Vulnerable APIs and Bot Attacks Costing Businesses up to $186 Billion Annually
18/09/2024
API insecurity and automated abuse by bots responsible for up to 11.8% of cyber events and losses globally
Bot-related security incident count rose 88% in 2022 and 28% in 2023
Insecure APIs result in up to $12 billion more in losses than they did in 2021
@Thales Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, releases the Economic Impact of API and Bot Attacks report. The analysis of more than 161,000 unique cybersecurity incidents and investigates the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186[1] billion for businesses around the world.
The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs.
Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from Imperva Threat Research finds that the average enterprise managed 613 API endpoints in production last year. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency.
Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats accounted for 30% of all API attacks, according to data from Imperva Threat Research. Today, automated API abuse by bots costs organizations up to $17.9 billion of losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data.
It's imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.
Some of the key trends identified in the report include:
Increased API adoption and usage is growing the attack surface: The rapid adoption of APIs, inexperience of many API developers, and lack of collaboration between security and development teams has led insecure APIs to now result in up to $87 billion of losses annually, a $12 billion increase from 2021.
Bots negatively impact organizations' bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots.
API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats.
Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses.
Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country.
Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models, adds Singh. At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.
Additional Information:
Download a copy of the The Economic Impact of API and Bot Attacks report for additional insights on the business impact of API and bot-related security incidents.
See how Imperva Advanced Bot Protection and API Security can protect websites, applications, and APIs from automated attacks and without affecting the flo
LINK: | https://www.thalesgroup.com/en/worldwide/defence-and-security/press_re... |
See more stories from thales |
Most recent headlines
09/12/2024
Dalet Named an IDC Innovator in Media and Entertainment
Dalet, a leading technology and service provider for media-rich organizations, today announced that it has been named an IDC Innovator in the IDC Innovators: ...
23/11/2024
Heartwarming Out of My Mind Highlights the Importance of Disability Advocacy
PARK CITY, UTAH - JANUARY 19: (L-R) Judith Light, Rosemarie Dewitt, Luke Kirby, Michael Chernus, Phoebe-Rae Taylor, Sharon M. Draper, Amber Sealey, and Courtney...
23/11/2024
TCLtv+ Adds 23 CBS Fast Channels
LOS ANGELES/NEW YORK TCL's streaming service TCLtv+ has struck a content deal with Paramount Streaming that will add 23 CBS FAST channels to its lineup....
23/11/2024
Viamedia Signs Ad Rep Deals with 7 More Service Providers
LEXINGTON, Ky. The independent advertising rep firm Viamedia has further expanded its sales network with news that it has agreements to manage advertising sale...
23/11/2024
The Trade Desk Jumps Into Streaming TV With Ventura OS
VENTURA, Calif. Programmatic ad giant The Trade Desk is pushing into the streaming technology business with a new operating system called Ventura....
23/11/2024
Writers Guild, 3 PBS Stations Reach Tentative Agreement for New Contract
BOSTON, LOS ANGELES AND NEW YORK The Writers Guild of America has announced that it has reached a tentative agreement with management at PBS member stations WGB...
23/11/2024
Supreme Court to Consider Legality of FCC's Universal Service Fund
WASHINGTON, D.C. The U.S. Supreme Court has agreed to hear an appeal in a case that alleges the FCC does not have the authority to decide how funds from the Uni...
22/11/2024
Michelle Satter to Be Honored at 2025 Sundance Film Festival Gala Celebrating Sundance Institute Presented by Google TV
Sean Wang, Julian Brave NoiseCat, and Emily Kassie to Receive Annual Vanguard Aw...
22/11/2024
Spotify Inks a New Partnership With Bloomsbury To Offer A Greater Assortment of Audiobooks
Our library continues to grow. In 2022, we announced the addition of audiobooks ...
22/11/2024
SBS wins Australian Podcast Publisher of the Year for third year running
SBS wins Australian Podcast Publisher of the Year for third year running 22 November, 2024 Media releases An outstanding slate of multilingual, multicultur...
22/11/2024
Film Lighting: a Cinematic Guide w/ Free Lighting Plots
Home Applications Film Lighting: a Cinematic Guide w/ Free Lighting Plots Your Guide to Film Lighting In this guide, we'll explore the history of fil...
