Jordanian Journal of Informatics and Computing

ISSN: 3080-6828 (Online)

Securing API Ecosystems in Banking: A Critical Review of Cyber Risks, Control Frameworks, and Future Trends

by 

Sopheaktra Huy ;

Sokroeurn Ang ;

Mony Ho ;

Vivekanandam Balasubramaniam

PDF logoPDF

Published: 2026/01/15

Abstract

The rapid evolution of open banking and digital financial services has fueled the widespread adoption of Application Programming Interfaces (APIs) across the banking sector. While APIs enable real-time payments, embedded finance, and seamless integration with third-party platforms, they simultaneously introduce critical cybersecurity risks including misconfigurations, excessive data exposure, broken authentication, and weak access controls. This review critically investigates the cyber threat landscape of financial APIs by synthesizing academic literature, industry frameworks, and real-world breach reports. It evaluates the practical effectiveness of controls such as the OWASP API Security Top 10, Financial-grade API (FAPI) standards, and Zero Trust Architecture, and explores the emerging role of AI-driven security models including machine learning, deep learning, and Bayesian attack graph modeling. The key findings reveal persistent implementation gaps despite available standards, with real-world breaches like Twilio and Dell highlighting the high-risk exposure of unsecured APIs. The review also uncovers fragmented regulatory maturity between jurisdictions: while the EU leads with structured mandates like PSD2, the US and UK adopt more market-driven, inconsistent approaches posing challenges for global financial compliance. Furthermore, the study identifies underexplored threat vectors such as insider misuse, unmanaged shadow APIs, and third-party abuse areas rarely addressed in existing frameworks. Most importantly, it emphasizes a critical lack of integration between technical controls, regulatory policies, and lifecycle security implementation in real-world banking environments. This paper concludes with forward-looking recommendations to enhance API resilience through layered defenses, global regulatory alignment, AI-enhanced threat detection, and embedding security within software development pipelines.

Keywords

API SecurityOpen BankingCyber Risk ManagementZero Trust ArchitectureFinancialGrade APIArtificial Intelligent (AI)Machine Learning (ML).

How to Cite the Article

Huy, S., Ang, S., Ho, M., Balasubramaniam, V., & . (2026). Securing API Ecosystems in Banking: A Critical Review of Cyber Risks, Control Frameworks, and Future Trends. Jordanian Journal of Informatics and Computing, 2026(1), 25–37. https://doi.org/10.63180/jjic.thestap.2026.1.3

