Sony Pixel Power calrec Sony

Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually

18/09/2024

Facebook

Twitter

LinkedIn

API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally

Bot-related security incident count rose 88% in 2022 and 28% in 2023

Insecure APIs result in up to $12 billion more in losses than they did in 2021

@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.

The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.

Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.

Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.



It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.

Some of the key trends identified in the report include:

Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.



Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.



API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.



Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.



Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.

Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.



Additional Information:

Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.

See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
LINK: https://www.thalesgroup.com/en/worldwide/defence-and-security/press_re...
See more stories from thales

More from Thales

18/09/2024

Thales contributes to the production of seven additional sections of the SAMP/TNG for the French Air and Space Forces

Facebook Twitter LinkedIn Thales As announced on the 17 September 2024 ...

18/09/2024

Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually

Facebook Twitter LinkedIn API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally Bot-related security...

17/09/2024

Thales Australia's Lithgow Arms partners with Vbenfabrikken to establish Danish small arms industrial capability

Facebook Twitter LinkedIn On 17 September 2024, Thales Australia and Denma...

17/09/2024

Thales joins the CAC 40 ESG index

Facebook Twitter LinkedIn The inclusion of Thales in this index reflects the Groups accelerating progress in terms of social and environmental responsibil...

16/09/2024

International ID Day: Thales stands up for a legal and trusted identity for everyone.

Facebook Twitter LinkedIn On the International Identity Day ID Day', ...

13/09/2024

Alaska awards Thales Driver's License, ID Card contract with next generation security

Facebook Twitter LinkedIn Alaska residents will be the first in the U.S. t...

10/09/2024

Appointment at Thales in the UK

Facebook Twitter LinkedIn Alex Cresswell has expressed his wish to step back from his executive role as Chairman and CEO of Thales in the UK. Therefore, P...

05/09/2024

Thales to lead DECOR research project to test solutions for lowering the environmental impact of flight operations

Facebook Twitter LinkedIn Working together to reduce the environmental imp...

03/09/2024

Thales and WB Group sign a Frame Agreement on Strategic Cooperation in the defence sector

Facebook Twitter LinkedIn Pascale SOURISSE, Thales International, and Piot...

03/09/2024

Thales i WB Group podpisay ramowe porozumienie o wsppracy strategicznej w sektorze obronnym

Facebook Twitter LinkedIn Pascale SOURISSE, Thales International, and Piot...

03/09/2024

Thales in Belgium and Polska Amunicja sign a MoU to collaborate on the production of 70mm rockets

Facebook Twitter LinkedIn Pawel Poncyljusz, Polska Amunicja, Magdalena Niz...

03/09/2024

Thales Belgium i Polska amunicja podpisay list intencyjny o wsppracy przy produkcji rakiet 70 mm

Facebook Twitter LinkedIn Pawel Poncyljusz, Polska Amunicja, Magdalena Niz...

03/09/2024

Thales and PIT-RADWAR (PGZ Group) to cooperate on radar technologies

Facebook Twitter LinkedIn Magdalena NIZIK, Thales Poland, Pascale SOURISSE, Thales International, Marek BOREJKO, PGZ PITRADWAR - Thales Thales, a glo...

03/09/2024

Thales i PIT-RADWAR (Grupa PGZ) podejm wspprac w zakresie technologii radarowych

Facebook Twitter LinkedIn Magdalena NIZIK, Thales Poland, Pascale SOURISSE, Thales International, Marek BOREJKO, PGZ PITRADWAR - Thales Thales, globa...

29/08/2024

Thales to present modern air defence technologies at the MSPO fair in Kielce

Facebook Twitter LinkedIn One of the key air defence solutions Thales will present at MSPO this year is the GM200 Multi-Mission family air surveillance an...

29/08/2024

Thales zaprezentuje nowoczesne technologie obrony powietrznej na targach MSPO w Kielcach

Facebook Twitter LinkedIn Jednym z kluczowych rozwi za obrony powietrznej...

21/08/2024

Thales and L&T Technology Services expand collaboration to provide innovative business models to customers

Facebook Twitter LinkedIn New contract builds on 20-year relationship with...

20/08/2024

Ita Unibanco innovates with a credit card specifically designed to meet the needs of visually impaired people

Facebook Twitter LinkedIn Sao Paulo - Itau Unibanco and Thales, a global l...

01/08/2024

Thales Chosen as Supplier for Lilium's Revolutionary eVTOL Jet Program

Facebook Twitter LinkedIn Thales, a global leader in airborne communication and navigation solutions, formerly known as Cobham Aerospace Communications, h...

31/07/2024

Thales to enhance mobile threat simulators for German forces

Facebook Twitter LinkedIn Thales has been entrusted with the upkeep of critical components and peripherals for the mobile threat simulators (Mobs). These ...

30/07/2024

Thales and Garuda Aerospace sign MoU for secure drone operations in India

Facebook Twitter LinkedIn Thales has signed a memorandum of understanding (MoU) with Garuda Aerospace to promote growth and innovation in the drone sector...

23/07/2024

Thales reports its 2024 half-year results

Facebook Twitter LinkedIn Order intake: 10.8 billion, up 26% ( 23% on an organic basis1) Order book: 47 billion, a new record high Sales: 9.5 billion...

19/07/2024

South Korea Institute of Startup & Entrepreneurship Development (KISED) and Thales to Champion Korea's Start-up Ecosystem

Facebook Twitter LinkedIn Mr Yeol-Soo CHOI, KISED Acting President, and Fr...

12/07/2024

Thales announces order for new SYRACUSE IV satcom stations to equip French Army Serval armoured vehicles

Facebook Twitter LinkedIn The French defence procurement agency (DGA) has ...

10/07/2024

Papara premieres Thales SketchMyCard

Facebook Twitter LinkedIn Papara is the first fintech in the world to deploy Thales' innovative personalisation solution which offers its users artist...

09/07/2024

Thales to test passive hull-mounted sonar on Naval Group's XL-UUV demonstrator

Facebook Twitter LinkedIn The passive omnidirectional hull-mounted sonar f...

01/07/2024

Thales ramps up rocket production at its Herstal site in Belgium to support European defence

Facebook Twitter LinkedIn Thales has opened a new assembly line to accommo...

27/06/2024

Thales Alenia Space reveals results of ASCEND feasibility study on space data centers

Facebook Twitter LinkedIn Cannes, June 27, 2024 - Thales Alenia Space, the...

26/06/2024

Lufthansa Technik selects Thales for the Pegasus program

Facebook Twitter LinkedIn Bombardier Thales will supply its last generation of secured audio/radio management system capable of managing the communicat...

25/06/2024

Cloud Resources have Become Biggest Targets for Cyberattacks, finds Thales

Facebook Twitter LinkedIn Cloud Security spending now tops all other security spending categories Nearly half (47%) of all corporate data stored in the c...

24/06/2024

Thales obtains the first Design Verification Report for a complete drone system ever granted by EASA

Facebook Twitter LinkedIn Design Verification Report (DVR) is a new proces...

21/06/2024

Space Alliance wins 2024 Farnse d'Or award

Facebook Twitter LinkedIn Thales and Leonardo recognized for strengthening ties between Italy and France through space cooperation under Quirinal Treaty ...

21/06/2024

Industry signs Letter of Intent on MGCS

Facebook Twitter LinkedIn At the Eurosatory 2024 international defence trade fair, the managing directors of KNDS Deutschland, KNDS France, Rheinmetall La...

21/06/2024

ASTRA 1P communications satellite successfully launched

Facebook Twitter LinkedIn The most powerful geostationary satellite ever designed to operate from 19.2 East Cape Canaveral, Florida, June 21, 2024 - AST...

20/06/2024

EDGE and Thales Announce a Strategic Partnership for Radio Communications Development and Manufacturing in the UAE

Facebook Twitter LinkedIn Didier Pagnoux, CEO of KATIM. Abdelhafid Mordi, ...

19/06/2024

Thales signs three agreements with ukrainian industry to strengthen front-line support and local defence capability

Facebook Twitter LinkedIn Thales has signed at Eurosatory three agreements...

18/06/2024

EURENCO and Thales sign a strategic partnership until2030

Facebook Twitter LinkedIn EUROSATORY, Parc des Expositions Paris-Villepinte, June 18, 2024 - EURENCO and Thales have strengthened their collaboration and ...

18/06/2024

Thales Belgium, WB Electronics and AREX signed an MoU to develop a new remote weapon system equipped with 70mm rockets

Facebook Twitter LinkedIn Leveraging their respective competencies, the th...

18/06/2024

EURENCO and Thales sign a strategic partnership until 2030

Facebook Twitter LinkedIn EUROSATORY, Parc des Expositions Paris-Villepinte, June 18, 2024 - EURENCO and Thales have strengthened their collaboration and ...

17/06/2024

Thales supports the Irish Defence Forces, providing more than 6 000 software defined radios

Facebook Twitter LinkedIn The Irish Defence Forces have selected Thales to...

17/06/2024

Thales is quadrupling its ammunition production capacity at its La Fert Saint Aubin site to meet the needs of the French Army

Facebook Twitter LinkedIn After an initial order in 2022 for 3,000 rounds ...

17/06/2024

Thales and CEA partner on trusted generative AI for defence and security

Facebook Twitter LinkedIn Thales and the French Alternative Energies and Atomic Energy Commission (CEA) have signed a new partnership agreement in the fie...

17/06/2024

Thales unveils OpenDRobotics to support a new era of extended collaborative combat enabled by AI

Facebook Twitter LinkedIn Thales is launching OpenDRobotics, a revolutiona...

17/06/2024

Thales unveils new range of tactical wideband High Frequency radios

Facebook Twitter LinkedIn Thaless first resilient high-data-rate High Frequency (HF) radio sets for land theatre command posts are on display on the compa...

13/06/2024

MEDIA INVITATION

Facebook Twitter LinkedIn Thales pavilion (stand C242), Parc des Expositions, Paris Nord Villepinte, 17-21 June 2024 Thales is pleased to welcome you to ...

13/06/2024

Thales teams up with Google Cloud to provide organisations with an extensive set of cyber detection and response capabilities

Facebook Twitter LinkedIn Thales and Google Cloud have signed a new partne...

13/06/2024

Thales, Spire Global and ESSP to develop a space-based air traffic surveillance service

Facebook Twitter LinkedIn Thales, Spire and ESSP are joining forces to dev...