Sony Pixel Power calrec Sony

Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually

18/09/2024

Facebook

Twitter

LinkedIn

API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally

Bot-related security incident count rose 88% in 2022 and 28% in 2023

Insecure APIs result in up to $12 billion more in losses than they did in 2021

@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.

The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.

Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.

Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.



It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.

Some of the key trends identified in the report include:

Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.



Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.



API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.



Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.



Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.

Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.



Additional Information:

Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.

See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
LINK: https://www.thalesgroup.com/en/worldwide/defence-and-security/press_re...
See more stories from thales

More from Thales

30/06/2025

Thales 2025 Global Cloud Security Study Reveals Organizations Struggle to Secure Expanding, AI-Driven Cloud Environments

Facebook Twitter LinkedIn 52% report AI security spending is displacing tr...

30/06/2025

Thales Alenia Space to develop SOLiS very-high-throughput laser communications demonstrator

Facebook Twitter LinkedIn Cannes, June 30th, 2025 - Thales Alenia Space, t...

27/06/2025

Thales and KONGSBERG to establish new major Defence communications joint venture in Norway

Facebook Twitter LinkedIn Thales, a global high-tech leader, and Kongsberg...

26/06/2025

The European Space Agency awards Thales Alenia Space the study of the SIRIUS mission to monitor Urban Heat Islands from space

Facebook Twitter LinkedIn Madrid, June 26, 2025 - The European Space Agenc...

24/06/2025

Thales Launches File Activity Monitoring (FAM) to Strengthen Real-Time Visibility and Control Over Unstructured Data

Facebook Twitter LinkedIn New capability gives instant visibility to detec...

24/06/2025

Imperva Application Security Integrates API Detection and Response, Setting A New Standard in API Security

Facebook Twitter LinkedIn First unified, single-pane-of-glass platform to ...

24/06/2025

Thales celebrates American Airlines 1st 787-9 aircraft flying with AVANT Up Inflight Entertainment System

Facebook Twitter LinkedIn The American Airlines 787-9 takes flight with Th...

20/06/2025

Thales supports airspace sovereignty in Albania with Ground Master 400 Alpha surveillance radar

Facebook Twitter LinkedIn At the Paris Air Show, in the presence of the Fr...

19/06/2025

Thales and Terma sign a Memorandum of Understanding to expand cooperation in the Air, Naval and Space domains

Facebook Twitter LinkedIn Thales, a global technology leader for the Defen...

12/06/2025

Thales ranked No.1 most attractive employer among engineering students in France in 2025

Facebook Twitter LinkedIn Thales has secured the top spot in the 2025 rank...

12/06/2025

Thales invests 55 million euros to anchor next-generation resilient navigation in France

Facebook Twitter LinkedIn Thales strengthens its European leadership in re...

11/06/2025

Software Rpublique unveils "vision 4rescue", an integrated technological ecosystem for the next-gen of Emergency Services

Facebook Twitter LinkedIn In response to the increasing frequency and inte...

05/06/2025

Vietnam Space Committee, OSB Group and Thales Partner to Promote Education and Innovation in Space Technologies

Facebook Twitter LinkedIn Vietnam has been building a national framework t...

04/06/2025

Thales Unveils State-of-the-Art Inflight Entertainment & Services Lab at its Engineering Competence Centre in Bengaluru

Facebook Twitter LinkedIn The new lab, dedicated to development of Infligh...

03/06/2025

Thales reinvents secure payment systems for a data-driven future, showcasing leadership at Money20/20 Europe

Facebook Twitter LinkedIn Payment systems must evolve beyond traditional c...

02/06/2025

cortAIx SG: Thales Accelerates Trusted AI Innovation in Singapore with Strategic Partnerships

Facebook Twitter LinkedIn Thales's global acceleration in trusted AI e...

02/06/2025

Cyshield uses Thales technology to launch Egypt's first connectivity service for eSIM devices

Facebook Twitter LinkedIn Cyshield, a leading digital solutions company, s...

22/05/2025

Thales Reinforces Commitment to Malaysia at LIMA 2025 with New Leadership and Contracts Awarded

Facebook Twitter LinkedIn As a strategic partner in helping Malaysia achie...

21/05/2025

Tawazun Council and Thales Sign Agreement to Establish Ground Master Air Surveillance Radar Production Facility in UAE

Facebook Twitter LinkedIn As part of the Tawazun Economic Program, Thales ...

19/05/2025

Thales to provide a cyber-secured and AI-powered autonomous mine countermeasures system to the Republic of Singapore Navy

Facebook Twitter LinkedIn The unique, sea-proven Pathmaster solution will ...

