The API Security Crisis Exposed By Akamai's State Of The Internet Report
Tech Talks DailyJune 23, 2026
3615
31:5521.11 MB

The API Security Crisis Exposed By Akamai's State Of The Internet Report

How prepared are businesses for a new wave of attacks targeting the apps, APIs, and AI systems now powering digital growth?

In this episode, I speak with Richard Meeus from Akamai Technologies about the latest findings from Akamai's State of the Internet report, with a focus on apps, APIs, and DDoS activity across EMEA.

Richard explains why APIs have become such an attractive target for attackers, especially as AI adoption accelerates. We discuss the sharp rise in API abuse, the growing use of automation to industrialize attacks, and why many organizations still lack visibility into the APIs exposing sensitive data.

We also examine the rise in layer 7 DDoS attacks, how attackers are combining multiple techniques to distract defenders, and why sectors such as retail and manufacturing are facing growing pressure. Richard also shares his view on the geopolitical forces shaping DDoS activity and why hacktivist groups continue to use these attacks as a public statement.

Another major theme is the security risk around AI chatbots. As more organizations deploy chatbots to improve customer service, Richard explains how overly helpful AI systems can expose data, respond to prompt injection attempts, or create new blind spots if the right controls are missing.

But this conversation is not all about risk. Richard also explains why AI can help defenders strengthen visibility, improve testing, analyze logs faster, and support more proactive security strategies.

So, as businesses race to adopt AI and modern digital services, are they paying enough attention to the APIs and infrastructure sitting underneath it all? Share your thoughts.

Useful Links

[00:00:04] What if the risk in your AI transformation is not the model itself, but the APIs, the apps and infrastructure that is quietly sitting underneath it all? Well, today I'm going to be joined by Robert Gerstmann from Akamai. And this is a conversation that gets right into the heart of a challenge that many leaders are only just beginning to fully appreciate. Because yes, we have heard a lot around AI opportunity, productivity and investment.

[00:00:33] But as organizations push harder into digital transformation, attackers are all feeling the same trail. And in many cases, they're heading straight for the APIs that are powering it all. And I think what makes this discussion so valuable is that it takes the latest Akamai State Of The Internet Report and turns a sea of big numbers into something much more practical.

[00:00:59] We will talk about why web attacks across EMEA have reached a two-year high, why APIs have moved from being the overlooked plumbing to a primary attack surface, and how attackers are combining techniques in ways that feel much more systematic, scalable and business-focused than we've seen before. And I also want to learn about what this means for organizations that are trying to keep pace without losing sight of the basics.

[00:01:27] Because AI is absolutely changing the speed and scale of attacks. But Richard will make a strong case that this is not a moment to panic or throw everything out. It's just a moment to strengthen the fundamentals and make sure the tools you already depend on are ready for the world that you're stepping into. So if you want a conversation that cuts through the noise, make sense of what cyber risk is really heading or where it is heading this year, this one's packed with some pretty big takeaways. But enough from me.

[00:01:56] Let me introduce you to my guest right now. So a massive warm welcome to the show. Can you tell everyone listening a little about who you are and what you do? Thanks very much, Neil. So, yeah, my name is Richard Mears, and I work in the security strategy team at Akamai Technologies. And my focus in EMEA, in this region, is to work with our customers and work with our partners,

[00:02:26] ensuring that they are best prepared for all the cybersecurity challenges that they're going to experience now and into the future. And that's done through sort of the Akamai suite of solutions. We've been basically delivering and protecting the Internet for over 25 years now.

[00:02:47] And we have a suite of products that helps to ensure that customers are protected, their users are protected, their websites, their apps, their APIs. The customers are protected from a credential abuse and things like that. And also the internal IT within their organizations. So we've been working together. And what it allows us to do is to generate large amounts of data and telemetry,

[00:03:17] which we put into what we call a state of the Internet report. And this is what we want to talk about today. Awesome. It's a pleasure to have you join me. I've had quite a few people from Akamai on the show over the years. And I know it's a huge organization, but I think the one that stands out is Dr. Robert Blumoff. Oh, Bobby Blumoff. Yes, Bobby is legendary within the industry and within the company. Dr. Blumoff is much a luminary.

[00:03:45] His talks and his presentations are always illuminating. Every time I have a chance to talk to Bobby, I learn something new. He's an incredibly cool guy. And one of the reasons I was excited to get you on today is after reading the latest Akamai State of the Internet report for this year, especially around apps and APIs and DDoS, I think it highlights a sharp rise in web attacks across EMEA. So what is driving this latest surge and what's changed?

