Akamai's 2026 report reveals a significant rise in API-related security threats amid increased AI adoption, highlighting evolving attack methods.
Quiver AI Summary
Akamai has released its 2026 Apps, APIs, and DDoS State of the Internet report, revealing a significant shift in cybersecurity threats, particularly as organizations adopt AI technologies. The report highlights that APIs, previously underappreciated as vulnerabilities, have become primary targets for attackers, who are using industrialized methods to execute coordinated campaigns blending API exploitation, web application attacks, and Layer 7 DDoS tactics. The data shows a 104% increase in Layer 7 DDoS attacks over two years, with 87% of organizations reporting API-related security incidents in 2025. As attackers focus on undermining performance and escalating operational costs, it's emphasized that application and API security must be treated as interconnected issues to avoid exploitation gaps. The report also discusses the rise of hacktivist DDoS actions and the emergence of “super botnets.” Akamai’s SOTI reports continue to provide crucial insights into evolving cybersecurity trends, and the company invites attendees to learn more at the RSA Conference.
Potential Positives
- Akamai's 2026 SOTI report highlights significant trends and insights in the threat landscape, showcasing its expertise and thought leadership in cybersecurity.
- The report reveals a 104% increase in Layer 7 DDoS attacks, indicating a growing need for Akamai's protective services, which may drive further business opportunities.
- With 87% of surveyed organizations reporting API-related security incidents, the demand for Akamai's security solutions is likely to rise as organizations seek to protect their critical infrastructure.
- Akamai's ongoing commitment to providing critical insights through its SOTI reports reinforces its position as a trusted partner for global enterprises in managing cybersecurity challenges.
Potential Negatives
- The report highlights a significant increase in API-related security incidents, with 87% of surveyed organizations experiencing an incident in 2025, indicating a severe vulnerability in the company's security approach.
- A 104% surge in Layer 7 DDoS attacks over the past two years suggests that Akamai must address critical weaknesses in its security infrastructure to protect clients effectively.
- The mention of "vibe coding" leading to new vulnerabilities signifies potential shortcomings in Akamai’s monitoring and mitigation processes for emerging threats.
FAQ
What are the key findings of the 2026 Akamai SOTI report?
The report highlights a significant rise in API-related attacks and Layer 7 DDoS incidents, alongside trends in application security.
How has the DDoS threat landscape changed recently?
Layer 7 DDoS attacks surged by 104% recently, fueled by accessible botnets and AI-driven attack scripts targeting APIs.
Why are APIs becoming the main attack surface?
As organizations accelerate AI adoption, APIs have emerged as a critical vulnerability point in securing AI transformations.
What impact does automation have on cyber attacks?
Automation and AI have made cyberattack campaigns cheaper, repeatable, and faster, allowing for more sophisticated attacks.
How can organizations protect against these evolving threats?
Integrating application and API security practices can help close visibility gaps and enhance overall security against coordinated attacks.
Disclaimer: This is an AI-generated summary of a press release distributed by GlobeNewswire. The model used to summarize this release may make mistakes. See the full release here.
$AKAM Insider Trading Activity
$AKAM insiders have traded $AKAM stock on the open market 25 times in the past 6 months. Of those trades, 0 have been purchases and 25 have been sales.
Here’s a breakdown of recent trading of $AKAM stock by insiders over the last 6 months:
- ADAM KARON (COO & GM Edge Technology Group) has made 0 purchases and 3 sales selling 25,048 shares for an estimated $2,574,275.
- MANI SUNDARAM (EVP and GM Security) has made 0 purchases and 6 sales selling 23,988 shares for an estimated $2,301,007.
- PAUL C JOSEPH (EVP - Global Sales) has made 0 purchases and 5 sales selling 15,000 shares for an estimated $1,420,581.
- EDWARD J MCGOWAN (Chief Financial Officer) has made 0 purchases and 2 sales selling 13,745 shares for an estimated $1,390,924.
- ROBERT BLUMOFE (Chief Technology Officer) has made 0 purchases and 4 sales selling 13,500 shares for an estimated $1,281,550.
- AARON AHOLA (EVP & General Counsel) has made 0 purchases and 2 sales selling 12,000 shares for an estimated $1,218,166.
- JON MILLER sold 11,000 shares for an estimated $1,129,370
- LAURA HOWELL (SVP, Chief Accounting Officer) sold 11,273 shares for an estimated $1,128,822
- MADHU RANGANATHAN sold 3,131 shares for an estimated $319,362
To track insider transactions, check out Quiver Quantitative's insider trading dashboard.
$AKAM Revenue
$AKAM had revenues of $1.1B in Q4 2025. This is an increase of 7.35% from the same period in the prior year.
You can track AKAM financials on Quiver Quantitative's AKAM stock page.
$AKAM Congressional Stock Trading
Members of Congress have traded $AKAM stock 3 times in the past 6 months. Of those trades, 1 have been purchases and 2 have been sales.
Here’s a breakdown of recent trading of $AKAM stock by members of Congress over the last 6 months:
- REPRESENTATIVE LISA C. MCCLAIN has traded it 3 times. They made 1 purchase worth up to $15,000 on 10/30 and 2 sales worth up to $30,000 on 10/31, 10/30.
To track congressional stock trading, check out Quiver Quantitative's congressional trading dashboard.
$AKAM Hedge Fund Activity
We have seen 333 institutional investors add shares of $AKAM stock to their portfolio, and 411 decrease their positions in their most recent quarter.
