Online gaming, particularly iGaming, has been a massive target for malicious bots for years because of poor bot management.
In 2025, gaming experienced a surge in bad bot traffic of 62%, making gaming the industry with one of the highest proportions of automated bot attacks. From weak security systems to endless sensitive customer information, including financial details, and potentially millions in real-money transactions, gaming platforms are a huge target.
After a recent study released by DataDome, compiled after they partnered with an online gaming platform and found security weaknesses and fraudulent bot behavior wreaking havoc across the platform, we wanted to explore how poor bot management impacts gaming companies. Read on to find out more.
Key Takeaways
- iGaming faced a 62% increase in bad bot traffic in 2025, making it vulnerable to various fraud risks.
- Poor bot management allows malicious bots to exploit weaknesses, leading to account takeovers and financial losses.
- DataDome’s study showed significant fraud missed by previous bot protection, flagging thousands of fraudulent attempts that went undetected.
- Effective bot management should analyze user behavior throughout the gaming lifecycle rather than just endpoints.
- Regularly testing bot management systems is crucial; what goes undetected poses a substantial risk to gaming companies.
Table of contents
Why Bot Management Protection Matters for Gaming Companies
Online gaming platforms can be a sitting duck for malicious bots because they typically store real money, payment details, promotional credits, and sensitive customer information. Bots target multiple stages of the customer journey, from login to withdrawals and gaming/platform APIs and pose risks for fake account creation, account takeovers, fraud, and so much more.
DataDome, which was recently named a leader in The Forrester Wave™: Bot And Agent Trust Management Software, Q2 2026 report, says the real-money gaming platform it studied was dealing with:
- Credential stuffing
- Account takeover and payment fraud
- Promotional and referral bonus abuse
- Automated scraping of proprietary platform data
That proves that poor detection can translate directly into fraudulent withdrawals, bonus losses, compromised accounts, payment disputes, and operational costs.
Before DataDome, the company believed it had high-level security layers, including:
- Layer 1: CDN-based bot management solution
- Layer 2: A bot management vendor (they called them ‘Vendor X’) deployed in full protection mode.
- Layer 3: Manual fraud review by their security team, supplementing automated detection with custom rules.
The issue was that sophisticated, multi-stage fraud operations, including account takeovers and deposit fraud, had been allowed through from a previous security vendor.
So for gaming companies, bot management protection matters for everything from preventing fraud to protecting the entire customer journey.
How Incorrect Bot Management Impacts Gaming Companies
False negatives cause the biggest risk, which is when malicious bots are classified as legitimate users and are allowed to pass through.
In DataDome’s gaming example, the security team had to create manual rules to compensate for what its incumbent bot vendor was missing. That increases workload and makes protection difficult to scale.
Account takeover can follow when credential-stuffing bots successfully test stolen username/password combinations. Accounts containing balances or payment information make gaming platforms particularly valuable targets.
Promo abuse can also become expensive at scale. DataDome observed fraud rings creating accounts, using referral codes and free promotional credits, making the minimum required deposit, and then quickly withdrawing the funds.
What DataDome Found When Existing Bot Protection Failed
DataDome was deliberately installed after the gaming company’s CDN bot protection and incumbent bot-management vendor. That meant they only examined approximately 75% of traffic those systems had already approved. The test ran for two weeks, and despite seeing already-approved traffic, DataDome reported substantial additional fraud:
- Registration: flagged 120,000 requests from traffic that Vendor X had allowed.
- Deposits: DataDome flagged 700,000 fraudulent attempts, around 27x more than Vendor X.
- Withdrawals: DataDome flagged 150,000 fraudulent attempts, compared with 4,000 blocked by Vendor X. That worked out to around 37x more.
It’s not that one vendor found more bots. It’s that having bot protection installed doesn’t guarantee sophisticated fraud is being detected. As DataDome argues, gaming companies need to measure what their bot-management solution is actually missing rather than assuming that traffic allowed through an existing solution is legitimate.
What Effective Bot Management Protection Should Look Like
Effective bot management should assess behavior across the full gaming lifecycle, from registration to play and withdrawal. Protecting individual endpoints essentially does nothing.
Signal can then correlate using device fingerprints, IP/network information, session history, payment actions, and timing. Following those signals, it’s then easy to track behavioral intent, especially unusual sequences such as immediate login attempts without prior activity or rapid deposit-to-withdrawal behavior.
In its case study, DataDome used the customer’s device and user-journey data to create specific detection rules. That proves that regularly testing an incumbent solution is more effective than judging its effectiveness purely from the number of attacks it reports blocking.
What’s most valuable from DataDome’s case study is that the more important question can be what is still being allowed through. Poor bot management can create a massive security issue for online gaming companies, and through the DataDome study, it’s evidence that even what appears to be a high-level security setup may not be enough to stop malicious bots.
Read Next
A few related pieces worth your time:
- Is MetaMask Safe in 2026? Security, Risks & How to Protect Your Crypto
- The Role of Identity Management in Modern Technology
- Traditional Antivirus to EDR: How to Start Protecting Your Endpoints