[00:04:13] Just to give you some context, the State of the Internet report, we do this every couple of months. And because we see so much traffic at Akamai, we sort of slice and dice all of this telemetry on a regular every couple of months into various different focus points. So sometimes we do it by vertical, so publishing, or it might be for gambling or for financial services. And sometimes we do it by Taktams and maybe DDoS.

[00:04:38] And this time we're sort of focusing on apps, APIs, and DDoS, mainly around sort of what was happening in 2025. And this focus is quite interesting. We look at it on a global scale and then we sort of zero in on to various regions, LATAM, North America, EMEA, and APJ. And we saw a steady increase throughout 2025 within EMEA. And then a bit of a spike in Q4, which was surprising.

[00:05:09] And a lot of us are doing, yes, AI is definitely involved. It's industrializing the attacks. It's making them faster, cheaper, more scalable. And that's due to a combination of automation and AI. We've also seen a big increase in attacks specifically against APIs. And this sort of contributes to that sort of large sort of up ramp that we were seeing,

[00:05:35] sort of a 113% increase on sort of attacks per company over the course of that year. So I think it's sort of a combination of a new attack vector or more focused attacks on APIs and AI helping to industrialize the attacks. And every person listening from every organization should know all about APIs. They are the connective tissue of the modern digital economy. And I think everybody relies on them.

[00:06:03] APIs are now being described as the primary attack surface, especially as AI adoption accelerates. We probably assume that that is going to continue as well. So why have APIs suddenly become such an attractive target for attackers? Or have they always been? I think that APIs have sort of steadily increased in usage over the last few years.

[00:06:26] But the increase in usage was not matched by the increase in security, focus, and awareness upon them. So even though they increased in usage and effectiveness, the security didn't follow. And especially now with AI, because we have to talk about AI, it impacts us all. Behind all AI is an API endpoint. And this becomes increasingly important.

[00:06:55] I mean, APIs were unloved, but in the security sense, to a massive degree anyway. Now we put AI on top of it. So the security focus is even more concentrated. We need to really start looking at how we utilize our APIs. The visibility aspect is huge. Most organizations do not know how many APIs they have. Most organizations do not know how many APIs have sensitive data in them.

[00:07:23] And then when you layer on top of that, that you're going to have AI in front of that, going to do all manner of things through those APIs, you begin to lose visibility about exactly what's happening. Most organizations, for example, have about 3,000 APIs that have sensitive data. But if you ask many organizations, they wouldn't have that visibility into that. They don't know where those APIs are. And there's been a big shift in the way that hackers are going after APIs.

[00:07:53] So if we look at 2024, the split between sort of traditional web-based attack, you know, the SQL injection attacks, those sort of things, against APIs, against behavioral attacks, as in the ones where they are logging in and actually just abusing the business logic, was about a 70-30 split.

[00:08:18] 70% on the traditional sort of web-based attacks that you'd associate, those were going against the APIs, 30% against behavioral. When we look at it last year, it's been flipped to 40-60. So now 60% of all the attacks are behavioral-based. This is being more intelligent. This is logging in as a legitimate user, but being able to abuse the business logic

[00:08:46] to be able to scrape data, to get personal data, to get thousands of records through common attack vectors such as BOLA and BOPLAR, which are acronyms that have been created through the OWASP Foundation where they're describing how the common attacks happen. 60% now as opposed to 30% in 2024. So I think this has been a big shift in the way that APIs are being abused.

[00:09:16] Wow, so many big figures there. And the report also suggests that attackers are now industrializing their methods, turning attacks into scalable and repeatable operations. But for people listening, what does that look like in practice? How should their organization rethink their defenses as a result? Can you maybe bring it to life with an example of what that looks like? Yeah, I think it's not necessarily about rethinking. It's about evolving. AI is helping to industrialize.

[00:09:46] Automation is helping to be industrialized. And this means that Layer 3, Layer 4, Layer 7 DDoS, plus DNS attacks, plus API attacks, plus the traditional web attacks, are being used as sort of a homogeneous attack vector. So they're being used together. So rather than being individual, where it was just a volumetric DDoS attack, or it was just a Layer 7 DDoS attack, they're now being used in combination.

[00:10:14] And automation AI are helping to wrap this up nicely to be able to try and get around traditional defenses. But organizations still need to go back to fundamentals. The fundamental tools still need to be there. We don't want to be chasing just an AI point product solution to protect against a specific element. We still need to get the fundamentals right about our access rights,

[00:10:40] our rate controls, how abuse is being managed. We know that AI is going to be a force multiplier, so we need to use a better understanding of what our assets are. We need to be using things like behavioral analytics, anomaly detection, and automated mitigation to help strengthen our defensive. But we don't want to throw existing everything out what we've already done.

