Cybersecurity statistics about apis
Showing 1-20 of 40 results
82% of the more than 10,000 Model Context Protocol (MCP) servers interact with sensitive APIs, creating additional vulnerabilities in 2025.
Within the next 12 to 18 months, nearly a third (32%) of CISOs, AppSec managers and developers expect Application Programming Interface (API) breaches via shadow APIs or business logic attacks.
APIs in technology & SaaS providers' environments saw a 400% spike in critical vulnerabilities.
Nearly 7 in 10 retail & consumer goods organizations had APIs with misconfigured authorizations or data exposure issues. These retail & consumer goods APIs averaged 15 vulnerabilities per API.
In one analysis, energy had 18% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, hospitality had 15% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, transport had 12% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, media had 21% of vulnerable assets across cloud, APIs, and web applications.
Top 5 industries by API vulnerability: Education: 37.7%, Retail: 29.8%, Media: 18.8%, Government: 18.5%, Professional Services: 10.6%.
In one analysis, retail had 27% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, technology had 15% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, the media sector had 18.8% vulnerable APIs.
In one analysis, retail had 29.8% vulnerable APIs.
In one analysis, education had 37.7% vulnerable APIs.
In one analysis, telecommunications had 15% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, education had 31% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, the government sector had 18.5% vulnerable APIs.
In one analysis, finance had 5% of vulnerable assets across cloud, APIs, and web applications.
In one analysis, the services sector had 10.6% vulnerable APIs.
In one analysis, government had 26% of vulnerable assets across cloud, APIs, and web applications.