Infosecurity Magazine reports that more than 40,000 API security incidents across over 4,000 environments have been recorded during the first six months of 2025, with attempted credential stuffing and account takeover intrusions against APIs without multi-factor authentication rising by 40%.
Most targeted by API intrusions during the first half of the year were organizations in the financial services sector, followed by telecommunications and internet service providers, travel firms, and entertainment organizations, with Log4j, Oracle WebLogic, and Joomla being the most impacted products, according to an Imperva analysis. Additional findings revealed that almost one-third of API bot activity was attributed to data scraping.
"Organizations must discover every live endpoint, understand its business value, and protect it with context-aware, adaptive defenses if they are to safeguard revenue, trust, and compliance," said Thales Vice President of Application Security Products Tim Chang, who noted that API attacks could exceed 80,000 by the end of the year.
Most targeted by API intrusions during the first half of the year were organizations in the financial services sector, followed by telecommunications and internet service providers, travel firms, and entertainment organizations, with Log4j, Oracle WebLogic, and Joomla being the most impacted products, according to an Imperva analysis. Additional findings revealed that almost one-third of API bot activity was attributed to data scraping.
"Organizations must discover every live endpoint, understand its business value, and protect it with context-aware, adaptive defenses if they are to safeguard revenue, trust, and compliance," said Thales Vice President of Application Security Products Tim Chang, who noted that API attacks could exceed 80,000 by the end of the year.




