Wallarm, the recognized leader in API security, has built a globally distributed API honeypot spanning 14 locations. It baits attackers by simulating real API environments—REST, XML-RPC, GraphQL, and more—and records every exploit in shocking detail. The data reveals that modern attackers prioritize APIs over traditional web apps. They discover newly deployed endpoints at breakneck speed, averaging just 29 seconds, with the slowest clocking at 34. From port opening to a valid API call often takes under a minute. Once they find an unprotected API, active exploitation happens almost immediately.
Wallarm observed attackers using about 50 IP addresses, each sending 50 requests per second, totaling 2,500 RPS. With minimal cloud costs—$50–$150 per IP monthly—and only around 20 Mbps of bandwidth, they pull off stealthy yet large-scale data theft. By batching API calls through protocols like XML-RPC or GraphQL, attackers can extract 10 million user records in as little as 6 seconds. A single-request approach takes around 66 seconds to achieve the same haul, while older-style web scraping might drag on for 1,666 seconds.
This new breed of automated, cost-effective assault underscores why port 80 and 443 alone aren’t enough. Attackers scan a wide range of ports for anything left exposed or misconfigured. They also zero in on popular API products and known CVEs, leveraging the smallest security gaps to breach entire systems and vanish with critical data.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
APIs now surpass regular web applications as top targets because they offer rapid, high-volume access to user data. With attackers discovering endpoints in under half a minute, defenses must respond just as fast. Traditional monitoring often misses these bursts of malicious traffic, especially when bandwidth usage hovers around 20 Mbps—far below typical DDoS volumes.
Wallarm’s honeypot research shows that real-time API visibility and security governance are vital. Teams need to track every endpoint, patch or segment risky services, and block suspicious traffic instantly. Even widely used or brand-name API products can’t bank on default settings. Attackers hunt them first, looking for quick wins.
This worldwide dataset clarifies one truth: APIs are fueling business growth, and attackers chase that growth. A single exposed API can compromise millions of records in mere seconds. Organizations must react with layered protections that scale as quickly as the threats do. Wallarm’s research proves it’s no longer a question of whether attackers will come for your APIs, but when—and in today’s threat landscape, “when” is measured in seconds.
Download full report: https://hubspot.wallarm.com/hubfs/API%20Honeypot%20report.pdf
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
8 Best AI Exposure Management Tools for CISOs in 2026
Scanners pile up findings faster than any team can patch, and attackers are weaponizing new flaws within hours. These eight AI exposure...
Security+ vs CySA+ (2026): Which CompTIA Cert to Take
Security+ SY0-701 vs CySA+ CS0-004: difficulty, $439 exam cost, renewal stacking, DoD 8140 roles, and which CompTIA cert to take first by...
DoD 8140 Approved Certifications (2026): Roles and Levels
How DoD 8140 replaced 8570 IAT/IAM with DCWF work roles and proficiency levels, plus which certifications qualify where in Qualification Matrix V2.1.
Friday’s brief: FortiMail due Saturday, then BoKS, vm2, Satellite
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.