Biggest Data Breaches Caused by API Mistakes

Published October 10, 2022
Author

Omer Imran Malik

Data Privacy Legal Manager, Securiti

FIP, CIPT, CIPM, CIPP/US

Listen to the content

Given that over 80% of internet traffic runs through APIs, it's no surprise that cybercriminals often try to find ways to exploit API vulnerabilities.

Over the last decade, major data breach incidents have increased, affecting hundreds of millions as attackers exploit data dependencies in everyday life. The number of data breaches increased by 68% year-over-year in 2021, setting a new record.

Private information tends to be a profitable data mound, hence the increase in the number of data breaches. And although data breaches are becoming increasingly common, even the largest organizations are unprepared for these attacks.

How Does an API Attack Work?

An API is an intermediary software tool that facilitates the connection between applications. In most cases, APIs contain information about their implementation methods and structure.

When a cybercriminal gains access to this information, they can use it to launch cyberattacks. Typically, the attacker will try to find more API vulnerabilities ranging from a lack of encryption to a poor authentication process.

It is essential to note that API attacks can be launched in various innovative ways, and they tend to be very different, making them harder to detect, predict and protect against.

Top Breaches Caused by API Mistakes

We have compiled a list of the top data breaches caused by API vulnerability exploitation that will significantly help organizations better understand the importance of data security and why to invest more in security costs.

Yahoo

In December 2016, Yahoo revealed that over three billion user accounts were breached. The attack took place three years earlier, in August 2013. Yahoo revealed that sensitive personal information, including names, phone numbers, dates of birth, and encrypted passwords, was part of the breach.

The attack began with a spear-phishing email sent years ago to an employee. The cybercriminal targeted two main areas: Yahoo's user database and the Account Management Tool, which is used to edit the database. After gaining privileges, the cybercriminal escalated it by installing a backdoor on a server that would always allow them access. Soon, the attacker stole the backup copy of Yahoo's user database and transferred it to their own computer.

It is critical to note that at the time, Yahoo was in the process of being acquired by Verizon, and it was estimated that a group of criminals had accessed the account records of more than a billion of its customers. Yahoo said the revised estimate was not a new security issue and sent emails to all additional affected user accounts.

LinkedIn

LinkedIn, owned by Microsoft, has always been an invaluable target for cybercriminals. In June 2021, A hacker called "God User Tom Liner'' used data scraping techniques by exploiting the site's APIs to collect over 700 million users' information and posted them for sale on a dark web forum called RaidForums, impacting over 90% of its user base.

A sample of extracted data posted by God User contained information like usernames, email addresses, phone numbers, geo-location logs, gender, and other social network account information. LinkedIn claims that the attack could not be technically termed a breach because the information exposed was already public, and it seemed to be an “aggregation of data from several websites and companies” and “publicly viewable member profile data.”

However, the implication of this incident is that more cybercriminals will leverage this vulnerability to scrape more data on LinkedIn APIs. Also, they will have a large amount of data to create compelling social engineering attacks after the leak, as warned by the NCSC in the UK.

Facebook

It was revealed in April 2019 that two datasets from third-party Facebook applications had been exposed to the public internet. The information contained the details of more than 530 million Facebook users, which included their phone numbers, account names, and Facebook IDs - and in some cases, even passwords set by the 22,000 users for the third-party Facebook application had been exposed.

This attack was possible because of the third-party developer’s API vulnerability. The API allows Facebook users to view their account interface from the perspective of other users. However, its loophole allowed the attacker to get access tokens which he used to escalate the privileges that resulted in the attack.

This attack is seen as a huge breach of Facebook’s user privacy when the implications are considered. One of which was the free publication of the extracted data on the dark web Two years later (April 2021). This publication included information as sensitive as mobile phone numbers of users on the dark web and passwords they might have used for other online accounts (including their Facebook passwords).

USPS Customer Database

The USPS customer database was another target in 2018. Critical information belonging to over 60 million users was exposed to attackers because of the vulnerabilities found in their API service.

This attack was initiated on their API called “informed visibility”, which was designed to let businesses, advertisers, and other bulk mail senders “make better business decisions by providing them with access to near real-time tracking data” about mail campaigns and packages.

Reports state that the attacker was able to gain privileged access to the API because of poor access control. Moreover, API already has an unpatched vulnerability that exposes its users while performing its function. Hence, when the attacker gained access to the API, they encountered no anti-scraping mechanisms that would prevent him from querying the API and extracting users’ vital information.

It seemed the attacker, however, was not malicious in nature, as he contacted the media about the discovery of this API vulnerability and wished for USPS to fix it - this flawed API was then eventually removed by USPS.

How to Protect Your APIs from Attacks and Breaches

Because organizations and developers are eager to digitize their businesses and advance their transformation goals, they need to invest in implementing API security best practices such as API testing.

To mitigate an API data breach, an organization should follow these steps to secure its existing APIs:

  • Identify APIs within your organization to avoid the risk of hidden or zombie APIs.
  • Use detailed access controls for each API to authenticate users and avoid broken user authentication.
  • Implement encryption methods to ensure secure data transfer.
  • Implement API request rate limit to mitigate IP abuse.
  • Ensure collaboration between developers, IT, and security teams.

Verdict

Proper cybersecurity practice advocates for mitigation before a response. Lately, threat actors think out of the box in order to perform many of the devastating attacks we see today. Hence, it is necessary that everything is built with a secure foundation.

This cannot be emphasized enough since the risk that is projected from API exploitations can cost billions of dollar loss for any affected enterprise. Enterprises can also patch up vulnerabilities discovered in their API services to meet up with the required protection standards to keep their business thriving.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 59:11
Data Controls for AI: Findings from the 2026 GigaOm DSPM Research
Watch Now View
Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Latest
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach View More
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach
Picture this: a fictional but entirely plausible scenario. An Australian financial institution's AI systems spend six months accessing a customer data repository nobody has...
View More
One Unrevoked Key, 37.5 Million People: What the Coupang data breach reveals about data access
Executive summary In June 2026, South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.68 billion won (approximately $409 million) which was the largest...
Enterprise Risk Management View More
What Is Enterprise Risk Management? Framework & Best Practices
Learn what Enterprise Risk Management (ERM) is, why it matters, key risk types, how ERM works, leading frameworks and standards, and how Securiti can...
View More
What is Data Transparency? Why it Matters for the Modern Enterprise
Learn what data transparency is, why it matters, and how organizations can improve visibility, accountability, governance, trust, and responsible data use.
View More
Green-Light AI, Not Data Exposure
Learn the five critical data-layer controls enterprises need to prevent sensitive data exposure and enable secure, scalable AI agent adoption.
Agentic AI Readiness View More
Agentic AI Readiness: Why Your Enterprise Needs a New Data Security Paradigm
Learn how to secure Agentic AI by discovering sensitive data, mitigating AI risks, and building an enterprise-ready AI security strategy.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
"The Algorithm Did It" Is Now Dead in Court View More
“The Algorithm Did It” Is Now Dead in Court
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New