Sony Pixel Power calrec Sony

Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually

18/09/2024

Facebook

Twitter

LinkedIn

API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally

Bot-related security incident count rose 88% in 2022 and 28% in 2023

Insecure APIs result in up to $12 billion more in losses than they did in 2021

@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.

The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.

Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.

Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.



It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.

Some of the key trends identified in the report include:

Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.



Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.



API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.



Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.



Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.

Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.



Additional Information:

Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.

See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
LINK: https://www.thalesgroup.com/en/worldwide/defence-and-security/press_re...
See more stories from thales

Europe Stories

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

21/03/2026

MPG announce new Impact Award

Presented to War Child UK's HELP(2) project The MPG (Music Producers Guild) have announced the launch of the MPG Impact Award, a brand-new honour that w...

21/03/2026

Eduardo Tarilonte's Ancient ERA Persia from Best Service

Microtuning support for Arabic, Persian & Turkish scales The latest release from Best Service brings together a selection of string, wind and percussion ins...

20/03/2026

Spotify Marks 5 Years of EQUAL With EQUAL: The Podcast' and Global Events

In 2021, we launched EQUAL, a program designed to address an industry reality that persists: Women artists, songwriters, and producers too often face fewer oppo...

20/03/2026

Spotify's BTS Music Quiz Celebrates ARIRANG' and Puts ARMY Knowledge to the Test

BTS' long-awaited fifth studio album, ARIRANG, is finally here. To celebrate...

20/03/2026

Spotify and Kenia Os Bring K de Karma' From Streaming to Stage With Fan-First Experiences

A new era for Kenia Os has arrived, and Spotify marked the moment by putting fan...

20/03/2026

Spotify y Kenia Os llevan K de Karma' del streaming al escenario con experiencias nicas para Top Fans

Una nueva era para Kenia Os ha llegado, y Spotify marc el momento poniendo a lo...

20/03/2026

Sound Magic launch Supreme Drums Orange

Combines sampling & physical modelling Sound Magic have announced the launch of a comprehensive virtual drum instrument that's been designed to cater to...

20/03/2026

Mix Rescue: Ian Shepherd Video

How much difference should mastering make? In our latest Mix Rescue feature, SOS Editor in Chief Sam Inglis revisits a project from back in 2019, carrying o...

20/03/2026

London Calling - When The Industry Convened to Help Streaming Find its MoJo

In this blog, Laura Rognoni reflects on key discussions from the Connected TV World Summit in London, where NAGRAVISION hosted a panel on content discovery and ...

20/03/2026

RT's Suzanne Kelly to receive the 2026 Murakami Award at Animation Dingle

Dingle, Co. Kerry - Animation Dingle is delighted to announce that Suzanne Kelly, Head of Children's and Young People's Content at RT , will receive the...

20/03/2026

Sky Extends Saturday Night Live UK Run to Eight Shows

Friday 20 March 2026 Sky Extends Saturday Night Live UK Run to Eight Shows Ahead of Saturday Night Live UK's launch tomorrow (March 21), Sky has confirmed...

20/03/2026

It's time to play The Money List! Baz Ashmawy is back at the helm as the quiz returns for a fourth season

It's time to play The Money List! Baz Ashmawy is back at the helm as the qui...

19/03/2026

Spotify Marks 5 Years of EQUAL With EQUAL: The Podcast and Global Events

In 2021, we launched EQUAL, a program designed to address an industry reality that persists: Women artists, songwriters, and producers too often face fewer oppo...

19/03/2026

Toontrack release Transistor Organ EKX

Latest EZKeys 2 expansion arrives Toontrack's staggering collection of EZKeys 2 expansions has grown once again, and the latest instalment delivers a on...

19/03/2026

Roland preview Melody Flip

New generative AI plug-in due in May 2026 Roland have announced the upcoming launch of a new generative AI tool created in collaboration with Sony Computer ...

19/03/2026

Native Instruments CEO Statement

Nick Williams updates users on insolvency process Nick Williams, the CEO of Native Instruments, has released the following official statement regarding thei...

19/03/2026

Milab to restart production

Iconic Swedish mic manufacturer back in action Legendary Swedish microphone manufacturer Milab have announced that production is now fully underway, and mic...

19/03/2026

FT1-EMU plug-in from Freqport

Acclaimed saturation unit goes virtual Freqport's Freqtube FT1 (reviewed here in SOS February 2023) offers a convenient way to integrate real valve-base...

19/03/2026

SGL Carbon: Restructuring ensures earnings forecast and creates basis for new growth

The discontinuation of loss-making business activities as part of the restructur...

19/03/2026

Sky TV customers can enjoy a taste of Hayus most popular reality shows from today

Thursday 19 March 2026 Sky TV customers can enjoy a taste of Hayu's most po...

19/03/2026

Foo Fighters' Other Voices performance to air on RT this Easter Monday

Other Voices presents a legendary night of music as Foo Fighters bring their stadium anthems to St James' Church, An Daingean. The surprise performance teas...

19/03/2026

RTS Ireland Awards / Gradaim RTS 2026 Shortlist Announced

***Issued by RT on behalf of RTS Ireland Awards / Gradaim RTS 2026...

18/03/2026

Music Row Piano from Wiltone Productions

Yamaha C7 captured in Nashville Wiltone Productions have announced the release of Music Row Piano, a deeply sampled Yamaha C7 piano library that's been ...

