SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path
Ninety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them.
Austin, Texas / USA, September 9th, 2026/CyberNewswire/ - SpyCloud, the pioneer in identity threat protection, has released its annual SpyCloud Identity Threat Report, highlighting that non-human identities (NHIs) have emerged as the primary avenue for attackers to infiltrate enterprises. The survey, conducted among 750 cybersecurity leaders and practitioners from large organizations across North America, the UK, and select European countries, reveals that compromised NHIs are nearly twice as likely to serve as the initial entry point compared to phishing and social engineering tactics.
Organizations often underestimate the risk posed by these machine identities, as they typically lack proper visibility and monitoring. Despite 95% of surveyed organizations believing they have adequate visibility into AI- and NHI-related exposures, only 36% actively monitor them. This negligence contributes to the alarming fact that 68% of organizations faced identity-based events, with affected entities experiencing an average of eight incidents each.
The report underscores the need for improved governance and visibility into service accounts, API keys, and AI agents that authenticate within enterprise systems. These identities, often provisioned for convenience, can remain dormant and unmanaged for extended periods. Trevor Hilligoss, SpyCloud's Chief Intelligence Officer, emphasizes that attackers exploit this asymmetry, as once an NHI is exposed, it remains usable until someone detects and addresses the issue.
The report also examines the impact of AI adoption, which has outpaced governance, with 91% of organizations utilizing AI tools or agents with access to internal systems. However, only 56% have formal governance and ownership in place, leaving room for shadow access – privileged connections operating outside normal governance and monitoring.
Exposed session blind spots also play a significant role in identity-based events. Organizations with visibility into stolen session cookies reported lower event rates (37%) compared to those without (50%). Moreover, session data has become the top target for attackers, surpassing passwords as they bypass authentication controls like MFA, allowing attackers to gain trusted access to applications and data.
Phishing and malware remain the primary delivery mechanisms for identity events, with 37% citing phishing and social engineering as common access paths. However, 53% of organizations can only monitor malware exposures on managed devices. Supply chain identity events, including malware-infected third-party devices and exposed API keys or application access involving vendors and partners, are also on the rise.
The report introduces SpyCloud's Identity Threat Protection Maturity Model, which categorizes organizations into four maturity tiers based on their visibility, monitoring, governance, automation, and remediation capabilities. The findings suggest that organizations with more mature identity programs rely on continuous exposure monitoring and automated remediation, leading to lower incident rates.
Ultimately, while some level of exposure is inevitable, the key to effective identity management lies in minimizing the duration of usable exposures. Most identity programs are measured solely by whether an exposure occurred, rather than the length of time it remains exploitable. Organizations must shift their focus to detecting and addressing these exposures promptly to mitigate the risks associated with non-human identities and third-party vulnerabilities.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.