Select your language

Virtual theft of financial services has reached an industrial scale: Akamai

El robo virtual a servicios financieros ha alcanzado una escala industrial: Akamai

International. Whether looking for profit or disruption, cybercriminals attack to steal lucrative personal data, from account credentials to payment card information.

The convergence of botnets, API vulnerabilities, and the rapid adoption of artificial intelligence (AI) is creating an extremely dynamic and complex threat landscape for financial services organizations around the world. This is the conclusion of the most recent research on threats to financial services, carried out by Akamai.

According to the State of the Internet (SOTI) Security Report AI API and Botnet Visibility Breaches: Attack Trends in the Financial Sector, the wave of activity has increased in both volume and complexity over the past two years.

In this document, John Denning, director of security at the Financial Services Information Sharing and Analysis Center (FS-ISAC) argues that, while AI is helping organizations transform their operations, it is also expanding the attack surface and aggravating risk. In this regard, Denning expresses the need for collective defense to address the current landscape of hyperconnected threats, emphasizing the importance of carrying out real-time threat intelligence work throughout the financial ecosystem and of protection experts sharing their knowledge and strategies with each other to make things more difficult for attackers.

- Publicidad -

After analysing trends over time and taking an in-depth look at the 2025 data, the SOTI report presents the following conclusions, among others.

DDoS attacks, the biggest threat
Akamai's research concludes that the financial services sector is one of the main targets of DDoS events, far surpassing other sectors; Banking remains the biggest target of layer-3 and layer-4 attacks, as well as layer-7 DDoS attacks, by a wide margin.

  • DDoS attacks targeting layers 3 and 4 increased by 5.2% year-over-year.
  • These incidents also grew in size, complexity, and duration of events.
  • The maximum size of DDoS attack events increased by 236%, and the average duration increased by 738% between 2024 and 2025.

This dramatic increase in threat scale and complexity is due to a combination of flaws in legacy systems, the rapid expansion of digital banking, and improved AI attack frameworks, which allow adversaries to adapt to real-time mitigation strategies.

Kimberly Gomez"The SOTI Security Report discusses this topic in detail, including information on regional trends, Internet of Things (IoT) botnets, and the role of hacktivist attacks by groups such as Keymous+, DieNet, Handala, and Islamic Cyber Resistance (CIR)," said Kimberly Gomez, Director of Security Research at Akamai.

DNS is a hidden attack surface
DNS has emerged as a major, often overlooked, attack surface for banking, wealth management, insurance, and fintech organizations. DNS infrastructure often outlives the systems, products, and business units it originally supported, opening the door to subdomain theft, spoofing, and unauthorized certificate issuance.

Common DNS issues that create vulnerabilities are misconfigured initiations of authority (SOA), missing certificate authority authorization (CAA) records, missing DNSKEY records, unnecessary DNS wildcard records, and disabled record locks. In a distributed cloud environment, DNS is no longer simply a routine maintenance issue, but the critical control point for digital trust and secure application delivery.

Web attacks continue to increase
Research also shows that cybercriminals relentlessly target financial services websites, with an 11% increase between 2024 and 2025 worldwide. With 110 billion attacks over the two-year period, financial services is the second most affected sector by web attacks, after commerce. The majority of web attacks (60%) targeted banking sites.

- Publicidad -

The growth of APIs is compounding the risk
API endpoints are an important vector for web attacks, underscoring the need for greater visibility and control. Faced with the pressing demand for new functionality, organizations are turning to shadow APIs and AI-assisted coding ("vibe coding"), a factor that exacerbates this problem.

The emergence of rent-for-hire botnets and other easy-to-use tools, coupled with insufficient DDoS protection, opens the door for less technically savvy actors to launch web attacks. This highlights the need for security teams to focus their attention on strong cyber hygiene and security fundamentals, including visibility into their APIs.

AI botnets are a critical threat
Advanced bot activity increased by 147% by the end of 2025, with an increase in AI evasion techniques. Today, hyperscale botnets can control millions of IoT devices to cause massive DDoS attacks, while also neutralizing standard IP reputation blocks.

"Akamai highlights the importance of moving from basic signature blocking to behavioral heuristics and user risk telemetry in order to identify fraudulent identities within transactional flows," says the company's Director of Security Research.

Practical Defense Strategies for Financial Services
AI does not eliminate traditional security risks, but rather causes them to multiply. That's why protection experts must move away from static perimeters and adopt adaptive, AI-aware security architectures to counter the volume and sophistication of today's attacks.

Among the practical defense strategies for financial services, Akamai highlights the MITRE ATT&CK matrix for enterprises and the ATLAS knowledge bases, which demystify the techniques cybercriminals use to execute their attacks.

- Publicidad -

In addition, the report AI API and Botnet Visibility Gaps: Attack Trends in the Financial Industry includes practical advice for financial services organizations to address today's increasingly complex compliance landscape. In addition, it recommends tools and practices to help security operations teams refine their red team assessments and activities, improve their security strategy, and secure AI deployments.


No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter