Akamai Technologies, Inc.

NASDAQ Global Select
Neutral 0

Financial Services at Risk: DDoS Attacks Are Bigger, Longer, and More Complex, Akamai Research Finds

πŸ“‰ Financial services are now the primary target for web and API DDoS attacks, surpassing all other industries according to Akamai's latest research.

⏱️ The median duration of global Layers 3 and 4 DDoS attacks on financial sectors has increased by 738% since 2024 due to AI-powered infrastructure.

πŸ€– Pro-Iran hacktivists and AI-driven bots are weaponizing DDoS tactics to disrupt online banking, payment systems, and critical applications.

πŸ“Š Among surveyed financial service leaders, 96% reported at least one API security incident in the past 12 months, the highest rate of any industry.

🏦 In 2025, 60% of total web attacks and 83% of incursions against API endpoints specifically targeted banking institutions.

πŸ’Έ Nearly 80% of financial institutions have faced ransomware attacks in the past two years, yet less than half have adopted advanced security technologies.

πŸ€– Advanced bot activity surged by 147% in late 2025, with one case study showing 96% of site traffic identified as malicious scraping bots.

🌍 DDoS attack methods vary significantly by region, with EMEA targeted for Layers 3/4 attacks (62%), APAC for Layer 7 (52%), and North America for web attacks (44%).

πŸ—£οΈ Steve Winterfeld, Advisory CISO of Akamai, stated that cybercriminals are escalating DDoS from nuisance attacks to sustained sieges targeting financial services.

πŸ€– AI is exacerbating security risks rather than reducing them, putting traditional vulnerabilities on "steroids" for attackers.

πŸ“š The report includes data-supported trends, a guest column by the CISO of FS-ISAC, and practical DNS and DDoS mitigation strategies.

🏒 Akamai's SOTI Security reports are now in their 12th year, drawing insights from attacks viewed across its global cybersecurity protective infrastructure.

Bullish Signals
  • Akamai's SOTI Security reports are now in their 12th year, demonstrating long-term industry leadership and consistent delivery of critical cybersecurity insights.
  • The report is drawn from attacks viewed across Akamai's cybersecurity protective infrastructure, which handles a significant portion of global web traffic, highlighting the company's massive scale and reach.
  • Akamai provides defense in depth to safeguard enterprise data and applications everywhere through its market-leading security solutions and superior threat intelligence.
  • Global enterprises trust Akamai for industry-leading reliability, scale, and expertise to grow their business with confidence, leveraging its full-stack cloud computing solutions.
  • The report includes practical DNS and DDoS attack mitigation strategies, offering actionable value to organizations seeking to protect against escalating cyber threats.
Risk Factors
  • Financial services are now the primary target for web and API DDoS attacks, with median attack duration up 738% since 2024 due to AI-powered infrastructure.
  • 96% of financial service leaders surveyed reported at least one API security incident in the past 12 months, the highest rate among all industries.
  • In 2025, 83% of incursions against API endpoints specifically targeted banking systems, indicating a severe concentration of risk.
  • Nearly 80% of financial institutions have faced ransomware attacks in the past two years, yet less than half have adopted advanced security technologies to defend against them.
  • Advanced bot activity surged by 147% in late 2025, with one case study showing 96% of all site traffic identified as malicious scraping bots.
  • Cybercriminals are escalating DDoS attacks from nuisance levels to sustained sieges that encompass both hacktivism and cybercrime, directly threatening online banking and payment systems.
Full Analysis
Financial services are facing an escalating threat landscape driven by AI-empowered botnets and complex distributed denial-of-service (DDoS) attacks, according to Akamai's latest State of the Internet Security report. Cybercriminals have shifted focus to this sector more than any other for web and API attacks, with pro-Iran hacktivists weaponizing these tactics to disrupt online banking and payment systems. The median duration of global Layers 3 and 4 DDoS attacks targeting financial services has surged by 738% since 2024, indicating a move from nuisance attacks to sustained sieges that encompass both hacktivism and cybercrime. API security remains a critical vulnerability, with 96% of financial service leaders surveyed reporting at least one API security incident in the past 12 months, the highest rate among all industries. In 2025 alone, 60% of total web attacks and 83% of incursions against API endpoints specifically targeted banking sectors. Advanced bot activity also saw a significant increase, rising by 147% in late 2025, with one case study revealing that 96% of all site traffic was identified as malicious scraping bots. Regional variations in attack methods are evident, with the EMEA region being the primary target for Layers 3 and 4 DDoS attacks at 62%, while APAC faces the most Layer 7 DDoS threats at 52%. North America sees web attacks as the most prevalent at 44%. Despite nearly 80% of financial institutions facing ransomware attacks in the past two years, less than half have adopted advanced security technologies. Akamai's Advisory CISO Steve Winterfeld noted that AI does not reduce traditional security risks but rather amplifies them, urging organizations to leverage detailed security strategies and best practices outlined in the report to mitigate these growing threats.