Akamai Research: Web Attacks Up 33%, APIs Emerge as Primary Targets
Surge correlates with accelerated adoption of AI-powered applications
The report also finds that APIs have emerged as primary targets, with Akamai documenting 150 billion API attacks from
In addition, Akamai documents a dramatic rise in Layer 7 (application-layer) distributed denial-of-service (DDoS) attacks against web applications and APIs. Quarterly attack volumes increased 94% year-over-year between Q1 2023 and Q4 2024. In early 2023, Akamai observed monthly numbers of 500 billion, which rose to 1.1 trillion in one month by
Other key findings of the report include:
- There were more than 230 billion web attacks targeting commerce organizations, making it the most impacted industry. This is nearly triple the number of attacks experienced by high technology (the second most attacked sector).
- There were 7 trillion Layer 7 DDoS attacks targeting the high technology sector from
January 2023 throughDecember 2024 , making it the most affected industry. - OWASP API Security Top 10–related incidents increased 32%, revealing authentication and authorization flaws that expose sensitive data and functionality.
- Growth in security alerts related to the MITRE security framework are up 30% as attackers are using advanced techniques such as automation and AI to exploit APIs.
- Shadow and zombie APIs present particularly vulnerable attack vectors within increasingly complex API ecosystems.
State of Apps and API Security 2025: How AI Is Shifting the Digital Terrain also contains a security spotlight on an API attack against an ecommerce company, an explanation of the differences between web and API attacks, regional and industry attack data, and recommended mitigation strategies. The report provides unique insights on risk scoring and technical methods that are designed to assist frontline defenders.
"AI is transforming web and API security, enhancing threat detection but also creating new challenges," said
This is the 11th year of Akamai's SOTI reports. The SOTI series provides expert insights on cybersecurity and web performance and is based on data gathered from our network infrastructure, which processes more than one-third of global web traffic.
About Akamai
Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense in depth to safeguard enterprise data and applications everywhere. Akamai's full-stack cloud computing solutions deliver performance and affordability on the world's most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog, or follow
Contact:
Akamai PR
akamaiPR@akamai.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/akamai-research-web-attacks-up-33-apis-emerge-as-primary-targets-302433477.html
SOURCE