Bad bots on the rise, targeting APIs

Bad bots are getting cleverer, and as a result, more advanced attacks, such as account takeover and attacks against APIs, are increasing.

In June 2022, hackers launched an attack against Australia’s largest Chinese-language platform, Media Today, making over 20 million attempts to reset user passwords. The attackers weren’t humans, but bots—complex, automated programs that swarm around the internet carrying out instructions.

Bots can be benign or malicious. Benign bots, such as search engine crawlers, are used to harvest data for search engines. Malicious bots, on the other hand, are used to target digital systems, web applications, and application programming interfaces (APIs) for data theft, fraud, denial of service, and more.

Bad bots are evolving to become more sophisticated and are getting better at mimicking human behavior and bypassing traditional security controls. According to Imperva, bad bots accounted for just under half (48%) of all internet traffic in the first six months of 2023, up from 43% in the same period last year.

APIs are a growing target for bot attacks because they are relatively under-protected and used extensively for automated processes and communications. Attackers target applications that use APIs to access email accounts, such as marketing mailshot applications that send and track bulk- or personalized- emails to potential or existing customers.

The sources for this piece include an article in SecurityBrief.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.