{"id":9371,"date":"2026-09-09T12:00:00","date_gmt":"2026-09-09T12:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9371"},"modified":"2026-09-09T12:00:00","modified_gmt":"2026-09-09T12:00:00","slug":"spycloud-2026-identity-threat-report-finds-non-human-identities-are-now-the-leading-path-into-the-enterprise","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9371","title":{"rendered":"SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\"><strong>Ninety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them.<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/spycloud.com\/\">SpyCloud<\/a>, the leader in identity threat protection, today released its annual <a href=\"http:\/\/spycloud.com\/resource\/report\/identity-threat-report-2026\/\"><strong>SpyCloud Identity Threat Report<\/strong><\/a>, a survey-based study finding that non-human identities (NHIs) \u2013 the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems \u2013 have become the most common route attackers take into the enterprise.<\/p>\n<p class=\"wp-block-paragraph\">SpyCloud 2026 Identity Threat Report, Source: SpyCloud<\/p>\n<p class=\"wp-block-paragraph\">The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer. NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organizations aren\u2019t watching for them. While 95% of organizations believe they have adequate visibility into AI- and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report. Further amplifying the problem, 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events each.<\/p>\n<p class=\"wp-block-paragraph\">Organizations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day. These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn\u2019t get off-boarded, doesn\u2019t rotate its own credentials, and doesn\u2019t fail an MFA challenge, so once one is exposed it can stay usable for months.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat asymmetry is what attackers are exploiting,\u201d said <strong>Trevor Hilligoss, SpyCloud\u2019s Chief Intelligence Officer.<\/strong> \u201cEvery one of these identities is a standing invitation that renews itself until someone notices.\u201d<\/p>\n<p class=\"wp-block-paragraph\">This year\u2019s report is based on a survey of 750 cybersecurity leaders and practitioners at organizations with 500+ employees across North America (US and Canada), the United Kingdom, and select European markets \u2013 Spain, Germany, the Netherlands, Austria, and Switzerland. It benchmarks how organizations detect, remediate, and govern identity threats across human and non-human identities.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Additional key findings include:<\/strong><\/p>\n<p><strong>AI adoption has outpaced governance. <\/strong>Nearly all organizations (91%) use AI tools or agents with access to internal systems, applications, or data, but only 56% have formal governance and ownership for the resulting privileges. Another 41% rely on informal processes or partial ownership, leaving shadow access \u2013 privileged connections operating outside normal governance and monitoring.<\/p>\n<p><strong>Exposed session blind spots track with higher event rates. <\/strong>Organizations that had visibility into stolen session cookies experienced identity-based events at a meaningfully lower rate (37%) than those that could not (50%).\u00a0<\/p>\n<p>Session cookies and tokens let attackers bypass authentication controls like MFA by resuming an already-authenticated session. This gives them trusted access to applications and data, it\u2019s no surprise then that SpyCloud research shows that session data has overtaken passwords as <a href=\"https:\/\/spycloud.com\/newsroom\/spycloud-surpasses-one-trillion-recaptured-identity-assets\/\">attackers\u2019 top target<\/a>.<\/p>\n<p><strong>Phishing and malware remain the delivery mechanism. <\/strong>Phishing and social engineering is cited as a common access path for identity events (37%) with 40% reporting incomplete visibility into successful phishing attacks, and 53% can see malware exposures on managed devices <em>only<\/em>.<\/p>\n<p><strong>Malware and exposed access top the list of supply chain identity events. <\/strong>Malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%) were the leading reported causes of supply chain identity events.<\/p>\n<p><strong>Third-party exposures are getting found, but not closed. <\/strong>Nearly 40% of organizations have no consistent process to confirm that a third-party identity exposure was actually resolved, even as 32% name enhancing supply chain and vendor risk management among their planned investments for the next 12 to 18 months.<\/p>\n<p class=\"wp-block-paragraph\">Non-human identities and third-party exposures are creating new paths into the enterprise, while stolen sessions give attackers ways around controls designed to protect authenticated users.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEvery control that works pushes attackers toward what it doesn\u2019t cover \u2013 we hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections,\u201d added Hilligoss. \u201cSpyCloud continues to track threat actor behavior closely to understand where attackers are moving, what data they value, and how those patterns evolve over time.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><strong>Continuous monitoring &amp; automation separate the most resilient identity programs<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Identity exposure creates an ongoing operational burden that extends well beyond the initial incident, and how quickly organizations respond has a direct impact on business outcomes. Those relying on manual, case-by-case remediation reported higher incident response costs than organizations with high levels of automation (39% versus 32%) and greater loss of customer or partner trust (47% versus 36%).<\/p>\n<p class=\"wp-block-paragraph\">The report also introduces <a href=\"https:\/\/spycloud.com\/identity-threat-protection-maturity-assessment\/\">SpyCloud\u2019s Identity Threat Protection Maturity Model<\/a>, which groups respondents into four maturity tiers \u2013 Reactive, Building, Operational, and Optimized \u2013 across identity exposure visibility, monitoring, governance, automation, and remediation. The findings reflect that the more mature an identity program gets, the more it relies on continuous identity exposure monitoring and automated remediation \u2013 and that combination is what actually drives incident rates down.<\/p>\n<p class=\"wp-block-paragraph\">At enterprise scale, some share of an organization\u2019s employees, vendors, and machine accounts will be exposed in the near future regardless of how strong its controls are. What changes business outcomes is how long that exposure stays usable.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMost identity programs are still measured on whether an exposure happened. That\u2019s the wrong scoreboard,\u201d said <strong>Damon Fleury, Chief Product Officer at SpyCloud<\/strong>. \u201cOrganizations that pair continuous identity monitoring with automated remediation of workforce exposures create the greatest friction for criminals and gain the biggest edge in preventing follow-on attacks.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Users can access the full, no form-fill <a href=\"http:\/\/spycloud.com\/resource\/report\/identity-threat-report-2026\/\">2026 SpyCloud Identity Threat Report<\/a> and benchmark their organization against the Identity Threat Protection Maturity Model by taking the free assessment <a href=\"https:\/\/spycloud.com\/identity-threat-protection-maturity-assessment\/\">here<\/a>.<\/p>\n<p class=\"wp-block-paragraph\"><strong>About SpyCloud<\/strong><\/p>\n<p class=\"wp-block-paragraph\">SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from the threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings. Customers include 7 of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.<\/p>\n<p class=\"wp-block-paragraph\">To learn more and see insights on your company\u2019s exposed data, visit<a href=\"http:\/\/spycloud.com\/\"> spycloud.com<\/a>.<\/p>\n<h5 class=\"wp-block-heading\"><strong>Contact<\/strong><\/h5>\n<p class=\"wp-block-paragraph\"><strong>Account Director<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><strong>Emily Brown<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><strong>REQ on behalf of SpyCloud<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><strong>spycloud@req.co<\/strong><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Ninety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them. SpyCloud, the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report, a survey-based study finding that non-human identities (NHIs) \u2013 the AI agents, service accounts, API keys, and authentication [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9372,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9371","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9371"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9371"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9371\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9372"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9371"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}