References

  1. Cybersecurity News. (2024). Twilio’s Authy breach exposes 33.4 million phone numbers via unauthenticated API. https://cybersecuritynews.com/securing-apis/
  2. Cybersecurity News. (2024). Dell customer data exposure affects 49 million records due to API vulnerability. https://cybersecuritynews.com/securing-apis/
  3. Behbehani, D., Rajarajan, M., Komninos, N., & Al-Begain, K. (2022). Detecting open banking API security threats using Bayesian attack graphs. In Proceedings of the 14th International Conference on Computational Intelligence and Communication Networks (CICN) (pp. 146–151). IEEE. https://doi.org/10.1109/CICN56167.2022.10008365
  4. Zuo, X., Su, Y., Wang, Q., & Xie, Y. (2020). An API gateway design strategy optimized for persistence and coupling. Advances in Engineering Software, 148, 102878.
  5. Basheer, N., Islam, S., Alwaheidi, M. K., & Papastergiou, S. (2024). Adoption of deep-learning models for managing threat in API calls with transparency obligation practice for overall resilience. Sensors, 24(15), 4859.
  6. OWASP Foundation. (2023). API security top 10 – 2023 edition. https://owasp.org/www-project-api-security/
  7. OpenID Foundation. (2024). Financial-grade API (FAPI) security profile. https://openid.net/wg/fapi/
  8. Casolaro, A. M. B., Rauber, G. N., & de Lima, U. S. M. (2024). Open banking: A systematic literature review. Journal of Banking Regulation. https://doi.org/10.1057/s41261-024-00262-x
  9. Briones de Araluze, G. K., & Cassinello Plaza, N. (2022). Open banking: A bibliometric analysis-driven definition. PLOS ONE, 17(10), e0275496. https://doi.org/10.1371/journal.pone.0275496
  10. Díaz-Rojas, J. A., Ocharán-Hernández, J. O., Pérez-Arriaga, J. C., & Limón, X. (2021, October). Web api security vulnerabilities and mitigation mechanisms: A systematic mapping study. In 2021 9th International Conference in Software Engineering Research and Innovation (CONISOFT) (pp. 207-218). IEEE.
  11. Gounari, M., Stergiopoulos, G., Pipyros, K., & Gritzalis, D. (2024). Harmonizing open banking in the European Union: An analysis of PSD2 compliance and interrelation with cybersecurity frameworks and standards. International Cybersecurity Law Review, 5(1), 79-120.
  12. Kumar, D., & Kumar, K. P. (2023, March). Artificial intelligence based cyber security threats identification in financial institutions using machine learning approach. In 2023 2nd International Conference for Innovation in Technology (INOCON) (pp. 1-6). IEEE.
  13. Jain, J., & Gupta, M. (2025, April). Cloud-Native Financial Intelligence: Distributed AI Architectures for Real-Time Market Analysis. In International Conference of Global Innovations and Solutions (pp. 267-278). Cham: Springer Nature Switzerland.
  14. Frei, C. (2023). Open banking: Opportunities and risks. In The Fintech disruption: how financial innovation is transforming the banking industry (pp. 167-189). Cham: Springer International Publishing.
  15. Premchand, A., & Choudhry, A. (2018, February). Open banking & APIs for transformation in banking. In 2018 international conference on communication, computing and internet of things (IC3IoT) (pp. 25-29). IEEE.
  16. Mansfield-Devine, S. (2016). Open banking: opportunity and danger. Computer Fraud & Security, 2016(10), 8-13.
  17. Boissay, F., Ehlers, T., Gambacorta, L., & Shin, H. S. (2021). Big techs in finance: on the new nexus between data privacy and competition. In The Palgrave handbook of technological finance (pp. 855-875). Cham: Springer International Publishing.
  18. Ali, M. A., & Salih, S. M. (2025). Impact of application programming interfaces (APIs) economy on digital economics in Saudi Arabia. Sustainability, 17(9), 4104.
  19. Babina, T., Bahaj, S., Buchak, G., De Marco, F., Foulis, A., Gornall, W., ... & Yu, T. (2025). Customer data access and fintech entry: Early evidence from open banking. Journal of Financial Economics, 169, 103950.
  20. Wang, S., Asif, M., Shahzad, M. F., & Ashfaq, M. (2024). Data privacy and cybersecurity challenges in the digital transformation of the banking sector. Computers & security, 147, 104051.
  21. Equixly. (2024). Cox Communications API flaw gives access to millions of modems. https://equixly.com/blog/2024/09/06/top-10-api-breaches-in-2024/
  22. The Australian. (2024). Aussie banks targeted in global cyber heist. https://www.theaustralian.com.au
  23. The Australian. (2024). Security flaw let hackers into super funds. https://www.theaustralian.com.au
  24. Business Insider. (2025). Citizens Bank open banking technology. https://www.businessinsider.com
  25. Silicon Digest. (2024). Barclays open banking APIs fintech collaboration. https://silicondigest.com
  26. Intellectsoft. (2024). How open banking APIs boost FinTech growth. https://www.intellectsoft.net
  27. Financial Times. (2024). US rolls out open banking rules. https://www.ft.com
  28. Traceable AI. (2024). Meeting regulatory and industry standards for API security. https://www.traceable.ai
  29. Central Bank of Oman. (2024). Open banking API specifications. https://cbo.gov.om
  30. European Banking Authority. (2019). Guidelines on ICT and security risk management. https://www.eba.europa.eu
  31. National Institute of Standards and Technology. (2020). Zero trust architecture (SP 800-207). https://doi.org/10.6028/NIST.SP.800-207
  32. Akamai. (2023). API security best practices: Protecting the digital gateway. https://www.akamai.com
  33. Salt Security. (2024). State of API security report (Q1 2024). https://salt.security/resources
  34. ENISA. (2023). Threat landscape for APIs. https://www.enisa.europa.eu
  35. IBM X-Force. (2024). Cloud threat landscape report: API vulnerabilities. https://www.ibm.com/security
  36. Mittal, A., Keshap, P., & Hosabettu, A. (2025, October). AI-Driven Real-Time API Security: Explainable Threat Detection for Cloud Environments. In 2025 IEEE International Carnahan Conference on Security Technology (ICCST) (pp. 1-7). IEEE.
  37. Bansal, A. K., Wadhwa, R., & Saini, S. (2024). Cybersecurity risks in open banking APIs. Journal of Information Security and Applications, 72, 103584.
  38. Alhuwayshil, S., Ramachandran, S., & Kim, K. (2025). Enhancing Ransomware Threat Detection: Risk-Aware Classification via Windows API Call Analysis and Hybrid ML/DL Models. Journal of Cybersecurity and Privacy, 5(4), 96.
  39. Colangelo, G., & Khandelwal, P. (2025). The many shades of open banking. Internet Policy Review, 14(1). https://doi.org/10.14763/2025.1.1821
  40. Mishra, S. (2023). Exploring the impact of AI-based cyber security financial sector management. Applied Sciences, 13(10), 5875.
  41. Qiu, M., Gai, K., Thuraisingham, B., Tao, L., & Zhao, H. (2018). Proactive user-centric secure data scheme using attribute-based semantic access controls for mobile clouds in financial industry. Future generation computer systems, 80, 421-429.