Urgent.News

What's breaking now, across thousands of outlets.

Tech

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

Austin, Texas / USA, 9th September 2026, CyberNewswire

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent of organizations believe they possess comprehensive visibility into their AI and machine identity exposures, yet only 36% are effectively monitoring them. SpyCloud, the premier provider of identity threat protection, has released its annual SpyCloud Identity Threat Report, a survey-based study revealing non-human identities (NHIs) as the leading route for attackers to infiltrate enterprises.

The report states that compromised NHIs are nearly twice as likely to serve as the primary entry point compared to phishing and social engineering, which rank second. The vast majority of organizations fail to monitor non-human identities, with 95% believing they have adequate visibility into AI- and NHI-related exposures, while only 36% actively monitor them.

The report also highlights that 68% of organizations experienced an identity-based event in the same period, with affected organizations averaging eight events each. Organizations typically maintain a clear inventory of their human workforce but often overlook the monitoring of service accounts, API keys, and AI agents that authenticate into their systems daily.

These identities, provided for convenience and often holding real privilege, remain unmanaged: a service account remains un-offboarded, fails to rotate its credentials, and evades MFA challenges, allowing it to remain accessible for months. Trevor Hilligoss, SpyCloud's Chief Intelligence Officer, attributes this to attackers exploiting the asymmetry between the coverage of protections on human identities and non-human identities.

"Every one of these identities is a standing invitation that renews itself until someone notices," Hilligoss explains. This year's report surveyed 750 cybersecurity leaders and practitioners from organizations with over 500 employees across North America, the United Kingdom, and select European markets. The study benchmarks how organizations detect, remediate, and govern identity threats across both human and non-human identities.

Additional key findings include: Organizations have rushed AI adoption ahead of governance, with nearly all (91%) employing AI tools or agents with access to internal systems, but only 56% having formal governance and ownership for the resulting privileges. A significant 41% rely on informal processes or partial ownership, resulting in shadow access – privileged connections operating outside normal governance and monitoring.

Organizations with visibility into stolen session cookies reported a significantly lower rate of identity-based events (37%) compared to those without this visibility (50%). Stolen session cookies and tokens enable attackers to bypass authentication controls like MFA by resuming an already-authenticated session, granting them trusted access to applications and data.

This finding suggests that session data has surpassed passwords as attackers' primary targets. Phishing and malware remain the delivery mechanisms for identity events, with phishing cited as a common access path for identity events (37%). However, 53% of respondents can only see malware exposures on managed devices. Malware-infected third-party devices and exposed API keys or application access involving vendors and partners were the leading causes of supply chain identity events.

Despite these exposures, nearly 40% of organizations lack a consistent process to confirm that a third-party identity exposure has been resolved. Non-human identities and third-party exposures are creating new pathways into the enterprise, while stolen sessions provide attackers with ways to circumvent controls designed to protect authenticated users.

Hilligoss notes that every control that works pushes attackers toward what it doesn't cover, leading them to target service accounts and vendor connections. The report introduces SpyCloud's Identity Threat Protection Maturity Model, which categorizes respondents into four maturity tiers - Reactive, Building, Operational, and Optimized - based on visibility, monitoring, governance, automation, and remediation.

The findings show that as identity programs mature, they rely more on continuous identity exposure monitoring and automated remediation, leading to a reduction in incident rates. At enterprise scale, some share of an organization's employees, vendors, and machine accounts will inevitably be exposed, regardless of how robust its controls are.

The key to improving business outcomes lies in how quickly these organizations address the exposures.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at devops.com →

More in Tech

More from Wednesday 9 September →