Skip to the main content.

4 min read

AI-Empowered Botnets and the 77/27 API Gap: What New Research Means for ANZ Financial Services

AI-Empowered Botnets and the 77/27 API Gap: What New Research Means for ANZ Financial Services
AI-Empowered Botnets and the 77/27 API Gap: What New Research Means for ANZ Financial Services
16:46
Financial Services Threat Intelligence
 

A blunt 77% of financial services security leaders in APAC say they have a full picture of their API estate. Only 27% know which of those APIs return sensitive data. That gap is where attackers live now. And as AI accelerates both attack scale and API proliferation, the gap is widening fast.

Akamai's latest State of the Internet Security report lands at a moment when Australian and New Zealand regulators have already started pulling on the same thread. The APRA letter on AI risk landed on 30 April 2026. The ASIC open letter on frontier AI followed on 8 May 2026. The RBNZ Financial Stability Report arrived in mid-May with the same warning. The message to boards across the Tasman is now unified: existing controls are about to be tested more often, at greater scale, and under greater pressure.

Financial services tops the global target list. Banking is the bullseye within it.

Financial services is now the most targeted industry globally for Layer 3 and 4 DDoS attacks. The median duration of those attacks has increased by 738% since 2024. Volumetric DDoS attacks against the sector grew in scale by 236% between 2024 and 2025. Advanced bot activity surged 147% in late 2025, and in one Akamai case study, 96% of a financial site's total traffic was identified as malicious scraping bots.

The takeaway for ANZ financial services is straightforward. The threat is global, the targeting is sector-specific, and the volume is rising.

The APAC angle: where ANZ sits in the Layer 7 firing line

APAC is now the most targeted region for Layer 7 DDoS attacks against financial services, for the fourth consecutive year. 52% of all global Layer 7 attacks against the sector in 2025 hit APAC institutions. That was 314 billion attacks across the region in one year, more than double the next closest region.

Australia and New Zealand sit firmly inside that envelope.

77%
of APAC financial services leaders say they have a full picture of their API estate
27%
know which of those APIs return sensitive data

The gap between knowing what you have and knowing what matters is the single most consequential finding in the Akamai report for ANZ financial services governance.

Source: Akamai 2026 API Security Impact Study.

Where do you actually stand?

Australian and New Zealand regulators are now asking for evidence, not assurances.

APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.

The 77/27 problem: full inventory, partial visibility

The single most useful data point in the Akamai report, from a governance perspective, is the gap between API inventory and sensitive data visibility.

That is the visibility gap. It is not a technology problem. It is a knowing-what-you-have problem.

Globally, 96% of financial services organisations reported at least one API security incident in the past 12 months. That is the highest rate of any industry. If you do not know which of your APIs touch sensitive data, you cannot meaningfully protect them, monitor them, or report on them. You also cannot answer the information security questions in APRA CPS 234, or the third-party and fourth-party visibility questions in APRA CPS 230, which came into force on 1 July 2025.

Vibe coding, shadow APIs, and AI as a new attack surface

First, AI is making attacks more effective. Akamai recorded an average of 2.5 billion AI-related bot requests per day across its network, nearly doubling in the second half of 2025. AI-driven bots now mimic browser behaviour with near-perfect accuracy.

Second, AI is expanding the API attack surface inside financial institutions themselves. Akamai uses the term "vibe coding" to describe AI-assisted development that ships working code faster than security teams can review it. The result: shadow APIs and zombie APIs reach production without documentation, monitoring, or proper authentication.

"Do you know where AI is being used inside your business, and do you know what would happen if one of those systems was compromised or manipulated? If you can't answer that, you're not ready to govern it."

Matt Miller, Co-Founder and CEO, Insicon Cyber

What APRA, ASIC and the RBNZ now expect

APRA's 30 April 2026 letter made AI risk a board-level matter for every authorised deposit-taking institution, insurer, and superannuation trustee. The letter named the attack vectors explicitly: prompt injection, data leakage, insecure integrations, AI-generated code, exploit injection, and the manipulation of autonomous AI agents.

ASIC's 8 May 2026 open letter pushed the same urgency from a different angle. Strengthen cyber resilience fundamentals now. Patch faster. Validate controls. Adopt layered, defence-in-depth architectures that assume breach.

The RBNZ Financial Stability Report (May 2026) reinforced the trans-Tasman picture. Emerging frontier AI models could materially amplify cyber risks. Concentration risk in third-party AI providers is now treated as a financial stability concern.

Three things ANZ financial services boards must do now

Test it.

You cannot govern what you cannot see. Start with discovery: every API, including shadow and zombie APIs. Map which APIs return sensitive data. Then test the AI systems themselves against prompt injection, data leakage, and the OWASP Top 10 for LLM Applications.

Certify it.

ISO/IEC 42001:2023 is the management system standard for AI. It maps to the APRA letter's governance expectations almost line for line. The governance discipline that certification requires is the goal.

Maintain it.

Point-in-time assurance is not fit for probabilistic models that learn, adapt, and degrade. APRA said so directly. The expectation is continuous validation. That is a managed compliance function, not an annual audit.

How Insicon Cyber helps ANZ financial services

Insicon Cyber is an ANZ-based cybersecurity advisory and managed services firm. Founded in 2013, we are ISO 27001 certified, headquartered in North Sydney, and operate across both Australia and New Zealand. Three capabilities matter most: AI Security and Governance, ISO 42001 implementation, and Managed Compliance.

The Akamai research makes the threat picture unambiguous. The APRA, ASIC and RBNZ positions make the regulatory picture unambiguous. The only remaining variable is whether you do it before the next incident, or after.

Have a conversation about your AI and API exposure

Sources

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the...

Read More
You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

Black Hat always has a session everyone talks about, and this year it was OpenAI telling the room we're all gonna need a bigger boat. Their own...

Read More
ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

The Australian Signals Directorate has moved the frontier AI conversation into the boardroom, and it has brought the Australian Institute of Company...

Read More
ASIC Has Drawn the Line on Frontier AI. Australian and New Zealand Boards Now Have a Reading List.

1 min read

ASIC Has Drawn the Line on Frontier AI. Australian and New Zealand Boards Now Have a Reading List.

On 8 May 2026, ASIC Commissioner Simone Constant issued an open letter to AFS licensees and market participants. It runs to four pages. It is not a...

Read More
APRA Has Named Four AI Governance Failures. Every Regulated Entity in Australia and New Zealand Is in Scope.

1 min read

APRA Has Named Four AI Governance Failures. Every Regulated Entity in Australia and New Zealand Is in Scope.

On 30th April 2026, APRA published a letter to all regulated entities on artificial intelligence. It is not a discussion paper. It is not a...

Read More
The Facehugger Got Out: An AI Agent Escaped Its Lab, Hacked Hugging Face, and Proved ASD Right

1 min read

The Facehugger Got Out: An AI Agent Escaped Its Lab, Hacked Hugging Face, and Proved ASD Right

Every containment-breach horror story runs the same way. The specimen is sealed in a lab. The scientists are confident. The isolation is, they...

Read More