Cloudflare Reports 65% of API Traffic Now Encrypted — But DDoS Attacks on APIs Triple

Cloudflare's new API security report shows encryption gains offset by surge in Layer 7 DDoS and credential stuffing attacks targeting API endpoints.

Cloudflare has released its annual API Security Report, revealing that 65% of API traffic is now encrypted — up from 42% in 2025. However, the report also documents a threefold increase in Layer 7 DDoS attacks and credential stuffing attempts targeting API endpoints.

The report analyzed traffic across Cloudflare's global network, covering millions of API endpoints. Key findings include: the financial services sector faces the highest rate of API attacks, REST APIs remain the most targeted architecture, and GraphQL adoption is growing rapidly but introduces new security considerations.

Cloudflare recommends organizations implement API discovery, schema validation, and rate limiting as foundational security controls, alongside a Web Application Firewall (WAF) with API-specific rule sets.

Source: Cloudflare Blog