[00:11:08] We just need to make what we have better, stronger, faster. A sort of $6 million man analogy of being able to leverage AI into our traditional defenses and really get the most out of those. Because if we omit the fundamentals of what we've been trying to do, we will create gaps. Now, we're also seeing Layer 7 DDoS attacks rise dramatically alongside API abuse as well. So how are attackers combining some of these techniques?

[00:11:37] And why is this combination proving so effective as well? Layer 7 DDoS attacks is quite interesting. That sort of evolves in various different regions. We've seen Layer 7 DDoS attacks be phenomenally popular over in APJ, for example, than that's in Asia Pacific. And that's been very common for a number of years. We're now seeing increases of it in EMEA as well. And over the last two years,

[00:12:04] we saw the Layer 7 DDoS attacks increase by like 104%. And I think there's various reasons behind this. One, there is the proliferation of ransomware, of DDoS as a service. So we've had the legacy sort of Mirai botnet that has evolved over the years. So we now have Turbo and Mirai. And these tools are available to many organizations

[00:12:31] to launch these Layer 7 DDoS attacks. But what's quite interesting is that they are sort of seen in conjunction with other attack vectors. So one of the things that Layer 7 DDoS attacks do is that they can be quite subtle. They can be under the radar. They can be used in a way to basically increase cost. So you can get things like performance degradation, cost spikes, and consequently much harder to spot.

[00:13:00] You don't realize that you're being attacked until you sort of see your cloud bill at the end of the month. But what we're also seeing now is a sort of rehash of what was happening until 10 years ago, where DDoS was used to basically provide a sort of blanket attack, create a lot of noise, while somebody would then go and abuse a SQL injection query or something like that, or try and get it in through an unpatched VPN.

[00:13:28] We're seeing sort of similar sort of stuff now with Layer 7, where Layer 7 is used to launch attacks, to distract organizations, so they can also do additional API and web application attacks. I'd like to thank Denodo for supporting the Tech Talks network and helping us bring so many different stories to life, because every business needs data that its teams can actually trust. So if you need data your teams can trust,

[00:13:57] Denodo can help your organization deliver curated, governed, and easy-to-use data products for analysts, business users, and AI applications alike. And you can learn more by simply visiting denodo.com. And I suspect we will have a few people listening from organizations that still treat application security and API security as completely separate challenges. And I'm curious, does this create risks,

[00:14:24] and how should leaders maybe think about bringing these strategies together? I think because API security and application security sort of evolved at different timelines, sort of application security sort of had a 10-year head start on it, and everybody sort of assumed that what we were doing, APIs was just like naturally covered by what we were doing with the web. But it wasn't. It got left behind.

[00:14:51] And the way that we were looking at API security as a whole was dramatically behind what we were doing with the web. Unfortunately, the attackers realized this, and they're fully tooled up. But everybody else, all the defenders, were like 10 years behind. So we have to sort of realize that the attack surface for APIs is a lot larger than it is for websites. As we sort of mentioned earlier,

[00:15:20] most organizations will tell you how many websites they've got. They won't tell you how many public-facing APIs they've got, or even Intel API, or which ones are facing or are hosting personal data. It's 3,000 APIs in a traditional organization have personal data. So organizations do have this sort of gap where the APIs have a larger attack surface, but they're not protected,

[00:15:49] and they don't have the visibility around that. So we need to have a more comprehensive view. We need to be treating APIs as basically the gateway to the organization. And there's more information that's passed back through the APIs than it is through the website. We need to get that visibility and that control, the authentication, and the authorization through the APIs to ensure that they are locked down and we have that control and visibility across them.

[00:16:18] And the data also shows that some sectors, like retail and manufacturing, are particularly being heavily targeted too. So what is it that makes these industries so vulnerable, and what lessons can maybe other industries learn from what's happening there? I think retail and manufacturing have always been targeted heavily, especially retail. People want stuff for free. So that's a common thing we've always seen, especially around commerce.

[00:16:47] So there'll always be an attack to see what they can get out of that. I think also with manufacturing and retail, there isn't the same sort of levels or burden of regulation that you get in other industries, such as financial services or in sort of critical national infrastructure. And therefore, there's less focus on being able to provide the financial services, financial ability to put the controls in place.