22/11/2024
Fox, Hulu Renew Content Deal
Fox Entertainment and Hulu have renewed a multi-year content distribution agreement that will keep in-season streaming rights for Fox's programming slate on...
22/11/2024
Academy Award-Winning Film Studio Caviar Signs Director Duo MAMA
Academy Award-Winning Film Studio Caviar Signs Director Duo MAMA Brie Clayton November 22, 2024 0 Comments Academy Award-winning independent film stud...
22/11/2024
A Creative Alliance for Black Friday: Independent Software Makers Unite for Photographers
A Creative Alliance for Black Friday: Independent Software Makers Unite for Phot...
22/11/2024
Partial Bold Text using After Effects expressions UPDATED
Partial Bold Text using After Effects expressions UPDATED Graham Quince November 22, 2024 0 Comments Now with an improved expression for Per Word Se...
22/11/2024
John Lawson Steps Down as AWARN Executive Director
WASHINGTON John Lawson, longtime broadcast alerting advocate and founder of the AWARN Alliance, said he is stepping down as its executive director to work full-...
22/11/2024
Red, white and Blue Lucy UK media tech provider reaches across the Pond
Entering the American market follows a period of significant growth for the company By Matthew Corrigan Published: November 22, 2024 Entering the American...
22/11/2024
Warner Bros. Discovery Introduces Shop With Max and Moments
NEW YORK Warner Bros. Discovery Advertising Sales has incorporated Kerv's AI-enhanced technology into its ad-tech platform and launched two new ad offerings...
22/11/2024
EDO, Vizio Ink New Multiyear Smart-TV Data Licensing Pact
NEW YORK Vizio's Inscape, a smart-TV data provider, and EDO said they have extended their longstanding data partnership....
22/11/2024
New Pixotope Reveal Enables AR, Virtual Production Without Green Screens
OSLO, Norway Live augmented reality and virtual production specialist Pixotope Technologies has launched Pixotope Reveal, an AI-powered background segmentation ...
22/11/2024
Nominations Open for 2025 NAB Technology Awards
The National Association of Broadcasters has opened nominations for the 2025 NAB Technology Awards, recognizing excellence in broadcast engineering, digital lea...
22/11/2024
Thanksgiving TV Sports Ad-Spend Binge To Hit $624 Million
In between helpings of turkey and other Thanksgiving Day fare, viewers will see companies dishing up hefty portions of ads on sports programming, with the natio...
22/11/2024
8 Channels Added to MyFree DirecTV Streaming Lineup
Following the recent launch of the MyFree DirecTV free-ad supported package of 70-plus streaming channels, DirecTV has launched eight new channels catering to s...
22/11/2024
Viant, Disney Advertising Expand CTV Ad Collaboration
IRVINE, Calif. Viant Technology said it has expanded its agreement with Disney Advertising that's focused on making premium connected TV, video and display ...
22/11/2024
Xumo To Make Ad Inventory Available Programmatically With PubMatic
PHILADELPHIA and REDWOOD CITY, Calif. Xumo, the streaming platform joint venture of Comcast and Charter Communications, has reached an agreement to make its pre...
22/11/2024
Mediaocean To Acquire Innovid, Will Merge It With Flashtalking
NEW YORK Privately-held ad tech giant Mediaocean has inked a definitive agreement to acquire Innovid, an independent software platform for advertising creation,...
22/11/2024
Viz University introduces new Viz Artist certifications aimed at upskilling designers of all levels
Viz University introduces new Viz Artist certifications aimed at upskilling desi...
22/11/2024
NBC Sports President Rick Cordella on How Comcast's NBCU Cable-Net Spinoff Will Impact Sports Ops
NBC Sports President Rick Cordella on How Comcast's NBCU Cable-Net Spinoff W...
22/11/2024
NWSL Championship 2024: CBS Sports Caps Off First Year of In-House Broadcasts With Saturday's Final in Kansas City
NWSL Championship 2024: CBS Sports Caps Off First Year of In-House Broadcasts Wi...
22/11/2024
Premier League To Establish In-House Media-Operations Business for 2026-27 Season
Premier League To Establish In-House Media-Operations Business for 2026-27 Seaso...
