SpyCloud, the leader in identity threat protection, today released annual SpyCloud Identity Threat Report, survey-based study finding that non-human identities NHIs AI agents, service accounts, API keys, and authentication tokens that connect to internal systems have become most common route attackers take into enterprise. Report was released from Austin, Texas, on September 9, 2026.
Organizations typically maintain clear inventory of human workforce, but few extend same visibility to service accounts, API keys, and AI agents authenticating into systems every day. Identities provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: service account doesn't get off-boarded, doesn't rotate own credentials, doesn't fail MFA challenge, so once exposed can stay usable for months.
"That asymmetry is what attackers are exploiting," said Trevor Hilligoss, SpyCloud Chief Intelligence Officer. "Every one of these identities standing invitation that renews itself until someone notices."
Additional key findings: AI adoption outpaced governance. Nearly all organizations 91% use AI tools or agents with access to internal systems, applications, or data, but only 56% have formal governance and ownership for resulting privileges. Another 41% rely on informal processes or partial ownership, leaving shadow access privileged connections operating outside normal governance and monitoring.
Exposed session blind spots track with higher event rates. Organizations that had visibility into stolen session cookies experienced identity-based events at meaningfully lower rate 37% than those that could not 50%. Session cookies and tokens let attackers bypass authentication controls like MFA by resuming already-authenticated session. SpyCloud research shows session data has overtaken passwords as attackers top target.
Phishing and malware remain delivery mechanism. Phishing and social engineering cited as common access path for identity events 37% with 40% reporting incomplete visibility into successful phishing attacks, and 53% can see malware exposures on managed devices only.
Malware and exposed access top list of supply chain identity events. Malware-infected third-party devices 23% and exposed API keys or application access involving vendors and partners 22% leading reported causes.
Third-party exposures getting found but not closed. Nearly 40% of organizations have no consistent process to confirm third-party identity exposure actually resolved, even as 32% name enhancing supply chain and vendor risk management among planned investments for next 12 to 18 months.
Identity exposure creates ongoing operational burden beyond initial incident, and how quickly organizations respond has direct impact on business outcomes. Those relying on manual, case-by-case remediation reported higher incident response costs than organizations with high levels of automation 39% versus 32% and greater loss of customer or partner trust 47% versus 36%.
Report introduces SpyCloud Identity Threat Protection Maturity Model, which groups respondents into four maturity tiers Reactive, Building, Operational, Optimized across identity exposure visibility, monitoring, governance, automation, remediation. Findings reflect more mature program gets more it relies on continuous identity exposure monitoring and automated remediation and that combination drives incident rates down.
"Most identity programs still measured on whether exposure happened. That's wrong scoreboard," said Damon Fleury, Chief Product Officer at SpyCloud. "Organizations that pair continuous identity monitoring with automated remediation of workforce exposures create greatest friction for criminals."
About SpyCloud
SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Customers include 7 of Fortune 10.