[00:17:16] So I think there's always an element of that. There's also, with especially retail, there's a rush, there's a need to get new products to market very quickly. There's always, and this is where things like APIs in the past and AI have become fantastically useful in creating the ability to deliver new websites, new services, new functions very, very quickly. But this speed and this pace that is intrinsic within things like retail

[00:17:46] creates a challenge for security for security to keep up. They're also very aware that things like retail, especially, is that they have certain times of year when they are especially vulnerable because they generate huge amounts of revenue at certain times of the year. And trying to target them at those specific times of the year means that they are especially sort of vulnerable to ransomware attacks

[00:18:13] and DDoS attacks that can be used to enforce leverage, for example. And there's also a huge geopolitical element in DDoS activity right now, especially across EMEA. And I'm curious, how are global events influencing attack patterns and anything else that businesses should be watching for this year? Because it feels that there's a lot of uncertainty out there and a lot of different attacks coming in.

[00:18:40] Yeah, so DDoS has always been an interesting attack vector. And as opposed to like a web application attack or an API attack or somebody trying to gain access through an unpatched VPN gateway, a DDoS attack is generally quite public. You know, it really is the equivalent of smashing in the front door or coming into your main business

[00:19:10] and smashing the plate glass windows in the front. It's an obvious statement. And hence, it's commonly used by the hacktivist as opposed to the cyber criminal who just wants the cash. DDoS is used by the hacktivist. These are the organizations that want to make a political statement, that want to maybe echo kinetic activity with cyber activity. So, for example, we see a lot of activity

[00:19:40] from people like NoName5716. They've been active since 2022 and have sort of affiliations or they have the same sort of affiliations as to Russia, along with the CARR, which is the Cyber Army of Russia Reborn. A lot of activity around those, which is sort of driven up from what happened in 2020 and the invasion of Ukraine. So, we see a lot of sort of cyber activity

[00:20:09] that follows that kinetic activity. We've also seen, obviously, lots of activity recently this year as well because of the increased activity around what's been happening in Iran as well. And therefore, there's been a corresponding amount of activity from pro-Iranian groups as well. And this is nothing new. This has always happened when anybody has a, either a following of a kinetic, following a kinetic battle,

[00:20:37] or there is somebody who has a political disagreement with certain organizations. If you want to go back to 2012, for example, when we had WikiLeaks, you know, there was a lot of DDoS activity then. That was just because of somebody having a disagreement and a different opinion. And therefore, the ability to do DDoS is a very public way of trying to destabilize, to get an opinion across at large. And it can impact thousands

[00:21:06] or millions of people within a certain geographical area. And for leaders listening today who are probably investing heavily in AI and digital transformation of everything, is there a single most important step that you think they should take to maybe better secure their infrastructure that is underpinning their growth? Because everyone's going so fast at the moment and implementing so many different things. We've got agentic AI agents, et cetera, as well. Any important steps that you would advise listeners

[00:21:36] to think about? Focus on the fundamentals. The tech that underpins all of this is still the same tech. Like, it still works an awful lot faster. It's an awful lot more intelligent. But the basic fundamentals are still the same. We're still working with those core concepts. We just need to energize them. We need to give them more visibility and more control. But the fundamentals still exist. And we shouldn't ignore that

[00:22:05] and just sort of go after sort of shiny new tools. We need to focus on the fundamentals. But that means giving them more power, more visibility, more control. And that means, yeah, we need to use AI to look at all the logs that we have. We need to use AI to find new variations of SQL injection attacks. We need to use AI to understand, say, to help with our proactive testing. But we also have visibility inside our state to understand

[00:22:36] where shadow AI is using. And therefore, consequently, maybe we've got shadow APIs that are being spun up, you know, to maybe people are running things like MaltBot, MaltBot inside our organization. And there could be an inherent risk through that. So understanding all of the new tools that are being brought into, visibility comes down to, and proactive testing. And before I let you go, there's a lot of hype at the moment around AI chatbots and agents, et cetera. So any risks

[00:23:05] that AI chatbots could introduce as targets for things like social engineering and anything organizations listening should be doing to maybe adapt their controls to ensure that they stay secure? It feels like a big talking point at the moment. I'm curious if you have any thoughts on that. Yeah, chatbots are most organized, most people's sort of traditional interaction with AI is through a chatbot. And we do that through the frontier models, you know,

[00:23:35] the chat GPTs and the anthropics and all those sort of things with the Gemini's. But also, when you're talking to an organization, you go onto their webpage, chances are they'll have a little icon bottom right-hand corner where you're going to start talking to them. It used to be a very hierarchical model on somebody's website, on their support website. You know, how can I help you today? And it was very, normally hierarchical and after three clicks, you'd normally ended up speaking to a human being because the hierarchy didn't work. Now with AI,

