Sony Pixel Power calrec Sony

Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually

18/09/2024

Facebook

Twitter

LinkedIn

API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally

Bot-related security incident count rose 88% in 2022 and 28% in 2023

Insecure APIs result in up to $12 billion more in losses than they did in 2021

@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.

The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.

Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.

Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.



It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.

Some of the key trends identified in the report include:

Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.



Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.



API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.



Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.



Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.

Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.



Additional Information:

Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.

See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
LINK: https://www.thalesgroup.com/en/worldwide/defence-and-security/press_re...
See more stories from thales

Europe Stories

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

17/03/2026

How Fresh Finds Africa Propelled Rapper Zaylevelten to a Breakout Year

Fresh Finds Africa spotlights emerging artists and movements across the continent and its global diaspora, with listeners tuning in to discover new Afro-forward...

17/03/2026

Spotify Sparked Viral Moments at G27: genie fest, Driving the Discovery of Thai Rock

Last month, more than 60,000 fans piled into Bangkok's Rajamangala National ...

17/03/2026

Black Rooster Audio release VWB-1X

Vintage-inspired channel strip joins line-up Black Rooster Audio's latest plug-in provides an all-in-one mixing tool inspired by classic analogue consol...

17/03/2026

Accentize unveil dxSplit

Level and EQ voice, reverb and noise independently The latest plug-in to join Accentize's collection is said to take a new approach to dialogue processi...

17/03/2026

RF Spectrum Threat: OFCOM Survey

UHF radio mic & IEM bandwidth at risk Once again, the UHF bandwidth that is currently allocated to RF audio gear is at risk of being reassigned to high-spee...

17/03/2026

SGL Carbon hosts Bavaria's first pilot training course for prospective plant fire department squad leaders

Last Friday, the first Plant Fire Department Training Week in Bavaria successf...

17/03/2026

SES Launches Cash Tender Offer

THIS ANNOUNCEMENT RELATES TO THE DISCLOSURE OF INFORMATION THAT QUALIFIED OR MAY HAVE QUALIFIED AS INSIDE INFORMATION WITHIN THE MEANING OF ARTICLE 7(1) OF THE ...

17/03/2026

VEON Strengthens Leadership Team to Accelerate Digital Ambition

17 Mar 2026 VEON Strengthens Leadership Team to Accelerate Digital Ambition Senior executive appointments are to enhance country operations and VEON Group'...

17/03/2026

Sam Tewungwa Appointed CEO of UKTV

UKTV today announces the appointment of Sam Tewungwa as Chief Executive Officer, who will lead the company's next phase of growth. Tewungwa, currently Mana...

17/03/2026

Disney+ included in the Sky TV subscription from today, bringing customers more of the best entertainment in one place

Tuesday 17 March 2026 Disney included in the Sky TV subscription from today, b...

17/03/2026

First look: Gugu Mbatha-Raw stars in Sky Original supernatural thriller Possession

The five-part thriller, formerly known as Inheritance, also stars Jonny Lee Mill...

17/03/2026

Sky Arts welcomes Fearne Cotton as co-host of Landscape Artist of the Year

Tuesday 17 March 2026 Sky Arts welcomes Fearne Cotton as co-host of Landscape Artist of the Year Sky Arts' much-loved Landscape Artist of the Year is set ...

17/03/2026

Ella Purnell returns as wallflower-turned-killer in Sky Original Sweetpea

Season 2 of the darkly comic thriller will launch on Sky in 2026Tuesday 17 March 2026 Ella Purnell returns as wallflower-turned-killer in Sky Original Sweetpea...

16/03/2026

Cloudvocal launch the SonoFlex instrument mic

Promises studio-grade fidelity for the stage Cloudvocal have announced the launch of a new instrument mic designed for professional live performers and engi...

16/03/2026

Kenton reveal the USB Solo Mk2

Popular MIDI/CV converter & interface overhauled Kenton have announced the launch of the USB Solo Mk2, a new and improved version of their compact MIDI to C...

16/03/2026

Sonarworks Spring Sale

Running from 16-29 March 2026 Starting from today (16 March) and running until 29 March 2026, Sonarworks are offering discounts of up to 40% across their ra...

16/03/2026

aconnic ramping up delivery of commercial 100-gigabit system

aconnic AG (ISIN: DE000A0LBKW6), Munich, is delivering the first commercial 100-Gigabit systems following successful validation and certification for customer n...

16/03/2026

VEON Files its 2025 Annual Report on Form 20-F

16 Mar 2026 VEON Files its 2025 Annual Report on Form 20-F Dubai and New York, March 16, 2026 - VEON Ltd. (Nasdaq: VEON), a global digital operator ( VEON'...

16/03/2026

Sky Commissions The 100 Day Split, A New Relationship Series Exploring What Time Apart Reveals About Lifelong Love

Six Couples. 100 Days Apart. One Question: Does Absence Make the Heart Grow Fond...

16/03/2026

Tina Fey, Jamie Dornan and Riz Ahmed announced as first three hosts of Saturday Night Live UK

Monday 16 March 2026 Tina Fey, Jamie Dornan and Riz Ahmed announced as first th...

16/03/2026

All UK national newspapers move to private circulation reporting while remaining audited by ABC

The reporting option was introduced following extensive consultation with publis...

