APIs Under Fire: Over 40,000 Attacks Hit Major Sectors in First Half of 2025

Security systems observed a sharp increase in API incidents in the first half of 2025, with over 40,000 security events targeting more than 4,000 environments globally. These incidents indicate that APIs — the unseen conduits connecting apps, payments and authentication — are now at the forefront of cybercriminal strategies.

Thales’ API Threat Report for H1 2025, built on Imperva telemetry, shows APIs represent about 14 percent of an organisation’s total attack surface but now draw 44 percent of advanced bot traffic. Attackers are leveraging sophisticated automation. A standout incident involved an application-layer DDoS that peaked at 15 million requests per second against a financial sector API. This large-scale assault underlines how cyber adversaries are combining volume with stealth to bypass traditional defences.

Data-access APIs bore the brunt of attacks, closely followed by checkout- and payment-oriented endpoints. Authentication interfaces accounted for 16 percent, with gift-card or promotion validation endpoints and misconfigured or shadow APIs making up smaller proportions. Shadow APIs — endpoints organisations don’t realise they have or monitor poorly — are described as one of the most serious blind spots.

Credential stuffing and account takeover attempts rose significantly for APIs that lack adaptive multi-factor authentication. Data scraping from high-value fields such as email and payment data is a growing bot activity, while fraud involving coupons or payments exploits weak or ill-validated checkout logic. Remote code execution probes, particularly those targeting known vulnerabilities such as Log4j, Oracle WebLogic, and Joomla, make up around 13 percent of the attack profile.

Financial services, already heavily dependent on real-time API-mediated functions, are under particular pressure. They accounted for 27 percent of API-targeted DDoS traffic in the first half of the year. Other industries targeted included travel, telecoms and entertainment, each facing specific but increasingly complex threats.

Efforts to detect and govern API risk remain uneven. Surveys indicate that nearly all organisations have encountered API security issues over the past twelve months. Vulnerabilities such as broken object-level authorisation, exposure of sensitive data, and weaknesses in API authentication are prominent. Although many companies are increasing budgets for API security, only a small fraction have advanced programmes in place.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Brother “Managed Print Service” Enables Businesses to Reduce Operating Costs and Enhance Efficiency with Flexible Deployment // Trump rebrand propels Slovenia’s .si domain registrations // DITP Promotes Thailand’s Entertainment Industry on the Global Stage with “Thai Night Busan 2026” at ACFM in the Republic of Korea // US court terminates LIBRA and M3M3 investor case // Ethiopian troops reclaim Mekelle airport as Tigray leaders retreat // Qupital Unveils World’s First AI-Driven On-Chain E-Commerce Lending Protocol, Accelerating Web3 Global Trade Finance // DeepSeek broadens Huawei software challenge to Nvidia // Israel’s top court restores Arab parties to ballot // Middle East crude exports regain pre-war pace // HID Enhances FARGO® DTC Printer Line to Help Organizations Issue Faster, More Secure ID Cards // Dr Maye Musk, author, supermodel, and dietitian, speaks at the Prudential Leadership Forum // Hong Kong Residential Market Sentiment Turns Cautious as Interest Rate Outlook Shifts // Supreme Court weighs limits on corporate climate lawsuits // Yemen government begins nationwide offensive against Houthis // Thailand’s LTR Visa Hits 12,000 Approvals in Four Years, Adding USD 1.28 Billion to the Economy // GST 3.0 Needs A New Bargain With Taxpayers, A Climate Without Fear // Katherine Ryan returns to Dubai Comedy Festival // Qualcomm secures access to Huawei LogicFolding patents // Cloudflare unveils Clef models to rival Jev // Rasmal, Bilişim Vadisi forge Gulf-Türkiye startup link //