[00:24:04] it's got access to all of those previous support queries and it's able to give you a lot more information and that is fantastic. It's a huge boom for organizations to be able to service their customers far more effectively. But the point, the problem is is that AI models, the chatbot wants to help. It really, really wants to help and if you're sure if you ever use a common chatbot and when you ask a question,

[00:24:34] you very rarely get a succinct answer. Normally, you get quite of a both answer because it wants to help. It wants to give you as much information as possible about these things you need and this is one of the things that AI models can be abused and those chatbots can be abused because they want to be overly helpful. It can be quite easy to get them to give you more than you need and it can be quite easy to get them

[00:25:03] to give you more data than is required to divulge information that is specifically being told not to because it really wants to help you and there's also things called prompt injection and prompt engineering now where it allows you to type in various commands type in various controls to get information out of it to get information so if you're a commerce organisation it may be able to give you discount codes it may be able

[00:25:32] to give you passwords for particular products and services that are for the root passwords and things like that maybe it's able to give you specific banking information in front of the person because it's trying to be helpful and one of the things I think organisations are missing out on at the moment is that when they're deploying chatbots is what controls are they putting around that do they really know what's happening in that conversation flow

[00:26:01] what questions are being asked of their chatbots and what information is being provided by your platform out by their chatbots to the public and we have focused today a lot on risks attack vectors etc and things that organisations can do but there is also a lot of good news out there many teams are adopting a more proactive than reactive approach now and I'm curious when you read through the report and there was a lot of familiar things in there I would imagine was there anything that made you very

[00:26:31] optimistic about where we're heading and attitudes towards this stuff now I think one of the things is that we tend to hear a lot about AI is going to make a lot of weaponisation and automation and I think that's definitely going to be a situation but I also think that AI can be used very effectively in helping our traditional defences in galvanising them and giving them more

[00:27:01] power more visibility more control and also to do things like proactive testing things where it would take months to do effective testing can now be done in hours so we're going to get better visibility and better control to our states through leveraging tools like AI Awesome well thank you so much for sitting down with me today I will include a link in the show notes to the apps APIs and DDoS state of the internet report I encourage people listening to check that out I'll also

[00:27:31] include a link to your LinkedIn if people want to reach you anywhere else you'd like me to point everyone I think the akamai.com security is a very good repository also do check out the akamai.com blog where we do lots of very focused reports we're doing a lot of reviews on specific application based attacks we do a lot of stuff on Intel based attacks on vulnerabilities

[00:28:01] we do a lot of assessments on patch Tuesdays for example and give a bit more detail on that so there's lots of really rich data within that as well so I do encourage you to visit the blog on a regular basis I know there were so many big stats in that report you mentioned today EMEA as a region averaging 69% more attack attempts than the last seven quarters in I think that was in 20 towards the end of 2025 retailers subject to 15.5 billion web attack

[00:28:30] attempts but there is so much positivity in there I urge everyone listening to check out the links and learn more about anything we talked about Richard thank you for sitting down with today and bringing all these insights to life really appreciate your time thank you very much indeed Neil it's been great to

[00:29:13] treated as almost a background infrastructure many organisations simply haven't given the same level of attention visibility or protection as they do the front end applications everyone can see and attackers well they've clearly noticed this and I think Richard made an important point when he said that this is about evolution not ripping everything out starting again because there is always a temptation in tech to believe the latest threat demands a completely no answer

[00:29:42] but in reality it's the fundamentals that matter more than ever visibility still matters good authentication and testing still matters and the difference now is that all of those things need to operate with more speed context and a better understanding of how modern attacks actually behave and yet there is the chat bot piece which I think will resonate with a lot of people at the moment and that creates a whole new set

[00:30:12] of questions around prompt injection data leakage and control and I think it's another reminder that every shiny new interface also opens a new door and somebody out there is already checking whether it's locked and at the exact same time there's also optimism in this conversation too because AI is not just helping attackers move faster it's also giving defenders better ways to analyze test detect and respond

[00:30:43] and that matters and it means that this is not a story about technology running away from us it's more a story about whether organizations can use it wisely enough to keep up so I'd love to hear your thoughts on this one as your business races to build with AI are enough of your teams paying attention to real exposure sits quietly in the background

[00:31:15] as always let me know techtalksnetwork.com love to hear from you on this one and we'll keep this conversation going but yet we're out of time already I'll be back again tomorrow with another guest hope you enjoyed today's as much as I did and I'll speak to you again tomorrow remember please check out tech talks network and the event page I've got back to back events up