API security

Report: API threats exceed 40K in first half

API Application Programming Interface Concept. A programmer types on a laptop, interacting with digital icons representing API development, security, and cloud computing. Application Software Tool,

Infosecurity Magazine reports that more than 40,000 API security incidents across over 4,000 environments have been recorded during the first six months of 2025, with attempted credential stuffing and account takeover intrusions against APIs without multi-factor authentication rising by 40%.

Most targeted by API intrusions during the first half of the year were organizations in the financial services sector, followed by telecommunications and internet service providers, travel firms, and entertainment organizations, with Log4j, Oracle WebLogic, and Joomla being the most impacted products, according to an Imperva analysis. Additional findings revealed that almost one-third of API bot activity was attributed to data scraping.

"Organizations must discover every live endpoint, understand its business value, and protect it with context-aware, adaptive defenses if they are to safeguard revenue, trust, and compliance," said Thales Vice President of Application Security Products Tim Chang, who noted that API attacks could exceed 80,000 by the end of the year.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds