Akamai reveals API security challenges in APAC surge

Across APAC, organisations are moving fast with AI. From customer support to finance and supply chains, everything is becoming AI-driven. But behind this rapid shift sits a less visible layer- APIs, and that’s where the real pressure is building. The latest findings show that API security challenges in APAC are growing faster than most teams can handle.
The issue is simple but serious. Innovation is moving ahead, but security maturity is not keeping pace. This gap is now starting to show real impact, with businesses already reporting financial and operational disruptions linked to API vulnerabilities.
Attacks are rising and getting smarter
The numbers tell a sharp story. In 2025 alone, nearly 65 billion web application and API attacks were recorded in APAC, marking a 23% increase year over year. On a global level, daily API attacks are growing even faster, with most organisations already facing at least one API-related security incident.
But the bigger shift is in how these attacks work. Instead of brute force, attackers are now focusing on business logic abuse. In fact, 61% of API attacks in APAC involved misuse of workflows, like triggering legitimate actions in unintended ways. It’s subtle. Harder to detect. And far more damaging over time.
AI is speeding up both innovation and risk
AI is not just helping businesses; it’s helping attackers, too. AI-powered bots are now mimicking normal user behaviour, making it difficult to separate real traffic from malicious activity. These bots target APIs directly, quietly bypassing traditional defences.
At the same time, AI-driven development is accelerating how APIs are built. But speed comes at a cost. Misconfigurations and weak defaults often slip into production without proper checks. The result? More APIs, more complexity, and a wider attack surface.
Different markets, same problem
The challenge looks different across APAC, but the outcome is similar. In mature markets like Singapore and Japan, the issue is scale. Too many APIs, not enough visibility. In emerging economies such as Vietnam and Thailand, rapid digitisation is outpacing security readiness.
India sits at an interesting intersection. The country’s fast-growing digital ecosystem is heavily dependent on APIs, but it is also among the most targeted for AI bot activity and Layer 7 DDoS attacks. This puts additional pressure on organisations to improve visibility and control over their API environments.
What this means for businesses
For sectors like retail, financial services, telecom, and technology, APIs are now core to operations. That also makes them prime targets. The message is clear—security can’t be an afterthought anymore. A shift is needed: Better visibility into API behaviour, Stronger alignment between development and security teams, and moving toward a Zero Trust API security model
The gap that needs urgent attention
The API security challenges in APAC are not just about rising attacks. They reflect a deeper imbalance between how fast systems are built and how well they are protected. As AI continues to reshape digital services, APIs will remain at the center of both innovation and risk.
Closing this gap is no longer optional. It’s what will define which organisations stay resilient and which ones fall behind.
Read More:
Lexar Udaan 2.0: Elite Indian partners head to Thailand for a landmark summit
AI Infrastructure and hybrid cloud driving channel evolution in India: Lenovo insights
14 Years of ASIRT: Strengthening India’s technology partner ecosystem
AI BPM platform strategy: 1Point1 solutions expands Global CX Delivery with multi-shore model






