Kong's New Study Reveals Alarmingly High Risks of AI-Driven Security Threats
Rising Threats in API Security: Insights from Kong's New Study
In a recent report released by Kong Inc., a leader in cloud API technology, alarming statistics surfaced revealing the increasing risks of AI-driven security threats affecting API infrastructures. The report titled API Security Perspectives 2025: AI-Enhanced Threats and API Security analyzed responses from IT professionals and business leaders primarily in the U.S. and U.K. It highlighted a significant breach in confidence within organizations regarding their API security measures.
Key Findings of the Report
The findings are sobering; 25% of the respondents indicated they had already fallen victim to AI-enhanced security incidents involving APIs or large language models (LLMs). More concerning is that 75% acknowledged their worries about potential AI-driven attacks in the future, implying a rising sense of vulnerability as AI technology continues to evolve.
Despite a general sense of optimism regarding organizational security capabilities—85% of participants reported confidence in their security measures—55% admitted to having experienced an API security incident within the last year. This disconnect underscores a critical gap in the actual security frameworks many organizations have in place.
Moreover, the report indicates that roughly one in five organizations faced API security incidents costing them above $500,000 in the past year, reflecting ongoing vulnerabilities in API security management. As the landscape changes with AI advancements, these incidents likely expose even more financial risks to businesses unaware of the complexities involved.
Respondents’ Strategies and Concerns
Interestingly, while 92% of respondents are taking some actions to counter AI-enhanced attacks, a significant portion seems underprepared. For instance, only 35% embrace a zero-trust architecture to mitigate API security risks effectively. Additionally, a mere 3% consider shadow APIs a serious threat, indicating a potential oversight that could have critical implications.
Kong Inc.'s Chief Technology Officer, Marco Palladino, emphasizes that it is imperative for organizations to understand their security vulnerabilities fully.