Financial Services at Risk: DDoS Attacks Are Bigger, Longer, and More Complex, Akamai Research Finds
π Financial services are now the primary target for web and API DDoS attacks, surpassing all other industries according to Akamai's latest research.
β±οΈ The median duration of global Layers 3 and 4 DDoS attacks on financial sectors has increased by 738% since 2024 due to AI-powered infrastructure.
π€ Pro-Iran hacktivists and AI-driven bots are weaponizing DDoS tactics to disrupt online banking, payment systems, and critical applications.
π Among surveyed financial service leaders, 96% reported at least one API security incident in the past 12 months, the highest rate of any industry.
π¦ In 2025, 60% of total web attacks and 83% of incursions against API endpoints specifically targeted banking institutions.
πΈ Nearly 80% of financial institutions have faced ransomware attacks in the past two years, yet less than half have adopted advanced security technologies.
π€ Advanced bot activity surged by 147% in late 2025, with one case study showing 96% of site traffic identified as malicious scraping bots.
π DDoS attack methods vary significantly by region, with EMEA targeted for Layers 3/4 attacks (62%), APAC for Layer 7 (52%), and North America for web attacks (44%).
π£οΈ Steve Winterfeld, Advisory CISO of Akamai, stated that cybercriminals are escalating DDoS from nuisance attacks to sustained sieges targeting financial services.
π€ AI is exacerbating security risks rather than reducing them, putting traditional vulnerabilities on "steroids" for attackers.
π The report includes data-supported trends, a guest column by the CISO of FS-ISAC, and practical DNS and DDoS mitigation strategies.
π’ Akamai's SOTI Security reports are now in their 12th year, drawing insights from attacks viewed across its global cybersecurity protective infrastructure.
- Akamai's SOTI Security reports are now in their 12th year, demonstrating long-term industry leadership and consistent delivery of critical cybersecurity insights.
- The report is drawn from attacks viewed across Akamai's cybersecurity protective infrastructure, which handles a significant portion of global web traffic, highlighting the company's massive scale and reach.
- Akamai provides defense in depth to safeguard enterprise data and applications everywhere through its market-leading security solutions and superior threat intelligence.
- Global enterprises trust Akamai for industry-leading reliability, scale, and expertise to grow their business with confidence, leveraging its full-stack cloud computing solutions.
- The report includes practical DNS and DDoS attack mitigation strategies, offering actionable value to organizations seeking to protect against escalating cyber threats.
- Financial services are now the primary target for web and API DDoS attacks, with median attack duration up 738% since 2024 due to AI-powered infrastructure.
- 96% of financial service leaders surveyed reported at least one API security incident in the past 12 months, the highest rate among all industries.
- In 2025, 83% of incursions against API endpoints specifically targeted banking systems, indicating a severe concentration of risk.
- Nearly 80% of financial institutions have faced ransomware attacks in the past two years, yet less than half have adopted advanced security technologies to defend against them.
- Advanced bot activity surged by 147% in late 2025, with one case study showing 96% of all site traffic identified as malicious scraping bots.
- Cybercriminals are escalating DDoS attacks from nuisance levels to sustained sieges that encompass both hacktivism and cybercrime, directly threatening online banking and payment systems.