APIs are becoming a worrying security target - here's what your business can do to stay safe

Zero-day attack
(Image credit: Shutterstock) (Image credit: Shutterstock.com)

The number of API-targeted attacks rose significantly as they become a more attractive and reachable target, a new report from Imperva has said.

APIs, or Application Programming Interfaces, are software intermediaries that allow two applications to essentially talk to each other. Some of the biggest benefits of APIs are seamless connectivity, improved user experience, and innovation. For years now, API traffic has been outgrowing human traffic and last year, the researchers said, API traffic constituted more than 71% of all web traffic. This has turned the attention of cybercriminals, who sought to abuse the trend for different purposes. 

That being said, attacks targeting the business logic of APIs constituted 27% of all attacks last year, which is also up by 10% compared to 2022. Account Takeover (ATO) attacks targeting APIs also rose, from 35% in 2022, to 46% in 2023. 

Lucrative attacks

Elsewhere, the report claimed the average number of API calls to enterprise sites is 1.5 billion. The high volumes of non-human, automated traffic, are “undeniably” linked to the rise in automated attacks on APIs, the researchers added. 

As a result, businesses need robust security measures to defend against things like Distributed Denial of Service (DDoS) attacks, or ATOs. In fact, 46% of all ATO attacks targeted API endpoints, they said. Finally, attackers are honing their strategies, and 28% of all DDoS attacks on APIs are going after financial services organizations. 

Traditional security tools, like Web Application Firewalls (WAF), will not suffice, Imperva concludes. API attacks will adeptly masquerade as regular traffic, rendering these defense mechanisms useless. 

Many IT professionals seem to agree with Imperva, as a recent Barracuda report found 55% stating attacks on APIs to be the most lucrative ones for criminals. Barracuda claims that "attackers will often target old vulnerabilities that security teams have forgotten about," and that "multiple layers" of security are needed to secure web apps and APIs.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
API
Businesses are being plagued by API security risks - with nearly 99% affected
Web DDoS attacks see major surge as AI allows more powerful attacks
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Sounding the alarm on AI-powered cybersecurity threats in 2025
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Google Pixel Watch 3 side dial and button
Google Gemini reportedly spotted on Wear OS – could a rollout be close at hand?
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Toni Collette in Hereditary
Everything leaving Netflix in April 2025 – from the scariest movie ever made to a beloved DreamWorks animation with 99% on Rotten Tomatoes
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think