An AI Crawler Treated a Missing robots.txt as Consent and Crashed a Seven-Person Company
What happened
Triplegangers is a seven-person Ukrainian company that sells digital assets to video game developers and artists: high-resolution product images and detailed 3D references built up over years of careful production work. In January 2025, the company's website went down. The cause was not a cyberattack or a hardware failure but a data-collection bot that had decided, without asking, to download everything the company had published online.
The bot arrived from over 600 different IP addresses, a distribution that made the traffic pattern look indistinguishable from a coordinated denial-of-service attack. Its apparent objective was to pull hundreds of thousands of product images along with detailed descriptions for more than 65,000 items. The volume of requests overwhelmed Triplegangers' servers and drove up its Amazon AWS bandwidth costs in ways a company of seven people cannot absorb as a routine line item. CEO Oleksandr Tomchuk described the effect as a DDoS attack in practical terms, even though no malicious actor had aimed it.
The source of the problem, as Tomchuk reconstructed it, was a configuration gap in Triplegangers' robots.txt file, the industry-standard mechanism a website uses to declare what crawlers may and may not access. The file had not been properly set up. The bot interpreted the absence of an explicit restriction not as ambiguity but as permission, and continued pulling at full speed. That interpretation placed the entire responsibility for protection on the website owner and none of it on the system conducting the harvest.
Tomchuk's attempts to get answers from the company operating the bot produced little. He could not determine why Triplegangers had been targeted, whether the scraped content would be retained or deleted, or what recourse was available. Larger organizations with legal departments and dedicated infrastructure teams can configure layered bot defenses and escalate through formal channels. A seven-person operation with a crashed site and a swelling AWS bill cannot. The incident made visible a structural asymmetry: a crawler with effectively no observable ceiling on its appetite, and a small business with no practical way to stop it or demand accountability after the fact.
What Triplegangers was left with after the disruption is a documentation problem with lasting consequences. There is no verified record of exactly what was taken, when the collection began, or what it will be used to train or build. No obligation existed on the other side to produce such a record. A provable account of what a system collected, under what authority, and from which sources would have changed the situation at every stage: before the crawl began, during it, and in the dispute that followed. Without that record, any business whose content sits on the public internet is exposed to the same outcome, with no audit trail and no path to remedy.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.