Report
2024 API Security Impact Study: Retail and Ecommerce Industry
This report analyzes API attacks affecting retail and ecommerce platforms, including payment systems, customer accounts, loyalty programs, and digital storefronts. Sixty-eight percent of respondents experienced an API incident, with average financial impacts of $526,531. Stress on security teams, remediation costs, damaged executive confidence, regulatory fines, and increased scrutiny were the leading effects. Although 67% had full API inventories, only 29% knew which APIs returned sensitive information. Common causes included GenAI-related APIs, unintended exposure, misconfigurations, failed web application firewalls and gateways, coding errors, and unmanaged endpoints. The report urges retailers to improve API discovery, data visibility, authorization, testing, and behavioral protection
