
Akamai Security Research: APIs Are Now Target of Choice for Cybercriminals Attacking Financial Services Organizations Up to 75% of all Credential Abuse Attacks Targeted APIs
Cambridge, MA | February 19, 2020
Akamai Technologies, Inc. (NASDAQ: AKAM) today published the Akamai 2020 State of the Internet / Security: Financial Services - Hostile Takeover Attempts report. The research findings reveal that from May 2019 and continuing on until the end of the year, there was a dramatic shift by criminals who started targeting APIs, in an effort to bypass security controls. According to data from Akamai, up to 75% of all credential abuse attacks against the financial services industry targeted APIs directly.
According to the report's findings, from December 2017 through November 2019, Akamai observed 85,422,079,109 credential abuse attacks. Nearly 20 percent, or 16,557,875,875, were against hostnames that were clearly identified as API endpoints. Of these, 473,518,955 attacked organizations in the financial services industry.
But not all attacks were exclusively API focused. On August 7, 2019, Akamai recorded the single largest credential stuffing attack against a financial services firm, in our companys history, consisting of 55,141,782 malicious login attempts. This attack was a mix of API targeting, and other methodologies. On August 25, in a separate incident, the criminals targeted APIs directly, in a run that consisted of more than 19 million credential abuse attacks.
Criminals are getting more creative and hyper-focused on how they go about obtaining access to the things they need to conduct their crimes, said Steve Ragan, Akamai security researcher and principal author of the State of the Internet / Security report. Criminals targeting the financial services industry pay close attention to the defenses used by these organizations, and adjust their attack patterns accordingly.
Indicative of this fluid attack dynamic, the report shows that criminals continue to seek to expose data through a number of methods, in order to gain a stronger foothold on the server and ultimately achieve success in their attempts.
SQL Injection (SQLi) accounted for more than 72% of all attacks when looking at all verticals during the 24-month period observed by the report. That rate is halved to 36% when looking at financial services attacks alone. The top attack type against the financial services sector was Local File Inclusion (LFI), with 47% of observed traffic.
LFI attacks exploit various scripts running on servers, and as a consequence, these types of attacks can be used to force sensitive information disclosure. LFI attacks can also be leveraged for client-side command execution (such as a vulnerable JavaScript file), which could lead to Cross-Site Scripting (XSS) and Denial of Service (DoS) attacks. XSS was the third-most common type of attack against financial services, with a recorded 50.7 million attacks, or 7.7% of the observed attack traffic.
The report also shows that criminals continue to leverage Distributed Denial of Service (DDoS) attacks as a core component of their attack arsenal, particularly as it relates to targeting financial services organizations. Akamai's observations from November 2017 until October 2019, show the financial services industry ranking third in attack volume, with gaming and high tech being the most common targets. However, more than forty percent of the unique DDoS targets were in the financial services industry, which makes this sector the top target when considering unique victims.
Security teams need to constantly consider policies, procedures, workflows, and business needs - all while fighting off attackers that are often well organized and well-funded, Ragan concluded. Our data shows that financial services organizations are constantly improving by adopting fluid security postures, forcing criminals to change their tactics.
The Akamai 2020 State of the Internet / Security Report is available here. In addition, Akamai will be conducting a webinar on Thursday, February 20 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.
For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
03/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
03/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
03/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
03/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
03/02/2026
Berklee Alumni Recognized at the 2026 Grammy Awards Winners took home trophies in nine categories, including Best Traditional Pop Vocal Album and Songwriter o...
02/02/2026
SBS's High-Flying Drama The Airport Chaplain casts Hugo Weaving alongside Th...
02/02/2026
The National Film and Video Foundation (NFVF), in partnership with the French Institute of South Africa (IFAS), is calling for applications from experienced Sou...
02/02/2026
Photo Credit: NASA. Space Launch System (SLS) rocket and Orion Spacecraft rollou...
