Report by Akamai

State of Apps and API Security 2025: How AI Is Shifting the Digital Terrain

8 FINDINGSPublished Apr 22, 2025
View Original Report →

Key Findings

OWASP API Security Top 10–related incidents increased by 32%, revealing authentication and authorization flaws.

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
API

Growth in security alerts related to the MITRE security framework are up 30%

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
MITRE ATT&CKAlerts

There were 7 trillion Layer 7 DDoS attacks targeting the high technology sector from January 2023 through December 2024, making it the most affected industry for this type of attack.

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
DDoSTechnology

Akamai documented 150 billion API attacks from January 2023 through December 2024.

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
APIAPI attack

There were 311 billion web attacks in 2024. This represents a 33% year-over-year increase in web attacks.

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
Web attacks

There were more than 230 billion web attacks targeting commerce organisations, making it the most impacted industry. This is nearly triple the number of attacks experienced by high technology (the second most attacked sector).

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
Web attacksCommerce

In early 2023, Akamai observed monthly Layer 7 DDoS attack numbers of 500 billion. This rose to 1.1 trillion in one month by December 2024.

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
DDoS

Quarterly Layer 7 (application-layer) distributed denial-of-service (DDoS) attack volumes increased 94% year-over-year between Q1 2023 and Q4 2024.

AkamaiState of Apps and API Security 2025: How AI Is Shifting the Digital Terrain·Apr 22, 2025
DDoS