How DataDome Stopped a CAPTCHA Farm Behind 18.8 Million Ticket Scalping Attempts
On June 27th, 2026, DataDome detected and blocked a large-scale scalping campaign that hit an online ticketing platform distributing sporting event tickets.
This attack never tried to overwhelm the platform with raw traffic. Instead, it targeted the add-to-cart endpoint, which the platform protects with an interactive slider challenge that every user must complete before reserving inventory—a DataDome feature that customers can configure across different parts of their website. This ticketing platform chose to enable the slider for all checkout traffic.
The scalping operation generated 18.8 million attempts to bypass the slider in roughly 24 hours, every one of them blocked before a single ticket landed in scalper hands.
Behind that volume sat a globally dispersed botnet of 3.2 million IP addresses spanning more than 22,000 autonomous systems, routed through residential and mobile proxies to mirror the traffic of real buyers. The operation was purpose-built: a CAPTCHA farm engineered specifically to defeat the slider challenge at scale, relying on raw challenge-solving throughput rather than brute force.
Below, DataDome’s Galileo threat research team breaks down the attack infrastructure, adversary profile, and detection signals behind this campaign.
Key metrics of the scalping attack
Attack timeline and pace
The attack activity stretched across roughly 24 hours, but was concentrated into four distinct spikes totaling about six hours of sustained pressure. Each spike was aligned with ticket inventory becoming available on the add-to-cart endpoint.
The four-spike cadence is itself a tactical signature. The opening wave was by far the most intense, sustaining 750,000 to 900,000 slider passing attempts every 10 minutes as the operator threw its full challenge-solving capacity at the first inventory release.
The three subsequent waves settled into a lower but still substantial rhythm of roughly 200,000 to 300,000 slider passing attempts per 10 minutes, with the operator falling silent between the bursts to let aggregate rate-limit counters reset while it cycled through its pool of 3.2 million IP addresses.
Even that reduced cadence represents a challenge-solving throughput few farms can sustain.
DataDome blocked the campaign wave after wave, stopping every slider passing attempt before it could secure inventory, all while keeping checkout available to genuine buyers throughout the 24-hour window.

Number of slider passing attempts blocked by DataDome’s detection engine during the attack
Infrastructure

The botnet spanned 3.2 million unique IP addresses across 22,171 autonomous systems—an exceptionally fragmented footprint that makes IP-based blocking ineffective by design. This campaign’s infrastructure shows that the top contributors are the largest consumer ISPs in the United States.
- Comcast Cable Communication: 15.48%
- Verizon Business: 7.62%
- Charter Communication: 7.25%
- T-Mobile USA: 4.11%
- AT&T: 4%
Comcast, Verizon, Charter, T-Mobile, and AT&T are not hosting providers—they are the residential and mobile networks that real ticket buyers connect from. Their dominance, together with the Geonode proxy marker, is the signature of a residential/mobile proxy network: the operator relays its automated traffic through genuine consumer devices and IP space so that each request originates from precisely the kind of address a ticketing platform expects during a high-demand drop.
Geographically, the traffic is anchored in the United States, then spread thinly across South America, Africa, Europe, and pockets of Australia and South Asia. That diffuse spread is the footprint of a large commercial proxy pool, not a targeted regional operation. The unlikely geolocations and negative IP reputation expose the seams in this otherwise well-camouflaged infrastructure.
Adversary profile and sophistication
We rate every campaign on five dimensions of attacker capability, each scored out of 10:
- Stealth: How invisible each individual source is, judged by its request pace. A low, human-like per-IP rate that stays under rate limits scores high.
- Distribution: How widely the traffic is spread across autonomous systems (networks), which determines how ineffective network-level blocking will be.
- Scale: The raw size of the botnet, measured by the number of unique IP addresses in play.
- Evasion: How sophisticated the actor is in impersonating a legitimate browser and defeating detection, from basic header forgery up to full client-side automation and challenge solving.
- Adaptability: How much the actor varies and rotates its fingerprints, sessions, and infrastructure mid-attack to avoid being captured.
Scored against these five dimensions, this campaign reveals a highly capable, purpose-built scalping operation with a clear specialization.
The actor operates a massive, globally dispersed botnet: 3.2 million distinct IPs across more than 22,000 autonomous systems push distribution and scale to the top of the range.
Stealth is high. With millions of sources sharing a modest per-node request budget, each individual IP averages only about 6 passing attempts every hour, far below any plausible per-source rate limit, and indistinguishable from a shopper occasionally refreshing a page.
Evasion is where this actor separates itself from a commodity bot. It reaches the expert tier. Beyond forged headers, cookies and URL parameters, and an inconsistent server-side fingerprint, the operator runs full client-side automation with forged JavaScript execution, spoofed client fingerprints, manipulated execution timings and, most tellingly, an automated challenge solver. That last capability is the crux of the campaign: this is a CAPTCHA farm engineered specifically to defeat the slider challenge protecting the add-to-cart flow.
Adaptability is more modest. The operator does rotate, relying on mobile/residential proxies (a reactive-tier behavior) and some session-sequence variation, but it lacks the deep device, hardware, and environment churn of the most adaptive actors. Its playbook is powerful but largely templated: it wins through sheer challenge-solving throughput rather than dynamic, reactive evasion.


How DataDome detected and stopped the scalping attack
DataDome’s multi-layered detection, combining server-side and client-side fingerprinting, behavioral analysis, and threat intelligence, identified and mitigated the campaign:
Network: Source IPs carry negative reputation scores accumulated from prior malicious activity across DataDome’s global network, and route through residential and mobile proxy infrastructure whose geolocation signals frequently contradict the claimed origin.
Server-side: The bots present themselves as standard browsers, but their server-side fingerprint disagrees, and HTTP headers, cookies, and request parameters show signs of deliberate crafting rather than organic generation.
Client-side: This is the deepest layer of the operation. The traffic is driven by browser automation with browser identity shifting within sessions, implausible JavaScript execution timings, spoofed client fingerprints, forged JS payloads and, decisively, automated challenge solving—the toolchain of a CAPTCHA farm built to pass the slider at scale.
Behavioral: Request sequences bear little resemblance to natural navigation—the synthetic signature of an automation layer generating session flow rather than experiencing it.
Protect your website from scalping attacks with DataDome
Scalping attacks don’t just drain inventory—they hand pricing control to secondary markets and erode the trust of the fans and customers you’re trying to serve.
This campaign is a signal of where these operations are heading: purpose-built CAPTCHA farms with residential proxy infrastructure, designed from the ground up to defeat the specific friction mechanisms protecting your checkout.
The sophistication gap between attackers and traditional defenses is widening. DataDome has several solutions that combat ticket scalping, including Bot Protect and Priority Protect—an intent-aware virtual waiting room that ensures every spot in the queue goes to a real fan, not a bot. Book a demo to learn more.