
Facebook
Twitter
LinkedIn
API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally
Bot-related security incident count rose 88% in 2022 and 28% in 2023
Insecure APIs result in up to $12 billion more in losses than they did in 2021
@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.
The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.
Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.
Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.
It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.
Some of the key trends identified in the report include:
Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.
Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.
API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.
Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.
Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.
Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.
Additional Information:
Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.
See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
Europe Stories
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
06/09/2026
June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
21/06/2026
New series now live on Udemy
Regular SOS contributor and Cubase workshop columnist John Walden has just released a new Cubase video course that is now avail...
21/06/2026
Sunday 21 June 2026
Sky announces immersive documentary series The Wargame
The Wargame first looks
ZIP (2MB)
Sky today confirms the commission of The Wargam...
20/06/2026
New add-on creates doubles & vocal stacks
IK Multimedia's latest ReSing add-on kits the innovative software out with the ability to automatically genera...
19/06/2026
Company launch comprehensive mix-comparison tool
The Him DSP are a plug-in company founded by The Him, an EDM DJ and producer who has amassed over half a bi...
19/06/2026
Major Sampler upgrades introduced
The latest version of Bitwig's DAW software has just entered public beta testing, and is available now for all users w...
19/06/2026
Four times the power of their predecessors
Akai Pro have just introduced upgraded versions of two of their popular standalone MPC systems, kitting them out ...
19/06/2026
Friday 19 June 2026
How to watch the 2026/27 Premier League season on Sky Sports
Which matches are Sky Sports showing on the 2026/27 Premier League opening we...
19/06/2026
Catch up on the latest developments across Baselight and Daylight v7, Nara and FilmLight API Wednesday 8 July, 5pm onwards
Firehouse: DCTV, 87 Lafayette St, Ne...
18/06/2026
Improvements & new IR content
iamReverb Audio have just launched a free update that kits their convolution reverb plug-in out with some new features and int...
18/06/2026
Modelling suite gains improved captures, iOS support & more
Two notes Audio Engineering have just announced the launch of Genome 2.0, a significant update t...
18/06/2026
New AI assistance feature, video overhaul & more
VSL have just announced the launch of Vienna Ensemble Pro 8.1 and 8.1V, a pair of major updates to their ev...
18/06/2026
New study reveals 10 hidden data drainers costing Brits hundreds abroad - and the holiday hotspots where you could get rinsed the mostThursday 18 June 2026
The...
18/06/2026
Thursday 18 June 2026
How to watch the 2026/27 Scottish Premiership season on Sky Sports
Which matches are Sky Sports showing on the 2026/27 Scottish Premiers...
18/06/2026
Thursday 18 June 2026
Sky Sale: Latest deals now on, with discounts on iPhone Air & 2.5Gbps speeds
The latest deals have dropped from Sky Mobile, the award-wi...
18/06/2026
FOX Advertising and Toonstar Team to Create New Opportunities for Brands in Digi...
18/06/2026
Arqiva's Crawley Court and Chalfont Grove teleports re-certified at highest World Teleport Association standard
18 June 2026, Winchester, UK - Arqiva, the ...
18/06/2026
Apple today announced changes impacting iOS apps in Brazil that reflect a recent agreement with Brazil's competition regulator, the Conselho Administrativo ...
17/06/2026
New features, changes & bug fixes
SoundBridge have just released another update for their remote collaboration-focused DAW - reviewed here in SOS March 2026...
17/06/2026
Valve-based front end for digital & modelling rigs
The latest addition to Fryette's product range delivers a packed-down, pedalboard-friendly version of...
17/06/2026
GearExpo UK - 27 June 2026
Sound On Sound are proud to announce GearExpo UK, a major new recording and music technology exhibition in London! This is the bi...
17/06/2026
SAM monitoring line-up gains Dante and AES67 support
The latest expansion of Genelec's UNIO monitoring ecosystem introduces a new device that provides D...
17/06/2026
The R&S PR300 portable receiver from Rohde & Schwarz sets new standards in spect...
17/06/2026
Elt Group and Rohde & Schwarz sign a cooperation agreement to explore commercial...
17/06/2026
** MEDIA ALERT **
BY POPULAR DEMAND SHONEN JUMP SHOP RETURNS TO
LOS ANGELES...
17/06/2026
Wednesday 17 June 2026
Two in three fans will connect to venue WiFi this World ...
17/06/2026
Transaction Positions Harmonic as a Pure-Play Broadband Company SAN JOSE, Calif. - June 17, 2026 - Harmonic Inc. (NASDAQ: HLIT), the worldwide leader in virtual...
17/06/2026
FOX Advertising To Launch Industry's First End-to-End Agentic Advertising Pl...
17/06/2026
How SGN is future-proofing critical national infrastructure with Arqiva Managed Connectivity.
When disruption becomes the norm As Storm Eunice tore across the ...
17/06/2026
The RT Concert Orchestra will bring the timeless music of The Beach Boys to aud...
16/06/2026
Thomson's highly regarded expert-led online learning courses are now easier to access on the go via our new App.
Available now on Google Play Store, the J...
16/06/2026
Boasts individual synths for each band
UVI's latest synth takes an interesting approach to synthesis, offering a trio of synth engines that each operate...
16/06/2026
New intelligent auto-fader plug-in unveiled
PSPaudioware's latest release offers automatic level adjustment and provides more detailed control than many...
16/06/2026
New performance-focused library announced
Crystal Pads is the latest addition to The Crow Hill Company's ever-growing product range, and according to th...
16/06/2026
Developed in partnership with Sequential
In recent years, GForce Software have branched into official emulations of classic hardware synths, delivering a ha...
16/06/2026
Designed specifically for live performance monitoring
beyerdynamic's latest announcement sees the company introduce an affordable in-ear monitoring syst...
16/06/2026
Official emulation celebrates iconic synth's 40th anniversary
Cherry Audio have just introduced Ensoniq ESQ-1, an official recreation of the 1986 polyph...
16/06/2026
Rohde & Schwarz achieves highest number of GCF validated 3GPP NR NTN test cases ...
16/06/2026
Bydgoszcz to Become a Local Centre of Excellence for Advanced Rail Technologies....
16/06/2026
Tuesday 16 June 2026
Record audiences tune in for opening weekend of ICC Women&...
15/06/2026
Innovative three-band soft synth introduced
UVI's latest synth takes an interesting approach to synthesis, offering a trio of synth engines that each op...
15/06/2026
Applications now open for 2026
The Oram Awards have returned for 2026 to celebrate the unusual, unique and unfiltered creative worlds of women and gender-di...
15/06/2026
New intelligent auto-fader plug-in revealed
PSPaudioware's latest release offers automatic level adjustment and provides more detailed control than many...
15/06/2026
Greater Manchester Police installs Rohde & Schwarz security scanner for custody ...
15/06/2026
Insights from NAGRAVISION's latest industry webinar featuring One Hungary, Liberty Global and Media Press Group
In this blog, Laura Rognoni explores the k...
15/06/2026
** MEDIA ALERT **
First-Ever Official Studio Ghibli Store Opens in the U.S.
Fans Can Step Into the World of My Neighbor Totoro, Kiki's Delivery Servic...
15/06/2026
Monday 15 June 2026
Sky News takes viewers inside Minab in new film investigati...