Web was locked down. The attackers pivoted to the mobile-app API.
Mid-size international airline · Web channel fully covered by Cloudflare WAF, Turnstile, and Bot Management, clean traffic, healthy conversion. The attack moved to the native iOS / Android app's API, where a CAPTCHA can't realistically run.
AI-based bot scoring is now the baseline for high-yield travel APIs.
Airlines and online travel agencies face some of the most persistent and sophisticated bot activity of any industry. Temporary-booking abuse, credential stuffing on loyalty accounts, and fare-scraping are three distinct threat families that all share one property: they are operationally harmless on their own but together distort pricing, revenue management decisions, and conversion analytics. Bot Shield's LOG-mode-first deployment approach lets a carrier build an evidence base before any enforcement decision, and the JA3/JA4 mobile-fingerprint layer is what makes the airline channel actionable without a CAPTCHA.
Seeing similar patterns on your mobile or API channel?
Bot Shield deploys in LOG mode first: no traffic impact, no CAPTCHA friction. Four weeks of evidence before any enforcement decision.