The Good Tech Companies - SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path
Episode Date: September 9, 2026This story was originally published on HackerNoon at: https://hackernoon.com/spycloud-2026-identity-threat-report-finds-non-human-identities-are-now-the-leading-path. Ni...nety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them. Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #cybersecurity, #spycloud, #cybernewswire, #press-release, #cyber-security-awareness, #spycloud-announcement, #cybercrime, #good-company, and more. This story was written by: @cybernewswire. Learn more about this writer by checking @cybernewswire's about page, and for more stories, please visit hackernoon.com.
Transcript
Discussion (0)
This audio is presented by Hacker Noon, where anyone can learn anything about any technology.
SpyCloud 2026 Identity Threat Report finds non-human identities are now the letting path by Cyber Newswire.
Austin, Texas, USA, September 9, 2026, Cyber Newswire, Spy Cloud, the leader in identity threat protection,
today released its annual Spy Cloud Identity Threat Report, a survey-based study finding that
non-human identities, N-HIs, the I agents, service accounts, API keys, and authentication tokens that
connect to internal systems have become the most common root attackers taken to the enterprise.
SPY-C-L-O-U-D-26 identity threat report, source, SPY cloud the survey found that compromised NHIs,
31% are nearly 2x as likely to be the primary entry point compared to fishing and social engineering,
17% the second ranked answer. NHA related misuse was also the most commonly reported identity-based
event type at 42% yet the vast majority of organizations aren't watching for them. While 95% of organizations
believe they have adequate visibility into AI and NHA related exposures, only 36% monitor them,
making machine identities the least watched category of identity risk in the report.
Further amplifying the problem, 68% of organizations experience,
an identity-based event in the same period, with those affected averaging eight events each.
Organizations typically maintain a clear inventory of their human workforce, but few extend that
same visibility to the service accounts, API keys, and AI agents authenticating into their systems
every day. These identities are provisioned for convenience and often hold real privilege,
yet in most environments nobody owns them. A service account doesn't get off-boarded, doesn't rotate
its own credentials and doesn't fail an MFA challenge, so once one is exposed it can't stay usable
for months. Greater than that asymmetry is what attackers are exploiting, said Trevor Hillegos,
greater than Spike Cloud's chief intelligence officer. Every one of these identities is a greater
than standing invitation that renews itself until someone notices. This year's report is based on a
survey of 750 cybersecurity leaders and practitioners at organizations with 500 plus employees
across North America, U.S. and Canada, the United Kingdom, and select European markets, Spain,
Germany, the Netherlands, Austria, and Switzerland. It benchmarks how organizations detect,
remediate, and govern identity threats across human and non-human identities. Additional key findings
include AI adoption has outpaced governance. Nearly all organizations, 91%, use AI tools or agents
with access to internal systems, applications, or data, but only 56% have formal governance
and ownership for the resulting privileges. Another 41% rely on informal processes or partial
ownership, leaving shadow access, privileged connections operating outside normal governance
and monitoring. Exposed session blind spots track with higher event rates.
Organizations that had visibility into stolen session cookies experienced identity-based
events at a meaningfully lower rate, 37% than
those that could not, 50%. Session cookies and tokens let attackers bypass authentication controls
like MFA by resuming an already authenticated session. This gives them trusted access to
applications and data. It's no surprise then that SpyCloud research shows that session data has
overtaken passwords as attack is top target. Fishing and malware remain the delivery mechanism. Fishing
in social engineering is cited as a common access path for identity events, 37%, with 40% report
importing incomplete visibility into successful fishing attacks, and 53% can see malware exposures
on managed devices only. Malware and exposed access top the list of supply chain identity
events. Malware infected third-party devices, 23%, and exposed API keys or application access
involving vendors and partners, 22%, were the leading reported causes of supply chain identity events.
Third-party exposures are getting found, but not closed. Nearly 40%
of organizations have no consistent process to confirm that a third-party identity exposure was
actually resolved, even as 32% name-enhancing supply chain and vendor risk management among their
planned investments for the next 12 to 18 months. Non-human identities and third-party exposures are
creating new paths into the enterprise, while stolen sessions give attackers ways around controls
designed to protect authenticated users. Greater than every control that works pushes attackers
toward what it doesn't cover, we greater than hardened passwords, so they targeted sessions,
we tightened employee accounts, greater than so they looked to service accounts and vendor
connections, added hiligoths.
Greater than, SpyCloud continues to track threat actor behavior closely to understand where
greater than attackers are moving, what data they value, and how those patterns evolve
over greater than time.
Continuous monitoring and automation separate the most resilient identity programs' identity
exposure creates an ongoing operational burden that extends well beyond the initial incident,
and how quickly organizations respond has a direct impact in business outcomes. Those relying on
manual, case-by-case remediation reported higher incident response costs than organizations with
high levels of automation, 39% versus 32% and greater loss of customer or partner trust,
47% versus 36%. The report also introduces Spy Cloud's identity threat protection maturity model,
which groups respondents into four maturity tiers, reactive, building, operational, and optimized,
across identity exposure visibility, monitoring, governance, automation, and remediation.
The findings reflect that the more remature and identity program gets, the more it relies on
continuous identity exposure monitoring and automated remediation, and that combination is what
actually drives incident rates down. At enterprise scale, some share of an organization's employees,
vendors, and machine accounts will be exposed in the near future regardless of how strong its controls are.
What changes business outcomes is how long that exposure stay suesable.
Most identity programs are still measured on whether an exposure happened.
That's the wrong scoreboard, said Damon Flurry, chief product officer at SpyCloud.
Organizations that pair continuous identity monitoring with automated remediation of workforce
exposures create the greatest friction for criminal sand gain the biggest edge in preventing follow-on
attacks.
Users can access the full, No Form-Fill-26 Spy Cloud Identity Threat Report and benchmark their
organization against the identity threat protection maturity model by taking the free assessment
here.
About SPY CloudSpy Cloud transforms recaptured darknet data to disrupt cybercrime.
Its automated identity threat protection solutions use advanced analytics and AI to accelerate
investigations and protect workforce, consumer, and supplier identities from the threats
that matter most.
authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud.
Its data from malware-infected devices, successful fishes, combalists, and third-party breaches
also powers many popular dark web monitoring and identity theft protection offerings.
Customers include seven of the Fortune 10, along with hundreds of global enterprises,
mid-sized companies, and government agencies worldwide.
Headquartered in Austin, Texas, SpyCloud is home to
more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the
stolen identity data criminals are using to target them now. To learn more and see insights on your
company's exposed data, visit SpyCloud.com contact account director Emily Brown, REQ on behalf of
SpyCloud, SpyCloud at Rec. CO, this story was published as a press release by Cyber Newswire
under Hackernoon Business Blogging Program. Thank you for listening to this hackernoon story,
read by artificial intelligence.
Visit hackernoon.com to read, write, learn and publish.
