ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

infoResearchimportance 32
What's new: New story (first merged summary): coverage of the release of SpyCloud's 2026 Identity Threat Report; all key facts are new. The three sources are consistent with no discrepancies. CSO Online uniquely adds the stolen session cookie/MFA bypass finding and the Identity Threat Protection Maturity Model, while Cyber Security News and GBHackers (identical reports) add the North America/Europe survey…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

SpyCloud's 2026 survey of 750 security leaders finds compromised non-human identities (31%) — nearly double phishing (17%) — are the top enterprise entry point, yet only 36% of organizations monitor them.

SpyCloud's 2026 Identity Threat Report, based on a survey of 750 cybersecurity leaders at organizations with 500+ employees across North America and Europe, found compromised non-human identities (31%) were the most cited primary attacker entry point, nearly twice as likely as phishing (17%). 68% of respondents reported identity-based events, averaging eight per affected organization. While 95% claim visibility into AI and non-human identity (NHI) exposures, only 36% actually monitor AI agents, service accounts and API keys. 91% use AI tools with internal access, but only 56% have formal governance over their privileges. Organizations with session-cookie visibility reported lower event rates (37% vs 50%), 40% lack a process to confirm third-party identity exposures were resolved, and automated remediation correlated with lower response costs and trust loss. The report also found stolen session cookies — which can bypass MFA — are now attackers' top target, and introduces an Identity Threat Protection Maturity Model.

  • Survey of 750 cybersecurity leaders at organizations with 500+ employees across North America and Europe
  • Compromised non-human identities (31%) were the most cited primary attacker entry point — nearly 2x phishing (17%)
  • 68% reported identity-based events, averaging eight per affected organization
  • 95% claim visibility into AI and NHI exposures, but only 36% actually monitor AI agents, service accounts and API keys
  • 91% use AI tools with internal access; only 56% have formal governance over their privileges
  • Organizations with session-cookie visibility reported lower event rates (37% vs 50%)
  • 40% lack a process to confirm third-party identity exposures were resolved
  • Stolen session cookies can bypass MFA and are now attackers' top target

Coverage timeline

  1. · 6d ago
    CSO Online· 30
    SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

    SpyCloud's 2026 survey of 750 security leaders finds compromised non-human identities are the top enterprise entry point, yet only 36% monitor them.

  2. · 6d ago
    Cyber Security News· 32
    SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

    SpyCloud survey of 750 security leaders finds compromised non-human identities are the top enterprise entry point, yet only 36% monitor them.

  3. · 6d ago
    GBHackers· 32
    SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

    SpyCloud survey of 750 security leaders finds compromised non-human identities are the top enterprise entry point, yet only 36% monitor them.