19/05/2025

Thales, Radiall and FoxConn have initiated preliminary discussions on semiconductor production

Facebook Twitter LinkedIn Thales, Radiall and FoxConn announce they have i...

15/05/2025

Thales powers one million digital payment experiences with Vipps mobile wallet in Norway

Facebook Twitter LinkedIn Thales fully supports the success of Vipps, Norw...

15/05/2025

Thales boosts Air Traffic Management System for Serbia and Montenegro Air Traffic Services SMATSA

Facebook Twitter LinkedIn Serbia and Montenegro Air Traffic Services SMATS...

15/05/2025

Thales inaugurates GenF, a first step towards nuclear fusion energy

Facebook Twitter LinkedIn Thales, a global leader in high-power lasers, will inaugurate GenF on Thursday 15 May 2025 in Le Barp (Bordeaux). GenF aims to t...

13/05/2025

Thales celebrates 50 years in Greece

Facebook Twitter LinkedIn On the occasion of DEFEA, Greece's premier defence exhibition, Thales, a global leader in advanced technologies for the Defe...

13/05/2025

Thales launches TRAC SIGMA - an innovative multi-mission Primary Surveillance Radar for Approach and Long-Range Air Surveillance

Facebook Twitter LinkedIn Thales unveils its new multi-mission Primary Sur...

30/04/2025

Thales modernises the world-class TACTIS armoured vehicle training centre for the Royal Netherlands Army

Facebook Twitter LinkedIn Thales has secured a major contract to modernise...

29/04/2025

One out of three secure civil IDs delivered each year is powered by Thales

Facebook Twitter LinkedIn In a world where identity fraud represents a critical vulnerability for citizens and societies, Thales is leading the transforma...

25/04/2025

Thales and Deloitte form Strategic Alliance to Help Enhance Data Protection and Governance Services

Facebook Twitter LinkedIn Enhancing Data Protection and Governance Service...

24/04/2025

Thales reports its order intake and sales for the first quarter of 2025

Facebook Twitter LinkedIn Order intake: 3.8 billion, down -25% (-27% on an organic basis1) Sales: 5.0 billion, up 12.2% ( 9.9% on an organic basis) A...

23/04/2025

Thales and Michelin drive software revenue growth with innovative simulation software

Facebook Twitter LinkedIn Enables Michelin to focus on development of its ...

17/04/2025

MGCS Project Company GmbH (MPC) established in Cologne

Facebook Twitter LinkedIn Thursday, 17 April 2025 - The next step has now been taken in the Franco-German armaments project Main Ground Combat System (MGC...

14/04/2025

Thales to supply NATO with latest-generation situational awareness solution to ensure decision superiority

Facebook Twitter LinkedIn Thales has been selected by NATO to deliver phas...

08/04/2025

U.S. Air Force awards NSPA F-16 Helmet Mounted Display contract for Thales Scorpion HMD

Facebook Twitter LinkedIn Thales Thales subsidiary, Thales Defense &...

08/04/2025

Thales revolutionizes Inflight Entertainment (IFE) with 360Stream Live TV and innovative Near-Live highlights

Facebook Twitter LinkedIn Thales revolutionizes inflight TV with 360Stream...

07/04/2025

Thales signs a contract to deliver the Ground Master 200 MM/C Multi Mission Compact radar to Sweden

Facebook Twitter LinkedIn The Swedish Defence Materiel Administration (F r...

07/04/2025

Thales announces next-generation Inertial Measurement Unit (IMU) for resilient navigation

Facebook Twitter LinkedIn Thales is a global leader in inertial navigation...

03/04/2025

Thales to recruit 8,000 people in 2025 and accelerate its 'Learning company' programme

Facebook Twitter LinkedIn Thales, a global leader in advanced technologies...

02/04/2025

Thales Alenia Space wins 51 million contract to extend EGNOS service life

Facebook Twitter LinkedIn Strengthening Europe's critical navigation infrastructure thanks to EGNOS satellite-based augmentation system Cannes, April ...

01/04/2025

DSTA and Thales Announce AI-Driven Co-Lab to Strengthen Singapore's Defence Systems

Facebook Twitter LinkedIn Defence Science and Technology Agency (DSTA) and...

31/03/2025

Thales unveils its PANORAMIC quad-tube night vision goggle

Facebook Twitter LinkedIn Presented for the first time at SOFINS1, PANORAMIC is a lightweight, compact night vision goggle equipped with four light intens...