
Facebook
Twitter
LinkedIn
API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally
Bot-related security incident count rose 88% in 2022 and 28% in 2023
Insecure APIs result in up to $12 billion more in losses than they did in 2021
@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.
The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.
Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.
Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.
It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.
Some of the key trends identified in the report include:
Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.
Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.
API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.
Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.
Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.
Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.
Additional Information:
Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.
See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
Europe Stories
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
26/03/2026
Spotify's partnership with NAVER, Korea's leading digital platform, is built around one simple goal: making it easier for listeners in Korea to discover...
26/03/2026
Exclusive to ComposerCloud for first month
Sample library and virtual instrument gurus EastWest have announced the upcoming release of a new virtual drum i...
26/03/2026
Friday 27 March
Friday 27 March will mark Dynamic Range Day 2026, the annual day of online activity that was started in 2010 by mastering engineer Ian Sheph...
26/03/2026
Includes four separate instruments
Max Richter's SRM Sounds venture have just announced their fifth release, ASMR Choir. Captured at the main live room ...
26/03/2026
Thursday 26 March 2026
HBO Max included for Sky and NOW customers from 26 March...
26/03/2026
Thursday 26 March 2026
Sky Sets Iconic Costumes Dancing Together Like Never Before' in Brand CampaignTurn on cookies to view this content. Go to Privacy o...
26/03/2026
Wuppertal March 26, 2026
CS live Builds Future-Ready OB Van With Riedel MediorNet and hi Control SystemRiedel Communications today announced that Czech-based ...
26/03/2026
Enhancements to Harmonic's Sports Streaming Solution Introduce Server-Side Multiview, Contextual Metadata-Driven Advertising, Dynamic In-Stream Ads and Robu...
26/03/2026
Open the report
Our 2025 report brings together results from 79 business magazine titles across 22 market sectors, published by 49 media owners. Over the year,...
26/03/2026
RT Commercial today announced Fiat as sponsor of The Louise Duffy Show on RT Radio 1, Weekdays 3pm 4pm.
The Louise Duffy Show is the home of daytime music...
26/03/2026
Wayne, N.J., March 26, 2026 Phantom High-Speed announces the latest product li...
25/03/2026
Directed By, Spotify's documentary-style series that pulls back the curtain ...
25/03/2026
BTS is so back. This week, the global pop superstars took the stage at New York City's Pier 17 for their first U.S. performance in four years.
Part of Spot...
25/03/2026
How you listen can shape what you hear. That's the idea behind the new Spotify Listening Lounge, an acoustic space at our London headquarters purpose-built ...
25/03/2026
Tape effects taken to the extreme
The latest release from New York-based developer Iconic Instruments is said to accurately recreate the saturation and comp...
25/03/2026
Launched alongside new Vocal Phrases bundle
Sonuscore's latest release has been designed specifically for composers working on fantasy TV, film and game...
25/03/2026
Latest update now live
The latest version of Steinberg's post-production-focused DAW has just arrived, and comes packed with new dialogue editing, sound...
25/03/2026
Rohde & Schwarz joins FormFactor's MeasureOne partner program FormFactor and Rohde & Schwarz advance their partnership for on-wafer RF component character...
25/03/2026
FOX Delivers Fan Factor to Fear Factor: House of Fear Finale with Interactive Af...
25/03/2026
UK-based pro audio provider 22live has strengthened its wireless offering with a strategic investment in DPA Microphones' new N-Series Digital Wireless Syst...
24/03/2026
As the music industry gathers for Canada's Juno Awards, the local edition of...
24/03/2026
Behind every great song is a complex web of people, stories, and inspirations th...
24/03/2026
Few filmmakers have shaped popular cinema as profoundly as Steven Spielberg. So ...
24/03/2026
Latest Eurorack modules revealed
ALM/Busy Circuits have just introduced another two Eurorack modules, delivering a powerful new modulator that builds on the...
24/03/2026
Smallest, most affordable MPC to date
Akai Pro have just introduced their most accessible standalone sampler to date, making the iconic MPC experience avail...
24/03/2026
Create & manage presets on Windows & macOS
Electro-Harmonix have announced that their free Mac/Windows application now allows users of their Oceans Abyss re...
24/03/2026
Rohde & Schwarz amplifiers enable high-field immunity testing expansion at IB Le...
24/03/2026
eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({...
24/03/2026
Rick Bernier reflects on a career that has taken him to the very top of live broadcast audio. As a Senior Broadcast Audio A1 Engineer and Music Director, he has...
24/03/2026
Jock and Conor are back in Cork for series 5
A new series of hit-comedy The Young Offenders will drop on RT Player on Good Friday 3 April. The show, produced...
24/03/2026
RT 's new history podcast, What Were We Like, is out now. Hosted by historian Diarmaid Ferriter and archivist Catriona Crowe, the series focuses on modern I...
24/03/2026
Tuesday 24 March 2026
Netflix partners with Sky Business to bring boxing night ...
24/03/2026
The Death of Bunny Munro and Lockerbie: A Search for Truth receive four nominations eachTuesday 24 March 2026
Sky celebrates 28 nominations at the 2026 BAFTA T...
24/03/2026
Tubi Turns Passion into Performance at IAB Newfront Announces New Interactive Ad Formats Including Scene Sense, Interactive Pause Ads and Connected Conversion...
24/03/2026
Arqiva shortlisted for Education Initiative of the Year'
We're excited to announce that we've been named a Finalist at the British Data Awards 202...
24/03/2026
Use of ABC data continues to grow, with 87% of buyers say they use it, compared ...
24/03/2026
All three presenters, Maura, D ith and Sinead, celebrate as afternoon chat show filmed in Cork hits milestone.
Ireland's longest running afternoon show, t...
24/03/2026
March 24 2026, 04:00 (PDT) Dolby Named to Fast Company's Annual List of the...
23/03/2026
It's been 20 years since Miley Cyrus introduced the world to Hannah Montana,...
23/03/2026
Made entirely from real natural recordings
Aimed at sound designers and editors working in film, TV and game audio, the latest release from BOOM Library com...
23/03/2026
Transcribe sheets, tabs or MIDI from audio files
Klang.io have announced the launch of a new AI-powered software tool that's capable of detecting multip...
23/03/2026
Monday 23 March 2026
Hacks, the multi-Emmy -winning Sky Exclusive comedy, retur...
23/03/2026
RT is sad today to learn of the death of legendary RT Sport broadcaster Michael Lyster, who died this morning aged 71 years.
Kevin Bakhurst, Director-General...
23/03/2026
RT Documentary On One has scooped its first ever dedicated music award. At the 2026 Icelandic Music Awards, composer lfur Eldj rn won Release of the Year in t...
23/03/2026
Inside Sport, Liveline, Morning Ireland and 2FM DRIVE will all be in Prague to bring fans to the heart of the action
Every Moment, Every GenerationRT | FIFA W...