SpyCloud has marked its 10-year anniversary, celebrating a decade spent transforming recaptured darknet data into actionable identity intelligence to protect businesses and consumers from identity attacks. The company has grown from a founding team to more than 250 employees protecting 4+ billion accounts for hundreds of global enterprises, including 7 of the Fortune 10.
SpyCloud celebrates 10 years of identity threat protection.
Protects 4+ billion accounts for 7 Fortune 10 companies.
Identity data repository exceeds one trillion recaptured assets.
Stolen session cookies and tokens now nearly half of all recaptured assets.
Automation revokes stolen sessions and resets exposed credentials.
Contributes to law enforcement operations including Tycoon 2FA takedown and Operation Serengeti.
Since 2016, SpyCloud's identity data repository has expanded past one trillion assets recaptured from infostealer malware, successful phishing attacks, combolists, and third-party breaches. Integrations with IdP, EDR, SIEM, and SOAR platforms turn that visibility into action, automatically revoking stolen sessions, resetting exposed credentials, and quarantining infected devices before stolen access can be weaponized. SpyCloud has worked alongside the FBI, Europol, the World Economic Forum's Cybercrime Atlas, and OSINT Foundation, contributing to law enforcement referrals and takedowns including the Tycoon 2FA phishing kit, Euroboss, and Operations Serengeti I and II.
Stolen session cookies and tokens now account for nearly half of all recaptured identity assets in SpyCloud's repository, overtaking passwords as the fastest-growing exposure category. Attackers have moved past the credential and into the session itself, exploiting a definition of identity most security programs were never built to protect. SpyCloud is closing that gap with automation that gives organizations visibility into compromised cookies, tokens, and credentials across workforce and consumer applications, enabling teams to invalidate sessions, revoke tokens, and require reauthentication automatically. As identity security expands to include non-human identities including APIs, service accounts, and AI agents, SpyCloud is extending automated remediation across the full identity lifecycle.
"Ten years ago, we founded SpyCloud with a clear mission: turn criminals' own data against them to disrupt the cybercrime economy," said Ted Ross, CEO and co-founder of SpyCloud. "Over the last decade, we've built the world's largest recaptured data lake and developed automation that works across every authentication environment, including passwordless, to give organizations the ability to act before identity compromise becomes business impact. This next decade is about extending that protection across the full spectrum of human and non-human identities to effectively stop criminals from using stolen identity data and access to fuel attacks."
About SpyCloud
SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings. Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts.