Sony Pixel Power calrec Sony

Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually

18/09/2024

Facebook

Twitter

LinkedIn

API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally

Bot-related security incident count rose 88% in 2022 and 28% in 2023

Insecure APIs result in up to $12 billion more in losses than they did in 2021

@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.

The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.

Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.

Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.



It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.

Some of the key trends identified in the report include:

Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.



Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.



API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.



Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.



Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.

Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.



Additional Information:

Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.

See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
LINK: https://www.thalesgroup.com/en/worldwide/defence-and-security/press_re...
See more stories from thales

Europe Stories

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

06/09/2026

Dolby and MagentaTV Bring Fans Closer to the FIFA World Cup 2026 in Germany with Dolby Vision and Dolby Atmos

June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

21/06/2026

John Walden's Cubase Video Tutorials

New series now live on Udemy Regular SOS contributor and Cubase workshop columnist John Walden has just released a new Cubase video course that is now avail...

21/06/2026

Sky announces immersive documentary series The Wargame

Sunday 21 June 2026 Sky announces immersive documentary series The Wargame The Wargame first looks ZIP (2MB) Sky today confirms the commission of The Wargam...

20/06/2026

IK Multimedia introduce ReSing Doubling

New add-on creates doubles & vocal stacks IK Multimedia's latest ReSing add-on kits the innovative software out with the ability to automatically genera...

19/06/2026

Ninja AB from The Him DSP

Company launch comprehensive mix-comparison tool The Him DSP are a plug-in company founded by The Him, an EDM DJ and producer who has amassed over half a bi...

19/06/2026

Bitwig Studio 6.1 enters beta testing

Major Sampler upgrades introduced The latest version of Bitwig's DAW software has just entered public beta testing, and is available now for all users w...

19/06/2026

Akai Pro's MPC One & MPC Key 37 get G2 upgrade

Four times the power of their predecessors Akai Pro have just introduced upgraded versions of two of their popular standalone MPC systems, kitting them out ...

19/06/2026

How to watch the 2026/27 Premier League season on Sky Sports

Friday 19 June 2026 How to watch the 2026/27 Premier League season on Sky Sports Which matches are Sky Sports showing on the 2026/27 Premier League opening we...

19/06/2026

What's New at FilmLight? New York. 8 July 2026

Catch up on the latest developments across Baselight and Daylight v7, Nara and FilmLight API Wednesday 8 July, 5pm onwards Firehouse: DCTV, 87 Lafayette St, Ne...

18/06/2026

iamReverb gets an update

Improvements & new IR content iamReverb Audio have just launched a free update that kits their convolution reverb plug-in out with some new features and int...

18/06/2026

Two notes unveil Genome 2.0

Modelling suite gains improved captures, iOS support & more Two notes Audio Engineering have just announced the launch of Genome 2.0, a significant update t...

18/06/2026

VSL update Vienna Ensemble Pro 8

New AI assistance feature, video overhaul & more VSL have just announced the launch of Vienna Ensemble Pro 8.1 and 8.1V, a pair of major updates to their ev...

18/06/2026

The Great Roaming Rinse

New study reveals 10 hidden data drainers costing Brits hundreds abroad - and the holiday hotspots where you could get rinsed the mostThursday 18 June 2026 The...

18/06/2026

How to watch the 2026/27 Scottish Premiership season on Sky Sports

Thursday 18 June 2026 How to watch the 2026/27 Scottish Premiership season on Sky Sports Which matches are Sky Sports showing on the 2026/27 Scottish Premiers...

18/06/2026

Sky Sale: Latest deals now on, with discounts on iPhone Air & 2.5Gbps speeds

Thursday 18 June 2026 Sky Sale: Latest deals now on, with discounts on iPhone Air & 2.5Gbps speeds The latest deals have dropped from Sky Mobile, the award-wi...

18/06/2026

FOX Advertising and Toonstar Team to Create New Opportunities for Brands in Digital-First Animation

FOX Advertising and Toonstar Team to Create New Opportunities for Brands in Digi...

18/06/2026

Arqiva secures WTA Tier-4 accreditation

Arqiva's Crawley Court and Chalfont Grove teleports re-certified at highest World Teleport Association standard 18 June 2026, Winchester, UK - Arqiva, the ...

18/06/2026

Apple announces changes to iOS in Brazil - UPDATE - Posted on 18 June 2026

Apple today announced changes impacting iOS apps in Brazil that reflect a recent agreement with Brazil's competition regulator, the Conselho Administrativo ...

17/06/2026

SoundBridge 3.1.0 now available

New features, changes & bug fixes SoundBridge have just released another update for their remote collaboration-focused DAW - reviewed here in SOS March 2026...

17/06/2026

Fryette launch the Valvulator Mini

Valve-based front end for digital & modelling rigs The latest addition to Fryette's product range delivers a packed-down, pedalboard-friendly version of...

17/06/2026

The Biggest UK Pro Audio Show In 20 Years!

GearExpo UK - 27 June 2026 Sound On Sound are proud to announce GearExpo UK, a major new recording and music technology exhibition in London! This is the bi...

17/06/2026

Genelec introduce the 9402A System Management Device

SAM monitoring line-up gains Dante and AES67 support The latest expansion of Genelec's UNIO monitoring ecosystem introduces a new device that provides D...

