Sony Pixel Power calrec Sony

Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually

18/09/2024

Facebook

Twitter

LinkedIn

API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally

Bot-related security incident count rose 88% in 2022 and 28% in 2023

Insecure APIs result in up to $12 billion more in losses than they did in 2021

@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.

The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.

Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.

Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.



It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.

Some of the key trends identified in the report include:

Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.



Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.



API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.



Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.



Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.

Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.



Additional Information:

Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.

See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
LINK: https://www.thalesgroup.com/en/worldwide/defence-and-security/press_re...
See more stories from thales

Europe Stories

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

19/03/2026

Spotify Marks 5 Years of EQUAL With EQUAL: The Podcast and Global Events

In 2021, we launched EQUAL, a program designed to address an industry reality that persists: Women artists, songwriters, and producers too often face fewer oppo...

19/03/2026

Toontrack release Transistor Organ EKX

Latest EZKeys 2 expansion arrives Toontrack's staggering collection of EZKeys 2 expansions has grown once again, and the latest instalment delivers a on...

19/03/2026

Roland preview Melody Flip

New generative AI plug-in due in May 2026 Roland have announced the upcoming launch of a new generative AI tool created in collaboration with Sony Computer ...

19/03/2026

Native Instruments CEO Statement

Nick Williams updates users on insolvency process Nick Williams, the CEO of Native Instruments, has released the following official statement regarding thei...

19/03/2026

Milab to restart production

Iconic Swedish mic manufacturer back in action Legendary Swedish microphone manufacturer Milab have announced that production is now fully underway, and mic...

19/03/2026

FT1-EMU plug-in from Freqport

Acclaimed saturation unit goes virtual Freqport's Freqtube FT1 (reviewed here in SOS February 2023) offers a convenient way to integrate real valve-base...

19/03/2026

SGL Carbon: Restructuring ensures earnings forecast and creates basis for new growth

The discontinuation of loss-making business activities as part of the restructur...

19/03/2026

Sky TV customers can enjoy a taste of Hayus most popular reality shows from today

Thursday 19 March 2026 Sky TV customers can enjoy a taste of Hayu's most po...

19/03/2026

Foo Fighters' Other Voices performance to air on RT this Easter Monday

Other Voices presents a legendary night of music as Foo Fighters bring their stadium anthems to St James' Church, An Daingean. The surprise performance teas...

19/03/2026

RTS Ireland Awards / Gradaim RTS 2026 Shortlist Announced

***Issued by RT on behalf of RTS Ireland Awards / Gradaim RTS 2026...

18/03/2026

Music Row Piano from Wiltone Productions

Yamaha C7 captured in Nashville Wiltone Productions have announced the release of Music Row Piano, a deeply sampled Yamaha C7 piano library that's been ...

18/03/2026

Techivation introduce T-Warmer Mk2

Bass-enhancement plug-in upgraded Along with a steady stream of new releases, Techivation have recently been revisiting some of the older plug-ins in their ...

18/03/2026

Tonal Balance Control 3 from iZotope

Mix-reference plug-in overhauled iZotope's powerful mix-referencing plug-in has just reached its third major version, and now boasts a new capture proce...

18/03/2026

Toontrack Transistor Organ EKX

Latest EZKeys 2 expansion arrives Toontrack's staggering collection of EZKeys 2 expansions has grown once again, and the latest instalment delivers a on...

18/03/2026

Future-ready broadcasts with ATSC 3.0 and enhanced services from Rohde & Schwarz at NAB 2026

Future-ready broadcasts with ATSC 3.0 and enhanced services from Rohde & Schwarz...

18/03/2026

LCTWS 2026

London Calling - When The Industry Convened to Help Streaming Find its MoJo In this blog, Laura Rognoni reflects on key discussions from the Connected TV World...

18/03/2026

SES Announces Extension of Tender Offer

THIS ANNOUNCEMENT RELATES TO THE DISCLOSURE OF INFORMATION THAT QUALIFIED OR MAY HAVE QUALIFIED AS INSIDE INFORMATION WITHIN THE MEANING OF ARTICLE 7(1) OF THE ...

18/03/2026

X-Rite Pantone Demonstrates Advanced Color Management Solutions to Support Smart Manufacturing at MAX and American Coatings Show

X-Rite Pantone Demonstrates Advanced Color Management Solutions to Support Smart...

18/03/2026

BAFTA winner James McAvoy to star in Sky Original series Meantime, based on the novel by Frankie Boyle

Wednesday 18 March 2026 BAFTA winner James McAvoy to star in Sky Original serie...

18/03/2026

Sky Sports and Zuffa Boxing announce multi-year agreement for the UK and Ireland

Wednesday 18 March 2026 Sky Sports and Zuffa Boxing announce multi-year agreement for the UK and Ireland Sky Sports and Zuffa Boxing have announced a new mult...

18/03/2026

Sky Unveils Poster and Trailer for Original Feature Film Shaun the Sheep: The Beast of Mossy Bottom

Wednesday 18 March 2026 Sky Unveils Poster and Trailer for Original Feature Fil...

18/03/2026

UP NEXT: Sky presents a bold slate of new, premium acquired content

Wednesday 18 March 2026 UP NEXT: Sky presents a bold slate of new, premium acquired content Sky reveals slate of newly acquired premium drama and comedy, as i...

