Traceable Releases 2025 State of API Security Report: API Breaches Persist as Fraud, Bot Attacks, and Generative AI Increase Risks
Traceable AI, the industry's leading API security company, today released its second annual research report—the 2025 Global State of API Security. The findings demonstrate that organizations are failing to protect their APIs despite persistent breaches and increased awareness of security risks. This comprehensive study, incorporating insights from over 1,500 IT and cybersecurity experts across the US, UK, and EMEA, reveals fundamental weaknesses in API security strategies and tracks how these issues have shifted since our inaugural report.
Key findings examine the most pressing API security issues organizations face today: increasing bot attacks and fraud, risks from third-party APIs, and the new security implications of generative AI applications.
Download the full report for in-depth analysis.
Key Findings Include:
- API-Related Data Breaches Continue to Wreak Havoc: 57% of organizations suffered an API-related data breach in the past two years, with a staggering 73% of these experiencing three or more incidents. Even more concerning, 41% endured five or more breaches, revealing a systemic failure in API defenses and a clear need for investment in purpose-built API security solutions.
- Traditional Security Solutions Fail to Deliver API Protection: Despite deploying an array of security tools—from legacy WAFs to CDNs and Gateways—only 19% of organizations rate their defenses as highly effective. Moreover, 53% admit that traditional solutions like WAFs and WAAPs are ineffective at identifying or preventing fraud at the API layer.
- Generative AI Applications Create New Risks: 65% of organizations state that generative AI applications pose a serious to extreme risk to APIs. 60% state that the additional API integrations required for generative AI applications expand their organization’s attack surface; the same percentage cite concerns about sensitive data exposure and unauthorized access.
- Bot Attacks and Fraud are Rampant: 53% of organizations have experienced one or more bot attacks involving their APIs, and 44% say that bot mitigation is a top challenge. Fraud is equally concerning, emerging as the second most prevalent cause of API-related data breaches among survey respondents.
- Third-Party APIs Are a Hidden Danger: Organizations now use an average of 131 third-party APIs, up slightly from last year's 127. Yet, only 16% have a “high ability” to mitigate these external risks, leaving a vast attack surface greatly exposed.
"API breaches are rampant, and the industry is in denial,” said Richard Bird, Chief Security Officer of Traceable. “Organizations keep deploying the same solutions—Web Application Firewalls, API gateways, and lifecycle tools—yet only a small percentage report any real success. This cognitive dissonance is a ticking time bomb. The truth is, these traditional defenses are failing, and the more companies rely on them, the more they expose themselves to devastating attacks. We’re also seeing a surge in bot attacks, increasing instances of API fraud, and new vulnerabilities emerging from the rapid adoption of generative AI applications. Companies must confront the uncomfortable truth: their current strategies are inadequate. Without a fundamental shift in how they secure APIs, breaches and their consequences will continue to escalate.”
Traceable conducts this annual research to provide organizations with an objective assessment of API security risks and trends. By tracking these patterns and emerging threats, we aim to offer security leaders the knowledge needed to make informed decisions and prioritize the most important security challenges. Our commitment is to ensure that as APIs continue to be central to business operations, organizations have the insights they need to protect their critical assets.
Download the full 2025 State of API Security report today.
About Traceable
Traceable’s intelligent and context-aware solution powers complete API security, API discovery and posture management, API security testing, attack detection and threat hunting, and attack protection anywhere your APIs live. Traceable enables organizations to minimize risk and maximize the value that APIs bring their customers. To learn more about how API security can help your business, book a demo with a security expert.