17/06/2026

The R&SPR300 portable receiver from Rohde & Schwarz sets new standards in spectrum monitoring

The R&S PR300 portable receiver from Rohde & Schwarz sets new standards in spect...

17/06/2026

Elt Group and Rohde & Schwarz sign a cooperation agreement to explore commercial opportunities in electronic warfare and defense

Elt Group and Rohde & Schwarz sign a cooperation agreement to explore commercial...

17/06/2026

** MEDIA ALERT ** By Popular Demand Shonen Jump Shop Returns to Los Angeles for Anime Expo 2026

** MEDIA ALERT ** BY POPULAR DEMAND SHONEN JUMP SHOP RETURNS TO LOS ANGELES...

17/06/2026

Two in three fans will connect to venue WiFi this World Cup, Sky Business research reveals

Wednesday 17 June 2026 Two in three fans will connect to venue WiFi this World ...

17/06/2026

Harmonic Completes Divestiture of Video Business to MediaKind

Transaction Positions Harmonic as a Pure-Play Broadband Company SAN JOSE, Calif. - June 17, 2026 - Harmonic Inc. (NASDAQ: HLIT), the worldwide leader in virtual...

17/06/2026

FOX Advertising To Launch Industry's First End-to-End Agentic Advertising Platform, Powered by FOX AdStudio

FOX Advertising To Launch Industry's First End-to-End Agentic Advertising Pl...

17/06/2026

Building resilience in an era of compounding threats

How SGN is future-proofing critical national infrastructure with Arqiva Managed Connectivity. When disruption becomes the norm As Storm Eunice tore across the ...

17/06/2026

Good Vibrations hit Dublin and Limerick as RT Concert Orchestra plays the music of the Beach Boys

The RT Concert Orchestra will bring the timeless music of The Beach Boys to aud...

16/06/2026

Thomson launches new learning App

Thomson's highly regarded expert-led online learning courses are now easier to access on the go via our new App. Available now on Google Play Store, the J...

16/06/2026

Rumble three-band soft synth by UVI

Boasts individual synths for each band UVI's latest synth takes an interesting approach to synthesis, offering a trio of synth engines that each operate...

16/06/2026

PSP Levelizer: auto level adjustment plug-in from PSPaudioware

New intelligent auto-fader plug-in unveiled PSPaudioware's latest release offers automatic level adjustment and provides more detailed control than many...

16/06/2026

The Crow Hill Company launch Crystal Pads

New performance-focused library announced Crystal Pads is the latest addition to The Crow Hill Company's ever-growing product range, and according to th...

16/06/2026

GForce launch official Prophet-5 soft synth

Developed in partnership with Sequential In recent years, GForce Software have branched into official emulations of classic hardware synths, delivering a ha...

16/06/2026

DT 30 IE: New in-ears from beyerdynamic

Designed specifically for live performance monitoring beyerdynamic's latest announcement sees the company introduce an affordable in-ear monitoring syst...

16/06/2026

Cherry Audio recreate the Ensoniq ESQ-1

Official emulation celebrates iconic synth's 40th anniversary Cherry Audio have just introduced Ensoniq ESQ-1, an official recreation of the 1986 polyph...

16/06/2026

Rohde & Schwarz achieves highest number of GCF validated 3GPP NR NTN test cases for RF, RRM and PCT domains

Rohde & Schwarz achieves highest number of GCF validated 3GPP NR NTN test cases ...

16/06/2026

Hitachi and PESA Announce Strategic Partnership to Drive Growth in Poland's Rail Market

Bydgoszcz to Become a Local Centre of Excellence for Advanced Rail Technologies....

16/06/2026

Record audiences tune in for opening weekend of ICC Womens T20 World Cup 2026 on Sky Sports

Tuesday 16 June 2026 Record audiences tune in for opening weekend of ICC Women&...

15/06/2026

Rumble from UVI

Innovative three-band soft synth introduced UVI's latest synth takes an interesting approach to synthesis, offering a trio of synth engines that each op...

15/06/2026

Oram Awards 2026: Open call announcement

Applications now open for 2026 The Oram Awards have returned for 2026 to celebrate the unusual, unique and unfiltered creative worlds of women and gender-di...

15/06/2026

PSPaudioware release PSP Levelizer

New intelligent auto-fader plug-in revealed PSPaudioware's latest release offers automatic level adjustment and provides more detailed control than many...

15/06/2026

Greater Manchester Police installs Rohde & Schwarz security scanner for custody searches

Greater Manchester Police installs Rohde & Schwarz security scanner for custody ...

15/06/2026

The New Discovery Stack: AI, Metadata and Audience Intelligence

Insights from NAGRAVISION's latest industry webinar featuring One Hungary, Liberty Global and Media Press Group In this blog, Laura Rognoni explores the k...

15/06/2026

** MEDIA ALERT ** First-Ever Official Studio Ghibli Store Opens in the U.S.

** MEDIA ALERT ** First-Ever Official Studio Ghibli Store Opens in the U.S. Fans Can Step Into the World of My Neighbor Totoro, Kiki's Delivery Servic...

15/06/2026

Sky News takes viewers inside Minab in new film investigating primary school strike in Iran

Monday 15 June 2026 Sky News takes viewers inside Minab in new film investigati...