18/03/2026

Techivation introduce T-Warmer Mk2

Bass-enhancement plug-in upgraded Along with a steady stream of new releases, Techivation have recently been revisiting some of the older plug-ins in their ...

18/03/2026

Tonal Balance Control 3 from iZotope

Mix-reference plug-in overhauled iZotope's powerful mix-referencing plug-in has just reached its third major version, and now boasts a new capture proce...

18/03/2026

Toontrack Transistor Organ EKX

Latest EZKeys 2 expansion arrives Toontrack's staggering collection of EZKeys 2 expansions has grown once again, and the latest instalment delivers a on...

18/03/2026

Future-ready broadcasts with ATSC 3.0 and enhanced services from Rohde & Schwarz at NAB 2026

Future-ready broadcasts with ATSC 3.0 and enhanced services from Rohde & Schwarz...

18/03/2026

LCTWS 2026

London Calling - When The Industry Convened to Help Streaming Find its MoJo In this blog, Laura Rognoni reflects on key discussions from the Connected TV World...

18/03/2026

SES Announces Extension of Tender Offer

THIS ANNOUNCEMENT RELATES TO THE DISCLOSURE OF INFORMATION THAT QUALIFIED OR MAY HAVE QUALIFIED AS INSIDE INFORMATION WITHIN THE MEANING OF ARTICLE 7(1) OF THE ...

18/03/2026

X-Rite Pantone Demonstrates Advanced Color Management Solutions to Support Smart Manufacturing at MAX and American Coatings Show

X-Rite Pantone Demonstrates Advanced Color Management Solutions to Support Smart...

18/03/2026

BAFTA winner James McAvoy to star in Sky Original series Meantime, based on the novel by Frankie Boyle

Wednesday 18 March 2026 BAFTA winner James McAvoy to star in Sky Original serie...

18/03/2026

Sky Sports and Zuffa Boxing announce multi-year agreement for the UK and Ireland

Wednesday 18 March 2026 Sky Sports and Zuffa Boxing announce multi-year agreement for the UK and Ireland Sky Sports and Zuffa Boxing have announced a new mult...

18/03/2026

Sky Unveils Poster and Trailer for Original Feature Film Shaun the Sheep: The Beast of Mossy Bottom

Wednesday 18 March 2026 Sky Unveils Poster and Trailer for Original Feature Fil...

18/03/2026

UP NEXT: Sky presents a bold slate of new, premium acquired content

Wednesday 18 March 2026 UP NEXT: Sky presents a bold slate of new, premium acquired content Sky reveals slate of newly acquired premium drama and comedy, as i...

18/03/2026

UP NEXT: Sky unveils an unmissable genre-spanning slate of new shows, exclusive previews and first looks for 2026 and beyond

Wednesday 18 March 2026 UP NEXT: Sky unveils an unmissable genre-spanning slate...

18/03/2026

Harmonic Enhances XOS Advanced Media Processor to Streamline Next-Generation Broadcast Distribution

New Playout-to-Delivery Capabilities Elevate ATSC 3.0 Experiences, Lower DTV In...

17/03/2026

How Fresh Finds Africa Propelled Rapper Zaylevelten to a Breakout Year

Fresh Finds Africa spotlights emerging artists and movements across the continent and its global diaspora, with listeners tuning in to discover new Afro-forward...

17/03/2026

Spotify Sparked Viral Moments at G27: genie fest, Driving the Discovery of Thai Rock

Last month, more than 60,000 fans piled into Bangkok's Rajamangala National ...

17/03/2026

Black Rooster Audio release VWB-1X

Vintage-inspired channel strip joins line-up Black Rooster Audio's latest plug-in provides an all-in-one mixing tool inspired by classic analogue consol...

17/03/2026

Accentize unveil dxSplit

Level and EQ voice, reverb and noise independently The latest plug-in to join Accentize's collection is said to take a new approach to dialogue processi...

17/03/2026

RF Spectrum Threat: OFCOM Survey

UHF radio mic & IEM bandwidth at risk Once again, the UHF bandwidth that is currently allocated to RF audio gear is at risk of being reassigned to high-spee...

17/03/2026

SGL Carbon hosts Bavaria's first pilot training course for prospective plant fire department squad leaders

Last Friday, the first Plant Fire Department Training Week in Bavaria successf...

17/03/2026

SES Launches Cash Tender Offer

THIS ANNOUNCEMENT RELATES TO THE DISCLOSURE OF INFORMATION THAT QUALIFIED OR MAY HAVE QUALIFIED AS INSIDE INFORMATION WITHIN THE MEANING OF ARTICLE 7(1) OF THE ...

17/03/2026

Comscore Reports Fourth Quarter and Full Year 2025 Results

Comscore Reports Fourth Quarter and Full Year 2025 Results RESTON, Va., March 17, 2026 - Comscore, Inc. (Nasdaq: SCOR), a trusted partner for planning, transact...

17/03/2026

VEON Strengthens Leadership Team to Accelerate Digital Ambition

17 Mar 2026 VEON Strengthens Leadership Team to Accelerate Digital Ambition Senior executive appointments are to enhance country operations and VEON Group'...