16/03/2026

Rose of Tralee Katelyn Cummins wins Dancing with the Stars 2026

After a nail-biting Grand Finale, Rose of Tralee Katelyn Cummins has been announced as the winner of Dancing with the Stars 2026. The four finalists each dance...

16/03/2026

New RT series Welcome to Moore Street gives a glimpse into life on iconic Dublin street

Welcome to Moore Street will begin on RT One and RT Player on Thursday 19 Marc...

15/03/2026

Visit ToolsOnAir at NAB Las Vegas 2026

Visit ToolsOnAir at NAB Las Vegas 2026 More Details:From April 19-22, join us at NAB Show Las Vegas in the North Hall, Booth N1258, for an exclusive preview of...

15/03/2026

Outland III from The Very Loud Indeed Co.

Latest dark drama, thrillers & tension library announced The Very Loud Indeed Co.'s latest Kontakt library has just arrived, delivering a third instalme...

14/03/2026

HISONG announce the AirStudio S1

Combines mic, USB interface & wireless IEMs Following a successful Kickstarter campaign, HISONG have announced that their innovative AirStudio S1 device is ...

13/03/2026

A New Era of Personalization: Shape Your Taste Profile on Spotify

Spotify has always been built around your taste. More than 80% of listeners say personalization is what they love most about us. Now we're taking that even ...

13/03/2026

Spotify Debuts Legends Club for Popular German-Language Podcasts With Kaulitz Hills'

The new Spotify Legends Club has opened its doors. Its members: select German-sp...

13/03/2026

Klevgrand release OneShot2

Pushing drum sampler technology into new territories The latest version of Klevgrand's software drum sampler has just arrived, boasting a newly designe...

13/03/2026

IK Multimedia update ARC On-Ear

Expanded headphone support & engine improvements IK Multimedia's recently introduced ARC On-Ear system brings the power of their monitoring-correction s...

13/03/2026

UVI introduce Mosaiq 26

Extra sound collections, more presets & new Keys category UVI's rhythm and pattern instrument has just received a major update that introduces four new ...

13/03/2026

VEON Delivers Record Digital Growth: 4Q25 Digital Revenues Grow 84% to 20.1% of Total, Driving 17% Revenue and 29% EBITDA Growth in 4Q25

13 Mar 2026 VEON Delivers Record Digital Growth: 4Q25 Digital Revenues Grow 84%...

13/03/2026

Sky Adds Blood on Snow to Original Film Slate in Acquisition Headlined by Benedict Cumberbatch and Aaron TaylorJohnson

Friday 13 March 2026 Sky Adds Blood on Snow to Original Film Slate in Acquisiti...

13/03/2026

RT announces Rick O'Shea as new presenter on RT Radio 1's Arena

RT has announced today that Rick O'Shea is the new presenter of Arena RT Radio 1's flagship weeknight arts and culture programme. Rick has been pres...

13/03/2026

Lights! Camera! Action! The 98th Oscars set to air live as RT backs the Irish nominees

Lights! Camera! Action! The 98th Oscars set to air live as RT backs the Irish n...

12/03/2026

Milano Cortina 2026: Yospace helps ad-funded rights-holders claim advertising gold

Staines-upon-Thames, UK, 11th March, 2026 - Yospace, the trusted leader in Dyna...

12/03/2026

Mon Laferte Leads All-Women Spotify Session as EQUAL Celebrations Kick Off in Latin America

In Latin America, women are shaping music and defining its future. To kick off t...

12/03/2026

Mon Laferte lidera la edicin EQUAL de Spotify Sessions, mientras comienzan las celebraciones de EQUAL en Latinoamrica

En Am rica Latina, las mujeres est n moldeando la m sica y definiendo su futuro....

12/03/2026

As Spotify Turns 20, the Most Global and Diverse Music Industry in History Has Taken Shape

Let's turn back the clock 20 years: The music landscape was a world away fro...

12/03/2026

Bad Bunny Brings the Sounds of Puerto Rico to Tokyo for Spotify's Billions Club Live

Bad Bunny is no stranger to Spotify's Billions Club. In fact, he has a whopp...

12/03/2026

At the London Book Fair, Spotify Shares Our Vision for the Future of Reading

Spotify was at the London Book Fair this week, joining conversations across the publishing industry about how people can make reading part of their daily lives....

12/03/2026

Ohlhorst Digital & Tokyo Dawn Labs launch Ancora

Mastering tool improves mono compatibility Tokyo Dawn Labs' Ohlhorst Digital range is a series of mastering-focused plug-ins developed by Jan Ohlhorst, ...

12/03/2026

Lewitt partner with Elgato

Wave FX processor integrated into four products Lewitt have teamed up with Elgato to create a new processor for the company's Wave Next product range, i...

12/03/2026

Mix Notes iOS App by David Thomas

Free tool for annotating audio files Mix Notes is a new, free iOS App that provides users with a simple way to annotate their audio files. It's been cre...

12/03/2026

Duck 2 from Devious Machines

Side-chain ducking tool gets an upgrade Devious Machines' popular side-chaining and envelope-shaping tool has just been kitted out with an improved enve...