That is why account creation bots are the clearest case for verification at signup. A bot farm opening ten thousand accounts is defeated not by better behavioral detection but by a requirement that each account present an authenticated document and a person who matches it. The attacker does not need a better bot; they need ten thousand documents and ten thousand faces, which is a different business.

The overlap with liveness detection is direct. Injection attacks — synthetic frames fed into a capture pipeline through a virtual camera — are automation applied to the verification step itself. Defending that means attesting the capture channel, not judging the image. Device and behavioral signals handle the session, and Microblink’s promo abuse detection covers the bulk-account case specifically.

Benign vs malicious bots

  Benign automation Malicious bots
Identifies itself Usually, via user agent and published IP ranges No — imitates a real browser
Respects robots.txt Generally No
Traffic pattern Steady, predictable Bursty, or deliberately paced to look human
Infrastructure Known datacenter ranges Residential proxies, rotating IPs
Browser Often a simple HTTP client Headless browser rendering the full page
Correct response Allow, rate-limit if needed Block, challenge, or escalate to verification

The distinction is getting harder rather than easier. Agentic AI sits awkwardly across it — automated, undisclosed, and acting for a genuine customer — which is why identity is becoming a more reliable question than automation.

What bot detection can’t do

It cannot prove a session is human. Detection produces a probability from behavioral and device signals, all of which sophisticated automation imitates. Absence of bot signals is not evidence of a person.

It cannot distinguish hostile automation from helpful automation. An AI assistant completing a form for a real customer looks like a bot because it is one. Blocking on automation alone increasingly blocks legitimate users.

It cannot stop a human doing the same thing slowly. Manual fraud farms — people paid to open accounts by hand — defeat every bot control by not being bots.

It cannot fix an unverified account population. Blocking bots at signup stops bulk creation. It says nothing about accounts already opened, and nothing about whether the humans who got through are who they claimed.

Frequently asked questions

Are all bots harmful?

No. Search crawlers, monitoring scripts, backup jobs and chat assistants are automation doing useful work. In fraud contexts the word usually means malicious automation specifically, which is a small share of total bot traffic but most of the damage.

What is credential stuffing?

Bots replaying username and password pairs stolen from unrelated breaches, at volume. It works because people reuse passwords — nothing is cracked. Success rates per attempt are low, and the scale makes it worthwhile.

How do bots get past CAPTCHA and bot detection?

Headless browsers that render pages fully, automation frameworks that mimic human mouse and typing patterns, residential proxy networks that borrow real consumer IP addresses, and commercial solving services. Simple signals catch the careless operators only.

Does identity verification stop bots?

It stops bulk account creation, which is the most damaging bot use case. A bot cannot produce ten thousand genuine government documents matched to ten thousand live faces, so requiring that at signup changes the attacker’s economics rather than their tooling.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data