Latin America. Akamai highlighted that 68% of ecommerce and retail companies reported having suffered security incidents of their APIs in the last 12 months.
Ecommerce in Latin America is becoming increasingly popular, driven by a greater number of digital shoppers. However, this growth has also led to a large increase in security breaches made by cybercriminals who can steal personal information, such as credit card numbers, passwords and email addresses or also damage companies' computer systems, causing service interruptions or even data loss.
According to the firm Statista, Latin America is home to approximately 300 million digital shoppers, a figure that is expected to grow by more than 15% by 2027. Although ecommerce adoption in this part of the world is still lower than in other emerging regions, online retail sales in Latin America are expected to be around 200,000 million by 2026.
Patricio Villacura, Enterprise Security Specialist for Akamai, noted that online stores store a large amount of sensitive information, including credit card data, addresses, and personal customer details. A security breach can result in information theft, fraud, and the loss of customer trust, which can have a lasting impact on the reputation and success of the business.
There are currently a number of major cybersecurity issues that e-commerce businesses are facing today, such as malware, DoS and DDoS attacks, social engineering, financial fraud, electronic skimming, bots, and more and more API attacks. Such threats result in significant annual losses for Latin American e-commerce.
The Akamai expert pointed out that today the APIs that power the digital initiatives of retail and e-commerce companies are under attack. Using increasingly innovative methods, threat actors can access data from unprotected APIs to
stealing credit card data, diverting funds from loyalty programs, launching credential attacks, and so on.
A study conducted by Akamai, "2024 API Security Impact Study: Retail and Ecommerce Industry", highlights that 68% of ecommerce and retail companies reported having suffered API security incidents in the last 12 months. On the other hand, they cited a cost of $526,531 to deal with the API incidents they had experienced. It also highlights that API attacks against retail and e-commerce businesses are growing in scope, scale, and sophistication.
This includes GenAI-powered bot attacks that adapt quickly to bypass traditional API security tools and other perimeter defenses. According to Patricio Villacura, the ecommerce sector is experiencing these threats first-hand and feeling the impacts, both financial and human. When organizations understand the importance of API threats, they must take steps to better protect their APIs (and the data they exchange), allowing the company to protect its revenue and ease the burden on security teams, while preserving the trust earned by boards and customers. These steps include developing your team's knowledge of advanced API threats and the capabilities you need to defend against them.
"As APIs become more complex, protecting them from cyberthreats becomes very difficult. More and more organizations are adopting microservices-based architectures and relying on APIs for virtually every online interaction, creating potential new entry points for hackers; cybercriminals are constantly refining their methods, using automated bots, botnets, and vulnerability scanners to launch multi-vector attacks," the Akamai expert reported.
Patricio Villacura highlighted that a web application firewall (WAF) can mitigate many types of cyberattacks on web applications and APIs. It has been designed to protect applications by filtering, monitoring, and blocking any malicious incoming HTTP traffic, while also preventing unauthorized data from leaving the API. As a result, WAFs protect business-critical applications and web servers against threats such as zero-day attacks, DDoS attacks, SQL injection, and cross-site scripting (XSS).
It is important to mention that WAF solutions must constantly adjust as threats evolve and applications change. In addition, they can be deployed through software, on-premises devices, or cloud-based technologies. Policies for a WAF can be tailored to the unique needs of your organization and its web applications.
Finally, Patricio Villacura recommended that e-commerce businesses choose a WAF solution that allows them to identify even the most evasive attacks, while keeping false positives at an ultra-low level: "Choose a WAF that integrates seamlessly with your current infrastructure, such as firewalls, identity and access management (IAM) systems, and security analysis tools. Also, make sure that the WAF can adapt to your future growth in terms of traffic and application complexity," the expert concluded.