View source version on businesswire.com: https://www.businesswire.com/news/home/20241030645718/en/
Contacts
Ryan Romana
Touchdown PR
traceable@touchdownpr.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Sultan bin Ahmed Visits Al Rahma Village in Sri Lanka26.9.2025 23:21:00 EEST | Press release
His Highness Sheikh Sultan bin Ahmed Al Qasimi, Deputy Ruler of Sharjah and Chairman of the Sharjah Media Council, visited Al Rahma Women’s Village in Puttalam, Sri Lanka, a community dedicated to widows, orphans, and their families. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250926962681/en/ Sultan bin Ahmed visits Al Rahma Village in Sri Lanka (Photo: AETOSWire) His Highness toured the village, exploring its facilities. He viewed the exhibition of the village’s diverse products, which are sold and exported to neighboring villages, and visited the women’s training rooms where sewing skills are taught. He also inspected the medical center, which provides free healthcare services for women and children, and met with children in the village’s garden, designed as a recreational space for them. He inaugurated 40 new houses by cutting the ceremonial ribbon, handing them over to deserving widows. He then visited the classrooms
L&T Technology Services, Siemens Partner for AI-led Transformation in Process Engineering & Smart Manufacturing26.9.2025 11:30:00 EEST | Press release
L&T Technology Services (BSE: 540115, NSE: LTTS), a global leader in AI, Digital & ER&D Consulting Services, announced an expanded partnership with Siemens Limited, a leading technology company focused on industry, infrastructure and mobility. This collaboration aims to advance Machine & Line Simulation and IIoT Technology, setting a new benchmark for innovation within LTTS’ Sustainability segment, which encompasses Process Engineering, Discrete Manufacturing and Industrial Products. Through this alliance, LTTS will utilize the digital technology portfolio of Siemens Limited to deliver simulation-driven automation and IIoT-enabled solutions for diverse sectors including Automotive & Transportation, Industrial Products, and Process & Plant Engineering. By combining Siemens’ flagship platforms, TIA Portal, Industrial Edge, and Tecnomatix, integrated with LTTS’ AI-driven engineering expertise, the partnership will accelerate digital adoption, improve precision in system design, and drive
SES Appoints Joseph Cohen to Board of Directors26.9.2025 09:50:00 EEST | Press release
SES today announced the appointment of Mr. Joseph Cohen, Co-Founding Partner of Trilantic Europe, to its Board of Directors effective immediately. This appointment is part of SES’s ongoing commitment to regularly review and strengthen the composition of its Board with diverse expertise and industry experience, ensuring the company is well positioned for future growth and value creation. Prior to his role as Co-Founding Partner of Trilantic Europe, Mr. Cohen spent over two decades at Lehman Brothers, including as European Co-Head of Lehman Brothers Merchant Banking and on the Investment Management Division’s European operating committee, among other roles. A U.K. citizen, he holds a BSc in Economics from the London School of Economics. Additionally, Mr. Kaj-Erik Relander has decided to step down from the SES Board of Directors, concluding a tenure marked by valuable contributions to strategy and governance. Frank Esser, Chairman of the Board of Directors of SES, said, “On behalf of SES,
SES Confirms Interim Dividend of EUR 0.2526.9.2025 09:45:00 EEST | Press release
The SES Board of Directors has approved the payment of an interim dividend of EUR 0.25 per A-share (EUR 0.10 per B-share) to be paid to shareholders on October 16, 2025, in line with SES’s commitment to shareholder returns. The interim dividend to be paid in October 2025 will be followed, subject to financial results and shareholder approval, by the payment of a final dividend of at least EUR 0.25 per A-share (EUR 0.10 per B-share) in April 2026. Follow us on: Twitter | Facebook | YouTube | LinkedIn | Instagram Read our Blogs > Visit the Media Gallery > About SES At SES, we believe that space has the power to make a difference. That’s why we design space solutions that help governments protect, businesses grow, and people stay connected—no matter where they are. With integrated multi-orbit satellites and our global terrestrial network, we deliver resilient, seamless connectivity and the highest quality video content to those shaping what’s next. Following our Intelsat acquisition, we n
Ant International Unveils AI SHIELD to Enhance Financial AI Security for Clients and Partners26.9.2025 07:31:00 EEST | Press release
Ant International, a leading global digital payment, digitisation, and financial technology provider, today officially launched AI SHIELD to protect AI systems from threats and vulnerabilities, a proactive toolkit to help AI-powered financial services stay secure and compliant as AI rapidly transforms global finance. Ensuring security is at the core of Ant International’s AI strategy, which also prioritises providing domain excellence in FinAI and extending AI services via an AI-as-a-Service platform. AI is integrated across every stage of payment processing at Ant International. In 2024, the company processed more than US$1 trillion of global transactions, all supported by AI. AI SHIELD uses AI Security Docker to address the unreliability inherent in AI services, including bias, security vulnerabilities, and ethical concerns. The increase in AI-caused incidents leads to an annual potential cost of US$57 billion, according to European Journal of Futures Research. While up to 90% of org
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom