03 Jul 2026
Akamai's latest security report, Securing the Agentic Storefront: Attacks on Commerce, reveals that bot activity targeting commerce companies in the Asia Pacific region surged 63 percent throughout 2025 — the highest increase of any region globally. The commerce sector alone accounted for 38 percent of all AI-driven bot traffic detected across industries in Asia Pacific during the second half of 2025.
The travel and hospitality sector in Asia Pacific faces greater risk exposure than other regions, driven by fragmented travel platforms, high digital and mobile adoption rates, popular loyalty programs, and seasonal booking surges around regional holidays such as Lunar New Year, Golden Week, Diwali, and year-end holidays. Travel accounted for 22 percent of all web attacks on the commerce sector in the region, with APIs targeted in a quarter of all attacks affecting this sector.
Layer 7 (application-layer) distributed denial-of-service attacks on the commerce sector also rose sharply, with incidents increasing 39 percent, from 260 billion to 361 billion events throughout 2025. Of all Layer 7 DDoS attacks targeting APIs in the commerce sector, retail accounted for the largest share at 51 percent, followed by hospitality at 28 percent and travel at 21 percent.
Reuben Koh, Director of Security Technology and Strategy APJ at Akamai, said Asia Pacific's commerce sector is moving quickly toward a more automated, AI-driven future as businesses leverage GenAI chatbots to personalize customer experiences and reduce friction. Every chatbot interaction, booking flow, and loyalty program integration creates a new digital surface that must be mapped and protected — particularly for the travel and hospitality sectors, whose exposure is higher due to fragmented platforms and seasonal traffic spikes.
Although Akamai's official regional statement does not specifically name Indonesia, the country remains Southeast Asia's largest e-commerce market, with annual online shopping moments such as Harbolnas on December 12, as well as surges in ticket and accommodation bookings ahead of the Lebaran homecoming (mudik) period. Both periods fall into the category of seasonal traffic surges that Akamai identifies as high-risk windows for the retail and travel sectors.
Akamai recommends that cybersecurity resilience in the commerce sector evolve beyond a purely security function into a comprehensive business discipline. Companies need to map their revenue chains by continuously identifying the APIs that support payments, loyalty programs, purchase flows, inventory, and partner integrations, while understanding the points that could expose sensitive data. Risk-based automation governance is also essential — an approach that moves beyond blanket "allow" or "block" decisions toward distinguishing legitimate automation from malicious bot activity. Building capacity ahead of peak traffic periods, through DDoS response plan testing and credential exposure monitoring, is also a key part of this strategy.
For retail companies, travel platforms, and hospitality providers in Indonesia evaluating their digital resilience ahead of peak traffic periods like Harbolnas or the mudik season, Perkom, as an Akamai partner, is ready to help with risk mapping and strengthening cybersecurity strategy tailored to each business's needs.
Author: Ghea Devita
Marketing Communication PT Perkom Indah Murni