When API security firm Salt Security wanted to see just how vulnerable financial institutions might be to common API attacks, it investigated a large U.S.-based financial institution’s online platform that provides API services to “thousands of partner banks and financial advisors.”

The vulnerability report, released Wednesday, does not disclose the name of this institution for security reasons, although Salt did say it was not a bank. However, researchers found that they could:
- Read the financial records of any customer;
- Delete customer accounts in the system;
- Take over any account; and
- Create a denial-of-service condition to render entire applications unavailable.
The rise in API attacks is particularly concerning development, given how widely deployed APIs are by fintechs and banks in mobile apps and other platforms. By 2022, API abuses will shift from infrequent attacks to the most frequent attack vector, research firm Gartner has predicted, which will result in data breaches for enterprise web applications.
During a webinar today on API security, Gartner analyst Mark O’Neill said that prediction is already playing out.
“If you’re following the news about API attacks, you’ll have seen a lot of these, including very well-known companies that have had APIs and security issues with them,” O’Neill said. “A security breach of an API is a data breach, because the person who has compromised the API has got access to data. That’s one of the many reasons why API security is a very important topic.”
Just five years ago, there was no awareness of the risk APIs posed, Roey Eliyahu, CEO and cofounder of the Palo Alto, Calif.-based Salt Security, told Bank Automation News. Salt Security was founded in 2016.
“In that specific report, we were engaged with the financial institution, and we found very critical vulnerabilities in their APIs,” Eliyahu said. “Essentially, an attacker, without an army of servers, with literally a single laptop, can actually take the entire service down.”
Researchers were able to exploit several high-severity API security vulnerabilities in the financial institution’s platform, and Salt Labs worked with the involved parties to resolve the issues.
Eliyahu’s firm is finding critical vulnerabilities in 90 percent of its customer engagements. To further research API attacks, Salt Security announced on Wednesday the creation of Salt Labs, a public forum for publishing research on API vulnerabilities.
Meanwhile, recent high-profile attacks have exploited API vulnerabilities, examples being the April Experian data breach, a 2019 Facebook data breach that led to the data exposure of 533 million users, and an attack on the popular fitness company Peloton.
Sander Vinger, a threat researcher with the technology security firm f5, also emphasized the rising threat of API attacks, especially against fintechs.
“We see that exploited very, very heavily in fintech,” Vinger told BAN. “I don’t want to make it sound like APIs are bad because they have enormous advantages. But they also have really big ramifications for security that I think are not very widely understood.”