18/03/2026

UP NEXT: Sky unveils an unmissable genre-spanning slate of new shows, exclusive previews and first looks for 2026 and beyond

Wednesday 18 March 2026 UP NEXT: Sky unveils an unmissable genre-spanning slate...

18/03/2026

Harmonic Enhances XOS Advanced Media Processor to Streamline Next-Generation Broadcast Distribution

New Playout-to-Delivery Capabilities Elevate ATSC 3.0 Experiences, Lower DTV In...

17/03/2026

How Fresh Finds Africa Propelled Rapper Zaylevelten to a Breakout Year

Fresh Finds Africa spotlights emerging artists and movements across the continent and its global diaspora, with listeners tuning in to discover new Afro-forward...

17/03/2026

Spotify Sparked Viral Moments at G27: genie fest, Driving the Discovery of Thai Rock

Last month, more than 60,000 fans piled into Bangkok's Rajamangala National ...

17/03/2026

Black Rooster Audio release VWB-1X

Vintage-inspired channel strip joins line-up Black Rooster Audio's latest plug-in provides an all-in-one mixing tool inspired by classic analogue consol...

17/03/2026

Accentize unveil dxSplit

Level and EQ voice, reverb and noise independently The latest plug-in to join Accentize's collection is said to take a new approach to dialogue processi...

17/03/2026

RF Spectrum Threat: OFCOM Survey

UHF radio mic & IEM bandwidth at risk Once again, the UHF bandwidth that is currently allocated to RF audio gear is at risk of being reassigned to high-spee...

17/03/2026

SGL Carbon hosts Bavaria's first pilot training course for prospective plant fire department squad leaders

Last Friday, the first Plant Fire Department Training Week in Bavaria successf...

17/03/2026

SES Launches Cash Tender Offer

THIS ANNOUNCEMENT RELATES TO THE DISCLOSURE OF INFORMATION THAT QUALIFIED OR MAY HAVE QUALIFIED AS INSIDE INFORMATION WITHIN THE MEANING OF ARTICLE 7(1) OF THE ...

17/03/2026

Comscore Reports Fourth Quarter and Full Year 2025 Results

Comscore Reports Fourth Quarter and Full Year 2025 Results RESTON, Va., March 17, 2026 - Comscore, Inc. (Nasdaq: SCOR), a trusted partner for planning, transact...

17/03/2026

VEON Strengthens Leadership Team to Accelerate Digital Ambition

17 Mar 2026 VEON Strengthens Leadership Team to Accelerate Digital Ambition Senior executive appointments are to enhance country operations and VEON Group'...

17/03/2026

Sam Tewungwa Appointed CEO of UKTV

UKTV today announces the appointment of Sam Tewungwa as Chief Executive Officer, who will lead the company's next phase of growth. Tewungwa, currently Mana...

17/03/2026

Disney+ included in the Sky TV subscription from today, bringing customers more of the best entertainment in one place

Tuesday 17 March 2026 Disney included in the Sky TV subscription from today, b...

17/03/2026

First look: Gugu Mbatha-Raw stars in Sky Original supernatural thriller Possession

The five-part thriller, formerly known as Inheritance, also stars Jonny Lee Mill...

17/03/2026

Sky Arts welcomes Fearne Cotton as co-host of Landscape Artist of the Year

Tuesday 17 March 2026 Sky Arts welcomes Fearne Cotton as co-host of Landscape Artist of the Year Sky Arts' much-loved Landscape Artist of the Year is set ...

17/03/2026

Ella Purnell returns as wallflower-turned-killer in Sky Original Sweetpea

Season 2 of the darkly comic thriller will launch on Sky in 2026Tuesday 17 March 2026 Ella Purnell returns as wallflower-turned-killer in Sky Original Sweetpea...

16/03/2026

Cloudvocal launch the SonoFlex instrument mic

Promises studio-grade fidelity for the stage Cloudvocal have announced the launch of a new instrument mic designed for professional live performers and engi...

16/03/2026

Kenton reveal the USB Solo Mk2

Popular MIDI/CV converter & interface overhauled Kenton have announced the launch of the USB Solo Mk2, a new and improved version of their compact MIDI to C...

16/03/2026

Sonarworks Spring Sale

Running from 16-29 March 2026 Starting from today (16 March) and running until 29 March 2026, Sonarworks are offering discounts of up to 40% across their ra...

16/03/2026

aconnic ramping up delivery of commercial 100-gigabit system

aconnic AG (ISIN: DE000A0LBKW6), Munich, is delivering the first commercial 100-Gigabit systems following successful validation and certification for customer n...

16/03/2026

VIZ Media Releases Official Teaser Trailer and Key Art For Hirayasumi Anime

VIZ Media Releases Official Teaser Trailer and Key Art For Hirayasumi Anime SAN FRANCISCO, CA March 16, 2026 Leading global manga and anime producer VI...

16/03/2026

VEON Files its 2025 Annual Report on Form 20-F

16 Mar 2026 VEON Files its 2025 Annual Report on Form 20-F Dubai and New York, March 16, 2026 - VEON Ltd. (Nasdaq: VEON), a global digital operator ( VEON'...

16/03/2026

Sky Commissions The 100 Day Split, A New Relationship Series Exploring What Time Apart Reveals About Lifelong Love

Six Couples. 100 Days Apart. One Question: Does Absence Make the Heart Grow Fond...