Case Study

Ulta Beauty Reduces Costs by Blocking API-based Enumeration Attacks

Ulta Beauty Reduces Costs by Blocking API-based Enumeration Attacks

Pages 1 Pages

Ulta Beauty partnered with Cequence Security to stop a large-scale API enumeration attack targeting a third-party local-inventory search API. The attack generated traffic 700 times higher than normal, cycling through over 153,000 product and SKU combinations and scraping data across 61,000 zip codes. While the attackers’ motives were unclear, possibilities included mapping popular inventory for real-world theft. By mitigating the attack, Ulta Beauty significantly reduced infrastructure and inventory-related costs, preventing further exploitation and ensuring API security.

Join for free to read