Traditional security doesn’t see it. Business metrics do.
The attack is invisible to access control. Visible only in outcomes.
The Detection Problem
API1–5 produce observable security signals: 404s for wrong IDs, 403s for wrong roles, 413s for oversized payloads, 429s for rate limit violations. API6 produces none of these. The bots have valid accounts, valid tokens, valid requests, and valid responses. The server is healthy. The logs look normal. The only signal is in business data: inventory gone in milliseconds, referral costs spiking, review counts exploding.
Security teams monitor security metrics — not business metrics
Fraud teams monitor payment fraud — not API flow patterns
Bot mitigation is expensive and requires specialization
Business logic controls require product + engineering alignment
Financial loss can be immediate and large — referral fraud at scale
Reputational damage — Ticketmaster is synonymous with bot failure
Legislative consequences — Congressional hearings on bot abuse
User trust — if real users can’t participate, they leave the platform