Here are some of the largest recent moves:
- UBS AM, A DISTINCT BUSINESS UNIT OF UBS ASSET MANAGEMENT AMERICAS LLC removed 5,069,562 shares (-89.9%) from their portfolio in Q4 2025, for an estimated $442,319,284
- POINT72 ASSET MANAGEMENT, L.P. added 3,797,143 shares (+inf%) to their portfolio in Q4 2025, for an estimated $331,300,726
- BLACKROCK, INC. removed 3,583,240 shares (-25.4%) from their portfolio in Q4 2025, for an estimated $312,637,690
- TWO SIGMA ADVISERS, LP added 1,539,700 shares (+511.0%) to their portfolio in Q4 2025, for an estimated $134,338,825
- TWO SIGMA INVESTMENTS, LP added 1,392,485 shares (+212.2%) to their portfolio in Q4 2025, for an estimated $121,494,316
- NORTHWESTERN MUTUAL WEALTH MANAGEMENT CO added 1,381,838 shares (+76896.9%) to their portfolio in Q4 2025, for an estimated $120,565,365
- RUBRIC CAPITAL MANAGEMENT LP added 1,200,000 shares (+inf%) to their portfolio in Q4 2025, for an estimated $104,700,000
To track hedge funds' stock portfolios, check out Quiver Quantitative's institutional holdings dashboard.
$AKAM Analyst Ratings
Wall Street analysts have issued reports on $AKAM in the last several months. We have seen 4 firms issue buy ratings on the stock, and 0 firms issue sell ratings.
Here are some recent analyst ratings:
- Scotiabank issued a "Sector Outperform" rating on 01/09/2026
- Keybanc issued a "Overweight" rating on 12/15/2025
- Oppenheimer issued a "Outperform" rating on 11/17/2025
- DA Davidson issued a "Buy" rating on 10/16/2025
To track analyst ratings and price targets for $AKAM, check out Quiver Quantitative's $AKAM forecast page.
$AKAM Price Targets
Multiple analysts have issued price targets for $AKAM recently. We have seen 13 analysts offer price targets for $AKAM in the last 6 months, with a median target of $110.0.
Here are some recent targets:
- James Fish from Piper Sandler set a target price of $97.0 on 02/23/2026
- Roger Boyd from UBS set a target price of $110.0 on 02/20/2026
- William Power from Baird set a target price of $110.0 on 02/20/2026
- Amit Daryanani from Evercore ISI Group set a target price of $115.0 on 02/20/2026
- Aaron Samuels from Susquehanna set a target price of $120.0 on 02/20/2026
- Jackson Ader from Keybanc set a target price of $120.0 on 02/20/2026
- Patrick Colville from Scotiabank set a target price of $120.0 on 02/20/2026
Full Release
CAMBRIDGE, Mass., March 17, 2026 (GLOBE NEWSWIRE) -- Akamai (NASDAQ: AKAM) today released its 2026 Apps, APIs, and DDoS State of the Internet (SOTI) report, highlighting a decisive shift in the threat landscape. Attackers are now industrializing their methods and targeting the infrastructure that fuels business growth and AI transformation.
As organizations accelerate AI adoption, APIs — long overlooked as a point of vulnerability — have become the primary attack surface. Akamai researchers have observed attacks evolve into coordinated campaigns that consistently blend API abuse, web application attacks, and Layer 7 DDoS activity into scalable, cost-efficient operations to disrupt availability and drive financial impact. Wherever investment concentrates, risk follows. APIs have become the foundation of AI transformation, and securing AI means securing APIs.
The report data underscores the scale of this industrialization:
- Layer 7 DDoS attacks surged 104% over the past two years.
- 87% of surveyed organizations reported experiencing an API-related security incident in 2025.
- Web application attacks rose sharply, climbing 73% between 2023 and 2025.
- The average number of daily API attacks rose 113% year over year.
“Attackers increasingly focus on degrading performance, driving up infrastructure costs, and exploiting AI-driven automation at scale, rather than seeking headline-grabbing campaigns,” said Patrick Sullivan, CTO of Security Strategy at Akamai. “Automation and AI are making these sophisticated campaigns cheap, repeatable, and fast. And as enterprises invest heavily in AI transformation, attackers are targeting the APIs that power that transformation.”
The report also finds that application and API security are now inseparable, though many organizations still manage them as distinct challenges. Treating them as separate problems creates visibility gaps that attackers need to successfully exploit them as a single attack vector.
Additional key findings include:
- “Vibe coding” is introducing new vulnerabilities and misconfigurations that often reach production without adequate testing.
- Hacktivist-driven DDoS activity continues to rise as politically motivated actors adapt to shifting global tensions and the increasing availability of rentable botnets.
- The 104% spike in Layer 7 DDoS attacks is fueled by easy access to botnets through DDoS-for-hire services and AI-enabled attack scripts that simplify targeting of APIs and web applications.
- “Super botnets” such as Aisuru and Kimwolf, evolved from Mirai’s original architecture, now power DDoS as a service (DDoSaaS) ecosystems used by both cybercriminal and hacktivist groups.
The 2026 Apps, APIs, and DDoS SOTI report also includes a deep dive on regional attack trends, expert insight into the economics of modern internet attacks, and a guest column that explores defenses against emerging agentic AI threats, along with practical mitigation strategies.
Now in their 12th year, Akamai’s SOTI reports continue to offer critical insights on cybersecurity trends and web performance, drawn from attacks viewed across Akamai’s cybersecurity protective infrastructure, which handles a significant portion of global web traffic.
To learn more, please stop by Akamai’s booth N-6245 at this year’s RSA Conference.
About Akamai
Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense in depth to safeguard enterprise data and applications everywhere. Akamai’s full-stack cloud computing solutions deliver performance and affordability on the world’s most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog , or follow Akamai Technologies on X and LinkedIn .
Contacts
Akamai Media Relations
[email protected]