Select your language

Five Reasons Why Banking APIs Attract Cybercrime

Cinco motivos por lo que las APIs bancarias atraen a la ciberdelincuencia

International. Application Programming Interfaces are the bridge that connects banks with a digital ecosystem, allowing the integration of services and the creation of user experiences that make banking more efficient and customizable.

Without APIs, each company would have to build its own communication system with each bank, which would be expensive, time-consuming, and complex. Thanks to banking APIs, this process is simplified, however, they also become one of the most attractive vectors for cyber attackers.

The number of Open Banking API calls is projected to grow from 102 billion in 2023 to 580 billion in 2027, highlighting the critical importance of APIs in the banking infrastructure of the future. On the other hand, the value of open banking transactions is also expected to rise considerably and reach $330 billion by 2027.

Oswaldo Palacios, Latam Senior Account Executive at Akamai, explained that a banking API acts as a bridge between different software and applications. When a user makes, for example, a bank transfer in an application, the API is responsible for transmitting the request to the bank and then transmitting the response back to the application. "A banking API is capable of offering a series of benefits in terms of adaptability and speed in a business context determined by immediacy," said the executive.

APIs are pillars of digital transformation, allowing banks to evolve and stay competitive in the face of the emergence of Fintech and Techfins. As with any aspect of computing, API security is a critical concern for businesses and organizations that rely on APIs to provide access to their services and data. "APIs can be vulnerable to a wide range of security risks, which can lead to data breaches, unauthorized access, and other forms of abuse," he said.

Akamai's study Digital Fortresses Under Siege: Threats to Modern Application Architectures, highlights that the main vertical sectors affected by attacks on web applications and APIs from January 2023 to June 2024 were: Commerce, High Tech, and Financial Services. The latter sector recorded 55 billion attacks, which were particularly problematic for both organizations and customers because they can compromise user account information. This opens up opportunities for credential theft and other forms of abuse across an organization's application landscape.

APIs that lack an effective security posture could be more exposed to attackers who have a keen eye for weaknesses and are quick to exploit them. In this regard, Oswaldo Palacios mentioned the five reasons why banking APIs are an attraction for cybercrime, and also alerted the financial sector to take appropriate security measures:

1) Cybercriminals love APIs because they usually contain the keys to a large amount of valuable information. If not properly secured, APIs can expose sensitive data.

2) Hackers look for APIs created and implemented without sufficient security measures, which offer an easy entry point. While legacy APIs, if not updated regularly, also become the target of attackers, as they often offer several entry points that have been ignored or overlooked.

3) An attacker can inject malicious code or commands into an API request to exploit a vulnerability and gain unauthorized access to sensitive data. Behavioral analysis can help detect these types of attacks by identifying anomalous patterns that could indicate that someone is trying to exploit an API weakness.

4) Unauthorized users can exploit vulnerabilities in an API to disrupt services or hijack the system for use. Common threats include injection attacks, intermediary machine attacks (MITMs), and DDoS attacks aimed at overwhelming an API with traffic.

5) Security teams face unique challenges given the volume, speed, and complexity of the API environment in many organizations. A significant number of companies lack visibility into their API footprint, leading to an incomplete picture of the overall security landscape. Knowing both the full inventory of an attack surface and having security controls in place to protect that surface is crucial to keeping intruders out of a network.

That is why Oswaldo Palacios advised implementing strong authentication and authorization protocols, using encryption to protect data during transit, limiting the exposure of API terminals to reduce potential attack vectors, carrying out security audits and periodic vulnerability assessments, and following a Zero Trust model: Do not trust any requests by default.

"Securing APIs can be a difficult task that goes beyond access restrictions. The goal is to create a security environment around APIs that can resist intrusion or misuse attempts. Organizations must invest time, resources and maintain a continuous strategy to protect their APIs against the numerous security risks they face," concluded Oswaldo Palacios.


No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter