Digital banking growth raises cyber risks across APAC: Akamai
π APAC accounted for 52% of global financial DDoS attacks in 2025, marking the fourth consecutive year it was the most targeted region.
π¦ Banking institutions represented 44% of Layer 7 DDoS attacks in the Asia-Pacific region, while fintech companies made up an additional 38%.
β οΈ Legacy infrastructure remains a significant challenge as banks secure new digital services on top of ageing systems that are difficult to patch.
π€ Advanced bot activity surged by 147% in late 2025, with AI-powered botnets mimicking browser behaviour to bypass conventional detection tools.
ποΈ There is a major visibility gap where 77% of IT leaders believe they have full API visibility, yet only 27% are aware of APIs exposing sensitive data.
π On a global scale, 96% of financial services organisations experienced at least one API security incident in the last year.
π‘οΈ Microsegmentation helped organisations respond to incidents 33% faster by isolating applications and limiting attacker movement after a breach.
π Cybersecurity is shifting from a compliance function to an operational resilience issue as digital banking ecosystems become more interconnected.
π€ AI-enabled workflows create new dependencies for attackers to probe, increasing the attack surface at a pace many organisations struggle to safeguard.
π Layer 7 DDoS attacks focus on application behaviour rather than bandwidth limits, complicating detection and raising operational risks for online banking systems.
π Security teams are expected to invest more heavily in API discovery tools and behavioural analytics capable of responding at machine speed.
π¦ Short outages caused by these attacks can affect customer trust, transaction continuity, and regulatory compliance for banks handling high volumes.
- APAC faced 52% of global financial DDoS attacks in 2025, making it the most frequently targeted region for the fourth consecutive year.
- Banking institutions alone accounted for 44% of Layer 7 DDoS attacks in the APAC region, while fintech companies represented an additional 38% of such attacks.
- A significant visibility gap exists where 77% of IT leaders believe they have full API visibility, yet only 27% are actually aware of which APIs expose sensitive information.
- 96% of financial services organizations globally experienced at least one API security incident in the last year, marking the highest incidence rate among all industries studied.
- Advanced bot activity surged by 147% during late 2025, with AI-powered botnets capable of mimicking browser behavior to bypass conventional detection tools.
- Legacy infrastructure complicates security as banks secure new digital services on top of ageing systems that may be difficult to patch or integrate securely.
- Attackers are increasingly focusing on operational disruption rather than simple infrastructure overload, posing risks to transaction continuity and regulatory compliance.
- Short outages caused by these attacks can directly affect customer trust, transaction continuity, and regulatory exposure for banks handling high-volume real-time payments.