Business Wire

Traceable Releases 2025 State of API Security Report: API Breaches Persist as Fraud, Bot Attacks, and Generative AI Increase Risks

30.10.2024 13:25:00 CET | Business Wire | Press Release

Share

Traceable AI, the industry's leading API security company, today released its second annual research report—the 2025 Global State of API Security. The findings demonstrate that organizations are failing to protect their APIs despite persistent breaches and increased awareness of security risks. This comprehensive study, incorporating insights from over 1,500 IT and cybersecurity experts across the US, UK, and EMEA, reveals fundamental weaknesses in API security strategies and tracks how these issues have shifted since our inaugural report.

Key findings examine the most pressing API security issues organizations face today: increasing bot attacks and fraud, risks from third-party APIs, and the new security implications of generative AI applications.

Download the full report for in-depth analysis.

Key Findings Include:

  1. API-Related Data Breaches Continue to Wreak Havoc: 57% of organizations suffered an API-related data breach in the past two years, with a staggering 73% of these experiencing three or more incidents. Even more concerning, 41% endured five or more breaches, revealing a systemic failure in API defenses and a clear need for investment in purpose-built API security solutions.
  2. Traditional Security Solutions Fail to Deliver API Protection: Despite deploying an array of security tools—from legacy WAFs to CDNs and Gateways—only 19% of organizations rate their defenses as highly effective. Moreover, 53% admit that traditional solutions like WAFs and WAAPs are ineffective at identifying or preventing fraud at the API layer.
  3. Generative AI Applications Create New Risks: 65% of organizations state that generative AI applications pose a serious to extreme risk to APIs. 60% state that the additional API integrations required for generative AI applications expand their organization’s attack surface; the same percentage cite concerns about sensitive data exposure and unauthorized access.
  4. Bot Attacks and Fraud are Rampant: 53% of organizations have experienced one or more bot attacks involving their APIs, and 44% say that bot mitigation is a top challenge. Fraud is equally concerning, emerging as the second most prevalent cause of API-related data breaches among survey respondents.
  5. Third-Party APIs Are a Hidden Danger: Organizations now use an average of 131 third-party APIs, up slightly from last year's 127. Yet, only 16% have a “high ability” to mitigate these external risks, leaving a vast attack surface greatly exposed.

"API breaches are rampant, and the industry is in denial,” said Richard Bird, Chief Security Officer of Traceable. “Organizations keep deploying the same solutions—Web Application Firewalls, API gateways, and lifecycle tools—yet only a small percentage report any real success. This cognitive dissonance is a ticking time bomb. The truth is, these traditional defenses are failing, and the more companies rely on them, the more they expose themselves to devastating attacks. We’re also seeing a surge in bot attacks, increasing instances of API fraud, and new vulnerabilities emerging from the rapid adoption of generative AI applications. Companies must confront the uncomfortable truth: their current strategies are inadequate. Without a fundamental shift in how they secure APIs, breaches and their consequences will continue to escalate.”

Traceable conducts this annual research to provide organizations with an objective assessment of API security risks and trends. By tracking these patterns and emerging threats, we aim to offer security leaders the knowledge needed to make informed decisions and prioritize the most important security challenges. Our commitment is to ensure that as APIs continue to be central to business operations, organizations have the insights they need to protect their critical assets.

Download the full 2025 State of API Security report today.

About Traceable

Traceable’s intelligent and context-aware solution powers complete API security, API discovery and posture management, API security testing, attack detection and threat hunting, and attack protection anywhere your APIs live. Traceable enables organizations to minimize risk and maximize the value that APIs bring their customers. To learn more about how API security can help your business, book a demo with a security expert.

View source version on businesswire.com: https://www.businesswire.com/news/home/20241030645718/en/

Contacts

Ryan Romana
Touchdown PR
traceable@touchdownpr.com

(c) 2024 Business Wire, Inc., All rights reserved.

Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Celltrion Expands Omlyclo ® Portfolio in Europe with Launch of 300 mg Strength25.8.2026 00:40:00 CEST | Press Release

Celltrion (KRX: 068270) today announced the launch of the 300 mg strength of Omlyclo® (omalizumab), a treatment for chronic spontaneous urticaria and allergic asthma, in Europe.1 With the addition of the 300 mg strength, Celltrion has expanded its Omlyclo® portfolio to include multiple dose strengths and device presentations for patients, healthcare professionals and healthcare institutions. Following the European launch of Omlyclo® 75 mg and 150 mg late last year, Celltrion began rolling out the 300 mg strength in key markets including Germany, the UK and France in the middle of this year. Celltrion is gradually expanding supply to other European countries and plans to complete the rollout across Europe by the end of the year. Celltrion is offering Omlyclo® 300 mg in both pre-filled syringe (PFS) and autoinjector (AI) presentations, allowing patients and healthcare professionals a choice of device depending on the treatment setting and individual patient needs. This comprehensive port

Fourthline Trust Services Granted Status as Qualified Trust Service Provider in the EU24.8.2026 15:13:00 CEST | Press Release

Fourthline Trust Services AB, a subsidiary of Fourthline, has been granted qualified status under the EU's eIDAS Regulation (910/2014)¹ and is now listed on the EU Trusted List as a Qualified Trust Service Provider (QTSP). Supervised by the Swedish Post and Telecom Authority (Post- och telestyrelsen, PTS), Fourthline Trust Services AB issues qualified certificates for electronic signatures. Fourthline, is the leading European provider of AI-powered identity verification (IDV) and compliance solutions. This milestone allows Fourthline full control over the entire digital trust value chain from identity verification to qualified electronic signature (QES) issuance. Ralph Post, Fourthline Trust Services AB Board Member: "By building our QTSP infrastructure similar to our sovereign AI-powered platform that drives our industry-leading identity verification, we're able to offer unprecedented security, performance, and innovation. Organisations can now accelerate their digital transformation

SLB Launches ExaCT Electrical Downhole CT Control System24.8.2026 13:02:00 CEST | Press Release

SLB (NYSE: SLB) today launched the ExaCT™ electrical downhole coiled tubing (CT) control system, an advanced intervention platform that introduces real-time electrical control to coiled tubing operations. By replacing pressure-dependent hydraulic actuation with electrical communication, power delivery and telemetry, the ExaCT system gives operators greater visibility, precision and control, helping improve intervention execution and reservoir access. The ExaCT system combines electrical power, telemetry and downhole measurements to enable communication with, actuation of and verification of downhole tools throughout an intervention. Continuous communication across the toolstring enables on-demand tool actuation across a wide range of intervention applications, including extended-reach and multilateral wells. The increased precision and control provided by the system help operators optimize reservoir access, improve production performance and maximize recovery. "Operators are asking int

Wolters Kluwer Transforms Trusted Legal Content Into Structured, AI-Ready Intelligence That Powers the Next Wave of Legal AI24.8.2026 13:01:00 CEST | Press Release

Wolters KluwerLegal & Regulatory today announced the next evolution of Libra by Wolters Kluwer, its all-in-one Legal AI Workspace. By transforming authoritative legal sources, expert commentaries, and practical guidance into structured legal intelligence, Wolters Kluwer is making the relationships across the full breadth of its expert legal sources more explicit. This will enable deeper contextual research, more comprehensible answers, and workflow-ready results across legal work. Following the integration of Wolters Kluwer content into the Libra AI workspace in the first half of 2026, laws, rulings, expert commentaries, and practical guidance will now be linked to one another and to the matter at hand, creating a connected knowledge graph of expert-curated and authoredlegal knowledge that AI can reason over. For customers, this means research that surfaces the right authority faster, answers with even clearer reasoning and sources, drafting guided by matter-specific context, and great

Daiichi Sankyo Appoints Markus Kosch to Lead Europe Business as Part of New Commercialization Organization24.8.2026 10:00:00 CEST | Press Release

Daiichi Sankyo (TSE: 4568) today announced the appointment of Markus Kosch, MD, as Head of Europe Business, effective April 1, 2027. In this role, he will lead the company's European business within the new globally integrated Commercialization Unit and serve as General Manager of Daiichi Sankyo Europe GmbH, with legal responsibility for the company in Europe. The appointment reflects the next phase of growth of Daiichi Sankyo under its Five-Year Business Plan and the establishment of a new Commercialization Unit. Within this new structure, Markus Kosch will bring together the Oncology and Specialty businesses in Europe under one integrated leadership model to help bring innovative medicines to more patients across the region. For the past five years, Markus Kosch has led the Daiichi Sankyo Oncology Business Division in Europe and Canada, overseeing a period of significant growth and preparing the organization for an increasingly expanding oncology portfolio. Prior to joining Daiichi S

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye