SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
SpyCloud's 2026 survey of 750 security leaders finds compromised non-human identities (31%) — nearly double phishing (17%) — are the top enterprise entry point, yet only 36% of organizations monitor them.
SpyCloud's 2026 Identity Threat Report, based on a survey of 750 cybersecurity leaders at organizations with 500+ employees across North America and Europe, found compromised non-human identities (31%) were the most cited primary attacker entry point, nearly twice as likely as phishing (17%). 68% of respondents reported identity-based events, averaging eight per affected organization. While 95% claim visibility into AI and non-human identity (NHI) exposures, only 36% actually monitor AI agents, service accounts and API keys. 91% use AI tools with internal access, but only 56% have formal governance over their privileges. Organizations with session-cookie visibility reported lower event rates (37% vs 50%), 40% lack a process to confirm third-party identity exposures were resolved, and automated remediation correlated with lower response costs and trust loss. The report also found stolen session cookies — which can bypass MFA — are now attackers' top target, and introduces an Identity Threat Protection Maturity Model.
- Survey of 750 cybersecurity leaders at organizations with 500+ employees across North America and Europe
- Compromised non-human identities (31%) were the most cited primary attacker entry point — nearly 2x phishing (17%)
- 68% reported identity-based events, averaging eight per affected organization
- 95% claim visibility into AI and NHI exposures, but only 36% actually monitor AI agents, service accounts and API keys
- 91% use AI tools with internal access; only 56% have formal governance over their privileges
- Organizations with session-cookie visibility reported lower event rates (37% vs 50%)
- 40% lack a process to confirm third-party identity exposures were resolved
- Stolen session cookies can bypass MFA and are now attackers' top target
Coverage timelineoldest first · each row is one article
- · 6d agoSpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
CSO Online· 30
SpyCloud's 2026 survey of 750 security leaders finds compromised non-human identities are the top enterprise entry point, yet only 36% monitor them.
- · 6d agoSpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Cyber Security News· 32
SpyCloud survey of 750 security leaders finds compromised non-human identities are the top enterprise entry point, yet only 36% monitor them.
- · 6d agoSpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
GBHackers· 32
SpyCloud survey of 750 security leaders finds compromised non-human identities are the top enterprise entry point, yet only 36% monitor them.