02/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/02/2026
Hewshott, an industry leading global AV, IT, Theatre, and Acoustics consultancy firm has completed a global transition with current UK Managing Director, Daniel...
02/02/2026
Public Media Management (PMM) today announced LTN as the technology partner for PMM Cloud, its new managed, cloud-based master control solution purpose-built fo...
02/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/02/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/02/2026
XR, the leading platform powering advertising operations, today announced the acquisition of Telly Traffic, a UK-based business affairs specialist with nearly t...
02/02/2026
Big Blue Marble, a provider of broadcast-grade, cloud-native video solutions for broadcasters, service providers, and content owners, has become a launch partne...
02/02/2026
February 2 2026, 20:30 (PST) Mahindra launches XUV 7XO as Indias first vehicle ...
02/02/2026
Teaser available to view HERE
Damien Molony as Jim Bergerac
Ahead of the hotly anticipated return of Bergerac to U and U&DRAMA in the Spring, a teaser has bee...
02/02/2026
Rohde & Schwarz reshapes mid-range market with new 44 GHz FPL spectrum analyzer ...
02/02/2026
Back to All News
Cesc Gays New Film Premieres March 27 on Netflix
Entertainment
02 February 2026
GlobalSpain
Link copied to clipboard
Download the first i...
02/02/2026
In addition to DPA Microphones, the company will also be acquiring Wisycom and Austrian Audio. The acquisition is now being filed for regulatory approval and sh...
02/02/2026
Arvato Systems launches a flexible and standardized billing solution
New SAP S/4HANA Utilities master system combines standardization, economies of scale, and...
31/01/2026
Spotify's annual Best New Artist celebration returned to Los Angeles last ni...
31/01/2026
The Navy's Air Test and Evaluation Squadron (HX) 21 launch a Long Range Attack Missile from an AH-1Z off coast of Virginia in late 2025. This demonstration ...
31/01/2026
DigitalGlue, creator of the award-winning creative.space Platform, has announced the release of creative.space OS 3.0.5, the latest software update within the ...
31/01/2026
ES Broadcast Hire, the long-established hire arm of ES Media Group, has spent the last few months busily preparing and sending out high-quality equipment for a ...
31/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
31/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
31/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
31/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
30/01/2026
Top L-R: The Friend's House is Here, Josephine, The Lake, Bedford Park, Who Killed Alex Odeh?
Second Row L-R: Take Me Home, American Pachuco: The Legend of...
30/01/2026
Spotify, Haziran ay sonunda kadar stanbul'da yeni bir ofis a aca n ve T rkiye pazar n y netmek zere yeni bir atama ger ekle tirdi ini duyurdu. Bu kaps...
30/01/2026
The Artemis II wet dress rehearsal will simulate the launch countdown, fully loading fuel and verifying systems ahead of the first SLS and Orion crewed flight....
30/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
30/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
30/01/2026
Grass Valley , the leading technology provider for live production solutions, and NETGEAR Inc. (NASDAQ: NTGR), a global leader in network solutions, today anno...
30/01/2026
tvONE, a leading video processor, signal distribution technology and media server developer, announces the expansion of Amit Singh's role to Regional Sales ...
30/01/2026
With a career that spans four decades across television, film and post-production, Freelance Sound Designer and Post-production Sound Mixer Mike Aiton has built...
30/01/2026
DPA Microphones will feature its new, fully integrated wireless microphone ecosystem, designed to let audio professionals work faster, cleaner and with total co...
30/01/2026
As the Middle East continues to accelerate investment in next-generation media, broadcast, and immersive content technologies, Ventum Tech today announced a str...
30/01/2026
Mark Roberts Motion Control (MRMC), a Nikon company and global leader in robotic camera systems, today announced its participation at Integrated Systems Europe ...
30/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
30/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
30/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
30/01/2026
Share Share by:
Copy link
Facebook
X
Linkedin
Bluesky
Email...
30/01/2026
Boston Conservatory at Berklee Hosts the National Opera Association's 2026 C...