Ensure fast, reliable experiences across web, mobile, and apps.
Protect against bots, fraud, and DDoS attacks.
Keep customer and supplier information secure.
Seamless experiences across every touchpoint.
This holiday season, the threat landscape is bigger than ever — and so is the opportunity. The businesses who win will be the ones who block the bad bots and welcome the good ones.
Last December, attackers launched a “Night Before Christmas” DDoS campaign that peaked at 205 million requests per second. Across 2025, Cloudflare mitigated 47.1 million DDoS attacks — more than double the prior year.
And that was before AI agents entered the picture.
This holiday season, there's a new kind of visitor at your front door. Not a shopper browsing your homepage — an AI assistant deciding whether to recommend you at all. In the US, nearly half of page requests now come from bots rather than humans. AI training crawlers surged to 52% of all crawler requests as of June 2026, up from 22% a year earlier, a sign of how fast AI systems are indexing the web to power the agents that search, compare, and recommend on behalf of real buyers.
When a customer asks an AI assistant “what should I get my dad who runs?” and your competitor gets recommended instead, that's a sale you never even knew you lost.
The businesses that win this peak season will be the ones who can do both — survive the attacks that come with the traffic and show up when AI agents go looking for products to recommend.
The same surge that brings record revenue also brings record attacks, and they come from every angle.
DDoS attacks get bigger and better-timed. In 2025 Cloudflare blocked a record 31.4 Tbps attack. Attackers target peak shopping hours because that is when downtime costs the most. Most hyper-volumetric attacks last under 10 minutes — some under 35 seconds — far too fast for any human or on-demand service to react. But the cascading failures can take days to recover from.
Bad bots swarm checkout, pricing, and login pages. Scalper bots grab limited inventory the moment it drops, tying up stock in carts and forcing legitimate shoppers out — even if those orders are later cancelled, the damage to your conversion window is already done. Scraper bots copy your pricing so competitors can undercut you in real time. Credential-stuffing bots test stolen passwords against customer accounts. These bots are harder to catch than ever — a growing share are routed through residential proxy networks to look like ordinary shoppers browsing from home.
APIs and client-side scripts are the soft underbelly of checkout. Each API endpoint and third-party script running in the shopper's browser is a potential entry point. Digital skimming attacks inject malicious code into checkout flows to harvest payment data as customers type. PCI DSS 4.0 now requires controls against client-side script tampering, making this a compliance obligation as much as a security one.
AI agents are arriving — and they are not all adversaries. Nearly half of all page requests to US sites now come from bots. A growing share of that traffic represents potential customers. Block every bot and you possibly block your next sale. Let everything through and you are exposed to every threat above.
The threat landscape is only half the story. How customers find and choose merchants is changing, fast.
A growing number of purchases start with a question to an AI assistant — not a search query. The decision happens inside the model's response, before a human ever sees a homepage. The sites that are easy for agents to find, read, and trust are the ones that get recommended. Just like early SEO, the bar is still low and the first movers have a real edge.
Cloudflare's Agent Readiness diagnostics scan your site the way an agent reads it: Can it get in? Can it discover your content? Can it fetch a clean, machine-readable version? Every check comes back pass, fail, or neutral — grouped by effort so you know where to start, from quick wins like a clean robots.txt and Markdown for Agents to advanced integration with MCP and emerging agent protocols.
Then there is the question readiness alone cannot answer: are AI assistants actually recommending you? Answer Engine Optimization (AEO) probes the leading models with real-world customer prompts in your category and measures what comes back — your Citation Rate, Mention Rate, Prominence, and Share of Voice against competitors. If agents mention your brand but do not cite your site, you are on their radar but not earning the recommendation. That is a specific, targetable gap.
“Understanding what that incoming traffic actually does is crucial, especially when deciding to let through automated traffic that is still commerce relevant. We see excellent results using Cloudflare bot prevention tools — every year we see a consistent increase in threat intensity, but regular Cloudflare updates mitigate complex new threats as they come up.”
Always-on, in-line protection backed by a network large enough to handle multi-terabit floods is the only viable defense when attacks end in seconds. Cloudflare's autonomous DDoS systems run across a 500 Tbps network spanning 330+ cities — the 31.4 Tbps record was detected and blocked without human intervention.
DDoS ProtectionA branded virtual waiting room holds peak traffic in an orderly queue during flash sales and product drops, keeping checkout stable instead of crashing under the rush.
Waiting RoomMachine-learning-based bot scoring evaluates every request against behavioral signals and threat intelligence. Continuous session-level analysis — such as Cloudflare's Precursor engine — watches how visitors behave across an entire session, catching automation that can pass a single challenge but cannot sustain realistic behavior over time. For trusted AI agents, cryptographic verification through Web Bot Auth confirms identity at the protocol level.
Bot Management + BotBase + Business Insights DashboardFirewall rules tuned for holiday patterns — promo code abuse, card testing, rapid account creation — catch malicious requests before they reach your application. A frictionless challenge like Turnstile confirms real users at login and checkout without CAPTCHAs.
WAF + TurnstileDiscover every API your checkout depends on, validate requests against expected schemas, and rate-limit abuse. On the client side, lock down third-party scripts to prevent digital skimming at the point of payment.
API Shield + Page ShieldMake sure your catalog is discoverable by the AI agents that are starting to drive real purchasing decisions. Check your agent readiness, measure your AEO, and serve clean machine-readable content.
Agent Readiness AssessmentStrategies for preparing digital infrastructure for holiday shopping peaks in the midst of evolving threats, from ransomware attacks to API vulnerabilities.
Watch webinar ›Your comprehensive guide to achieve retail holiday success across: performance, security, data access, and omnichannel experience.
Download ebook ›Get actionable insights and tips to protect your business and customers this holiday season.
Read article ›