Site navigation

API and Bot Attacks Cost Businesses £141 Billion A Year

Tom Quinn

,

API and bot attack report
Research has found that insecure APIs now result in up to $87 billion (£65.9 bn) of losses annually, while bot attacks are responsible for up to $116 billion (£87.8 bn) in damages.

New research from Thales, the cybersecurity firm, has uncovered the rising financial cost of insecure APIs and automated bot attacks. 

The report, Economic Impact of API and Bot Attacks, analysed over 161,000 unique cybersecurity incidents, and reveals that these threats are costing up to $186 billion (£140.8 bn) every year.

According to the report, larger companies are more vulnerable, with firms earning over $1 billion (£756.7 million) being two to three times more likely to face security incidents involving automated API abuse by bots than smaller businesses. 

Companies with revenues over $100 billion (£75.7 bn) are particularly at risk, with API and bot-related security threats found to make up 26% of all their reported security incidents.

That’s because the complexity of their API ecosystems leaves them exposed, with cybercriminals exploiting weaknesses in insecure APIs to steal sensitive data.

The report found that APIs, which are crucial for seamless communication between different applications and services, have become a prime target for cybercriminals. 

Last year, data from the Imperva Threat Research team at Thales found the average company managed 613 API endpoints, with pressure to deliver more efficient and agile digital services meaning that number is rising.

That means that APIs have become an attractive target for bot operators.

In 2023, bot-driven threats made up 30% of all API attacks, and now cost businesses as much as $17.9 billion (£13.5 bn) annually. As more APIs come online, bots are increasingly being used to find vulnerabilities, bypass security measures, and access valuable information.

The rapid adoption of APIs, coupled with the inexperience of many API developers and lack of collaboration between security and development teams, has led insecure APIs to now result in up to $87 billion (£65.9 bn) of losses annually, a $12 billion (£9.1 bn) increase from 2021.

At the same time, bot attacks are responsible for up to $116 billion (£87.8 bn) in damages, fueled by the widespread availability of attack tools and genAI models which have enhanced bot evasion techniques and lowered the barrier of entry for attackers to launch sophisticated attacks.

Security incidents involving APIs surged by 40% in 2022, while bot-related attacks spiked by 88%, driven by increased digital transactions and geopolitical tensions such as the war in Ukraine.


Recommended reading


Although the pace of attacks slowed in 2023, they continued to rise, with API incidents up by 9% and bot attacks climbing 28%.

Nanhi Singh, general manager of application security at Imperva, said: “It’s imperative that businesses across the world address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden.

“The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks. As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.”

Tom Quinn

Staff Writer, DIGIT

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far