22/11/2024
SailGP Season 5 Set to Be Most Expansive Yet'
SailGP Season 5 set to be most expansive yet' By George Bevir Friday, November 22, 2024 - 10:34 Print This Story SailGP: The New Zealand Sail Grand P...
22/11/2024
SailGP Season 5: New Broadcasters, New Requirements
SailGP Season 5: New broadcasters, new requirements By George Bevir Friday, November 22, 2024 - 10:34 Print This Story The Germany SailGP team in action a...
22/11/2024
SailGP Season 5: AI Cameras to Get Viewers Closer to the Action
SailGP Season 5: AI cameras to get viewers closer to the action By George Bevir Friday, November 22, 2024 - 10:33 Print This Story Getting viewers closer ...
22/11/2024
SailGP Season 5: Getting Umpires Onscreen and More Studio-Based Content
SailGP Season 5: Getting umpires onscreen and more studio-based content By George Bevir Friday, November 22, 2024 - 10:33 Print This Story Australia SailG...
22/11/2024
SailGP Season 5: Enhanced LiveLine Graphics Bring Augmented Reality to Chase Boats
SailGP Season 5: Enhanced LiveLine graphics bring augmented reality to chase boa...
22/11/2024
Full House: Inside Production of the European Curling Championships
Full house: Inside production of the European Curling Championships By Kevin Hilton Thursday, November 21, 2024 - 12:40 Print This Story Curling star Anna...
22/11/2024
NBC Sports President Rick Cordella on How Comcast's NBCU Cable Net Spinoff Will Impact Sports Ops
NBC Sports President Rick Cordella on How Comcast's NBCU Cable Net Spinoff W...
22/11/2024
Sky and Peacock's Original hit drama series The Day of the Jackal scores a second season renewal
Sky and Peacock's Original hit drama series The Day of the Jackal scores a s...
22/11/2024
Rugged Rugby: Conquer or Die' Premieres December 10: A Battle for Supremacy Begins
Back to All News Rugged Rugby: Conquer or Die' Premieres December 10: A Ba...
22/11/2024
Standards Pavilion elevates the role of standards in advancing climate action at COP29
Friday 22 November, Baku, Azerbaijan: As COP29 wraps up in Azerbaijan, the Stand...
22/11/2024
Let's Make Toy Show Day Official
Let's Make Toy Show Day Official The Late Late Toy Show | Friday December 6th | 9:35PM Watch Below The Late Late Toy Show is fast approaching and kids al...
22/11/2024
COOPANS, the Alliance Managing Europe's Largest Air Traffic Volume, Upgrades its Air Traffic Control (ATC) System with Thales
Facebook Twitter LinkedIn COOPANS is a leading international cooperation b...
22/11/2024
Press release
Facebook Twitter LinkedIn Thales confirms that the Parquet National Financier (PNF) in France and the Serious Fraud Office (SFO) in the United Kingdom hav...
22/11/2024
RT General Election 2024: Critical Election Period
The broadcasting regulator, Coimisi n na Me n has removed the traditional broadcast Moratorium for television and radio. In the past, this applied from 14:00 ...
21/11/2024
Neneh Cherry Takes Us on a Musical Journey Inspired by Her Memoir, A Thousand Threads'
Neneh Cherry, a musical trailblazer for more than three decades, is full of stor...
21/11/2024
6 Spotify Audiobook Features That Level Up Your Listening Experience
Since launching our audiobooks offering, we've continuously upped our game on designing a user experience that provides seamless and engaging listening. You...
21/11/2024
SEP 2024 / PAG launches new MPL150 Battery at IBC24
1ST SEPTEMBER 2024 PAG Ltd. UK, the creator of innovative, high-end portable power systems for the film and television industry, has announced the introduction...
21/11/2024
SEP 2024 / PAG Introduces new Cinergy Battery
1ST SEPTEMBER 2024 PAG Ltd. UK, the creator of innovative, high-end, portable power systems for the film and television industry, has announced the introductio...
21/11/2024
Celebrating The Best Of The Best
The HPA Awards exist to honor and recognize the accomplishments of the talented HPA community and to support their efforts with increased awareness and celebrat...
21/11/2024
L3Harris Co-Founder, Chair and CEO Chris Kubasik: Arsenal of Democracy 2.0 Will Require New Ways of Doing Business
He writes in POLITICO: When it comes to protecting our country, innovation and s...