Akamai Technologies, Inc.

NASDAQ Global Select
Neutral 0

Digital banking growth raises cyber risks across APAC: Akamai

πŸ“ˆ APAC accounted for 52% of global financial DDoS attacks in 2025, marking the fourth consecutive year it was the most targeted region.

🏦 Banking institutions represented 44% of Layer 7 DDoS attacks in the Asia-Pacific region, while fintech companies made up an additional 38%.

⚠️ Legacy infrastructure remains a significant challenge as banks secure new digital services on top of ageing systems that are difficult to patch.

πŸ€– Advanced bot activity surged by 147% in late 2025, with AI-powered botnets mimicking browser behaviour to bypass conventional detection tools.

πŸ‘οΈ There is a major visibility gap where 77% of IT leaders believe they have full API visibility, yet only 27% are aware of APIs exposing sensitive data.

πŸ“‰ On a global scale, 96% of financial services organisations experienced at least one API security incident in the last year.

πŸ›‘οΈ Microsegmentation helped organisations respond to incidents 33% faster by isolating applications and limiting attacker movement after a breach.

πŸ”„ Cybersecurity is shifting from a compliance function to an operational resilience issue as digital banking ecosystems become more interconnected.

πŸ€– AI-enabled workflows create new dependencies for attackers to probe, increasing the attack surface at a pace many organisations struggle to safeguard.

πŸ“‰ Layer 7 DDoS attacks focus on application behaviour rather than bandwidth limits, complicating detection and raising operational risks for online banking systems.

πŸ” Security teams are expected to invest more heavily in API discovery tools and behavioural analytics capable of responding at machine speed.

🏦 Short outages caused by these attacks can affect customer trust, transaction continuity, and regulatory compliance for banks handling high volumes.

Risk Factors
  • APAC faced 52% of global financial DDoS attacks in 2025, making it the most frequently targeted region for the fourth consecutive year.
  • Banking institutions alone accounted for 44% of Layer 7 DDoS attacks in the APAC region, while fintech companies represented an additional 38% of such attacks.
  • A significant visibility gap exists where 77% of IT leaders believe they have full API visibility, yet only 27% are actually aware of which APIs expose sensitive information.
  • 96% of financial services organizations globally experienced at least one API security incident in the last year, marking the highest incidence rate among all industries studied.
  • Advanced bot activity surged by 147% during late 2025, with AI-powered botnets capable of mimicking browser behavior to bypass conventional detection tools.
  • Legacy infrastructure complicates security as banks secure new digital services on top of ageing systems that may be difficult to patch or integrate securely.
  • Attackers are increasingly focusing on operational disruption rather than simple infrastructure overload, posing risks to transaction continuity and regulatory compliance.
  • Short outages caused by these attacks can directly affect customer trust, transaction continuity, and regulatory exposure for banks handling high-volume real-time payments.
Full Analysis
Akamai Technologies' State of the Internet Security report indicates that the Asia-Pacific (APAC) region accounted for 52% of global Layer 7 distributed denial-of-service (DDoS) attacks against financial services in 2025, marking it as the most targeted area for the fourth consecutive year. Banking institutions specifically represented 44% of these Layer 7 attacks in APAC, while fintech companies accounted for an additional 38%. These sophisticated attacks mimic real user traffic to target application behavior rather than just bandwidth, complicating detection and posing significant operational risks to online banking systems and payment processors. A critical finding highlights a severe visibility gap regarding Application Programming Interfaces (APIs). While 77% of IT and security leaders in the APAC financial sector believe they have full visibility into their API environments, only 27% are actually aware of which APIs expose sensitive information. Globally, 96% of financial services organizations experienced at least one API security incident in the last year, with advanced bot activity surging by 147% in late 2025 due to AI-powered botnets that can bypass conventional detection tools. The report emphasizes that cybersecurity is shifting from a compliance function to an operational resilience issue, particularly as banks layer modern digital services onto legacy infrastructure that is difficult to patch. Akamai recommends that organizations prioritize investments in containment and resilience strategies, such as microsegmentation, which allows for 33% faster incident response times compared to those without it. As digital banking ecosystems become more interconnected through APIs and third-party integrations, visibility into application behavior and traffic patterns is becoming as critical as traditional network security controls to maintain uninterrupted service availability and customer trust.