TL;DR
- 92% of government organizations experienced an identity-based event in the past year – the highest rate of any industry.
- 47% of government organizations tied credential or session exposure to phishing, compared with 30% overall.
- 95% of government organizations use AI tools or agents with internal access, but only 33% have formal governance and ownership for AI- and NHI-related privileges, compared with 56% overall.
- Government identity security is still maturing. More than half of government organizations fall into the Building tier, where response is less consistent, and 23% still remediate case by case.
Source note: Unless otherwise noted, findings in this article are based on SpyCloud’s 2026 Identity Threat benchmark research – a survey conducted in June 2026, that was the basis for the 2026 SpyCloud Identity Threat Report.
Government organizations reported the highest identity-based event rate of any industry in SpyCloud’s 2026 Identity Threat Report. In the past year, 92% of government organizations experienced an identity-based event, compared with 68% overall. Among those affected, the average was 10 events, compared with eight overall, and 81% experienced six or more.
Those events are occurring against a rapidly expanding identity attack surface. Government agencies must now manage identity risk across employee and contractor credentials, session cookies, tokens, API keys, service accounts, vendor connections, and AI agents and other non-human identities (NHIs), many of which sit outside the traditional username-and-password controls identity programs were built around.
Recent public warnings make that risk feel immediate. The FBI has warned about a smishing (malicious texts) and vishing (AI-generated voice messages) campaign impersonating senior U.S. officials to target current and former officials and their contacts, and has separately flagged OAuth consent phishing, where attackers gain persistent access through malicious authorization requests rather than stolen passwords.
For government agencies, the problem is no longer the occasional compromised account. It is continuous exposure across a wider range of identity assets. Reducing identity risk requires finding exposed assets early, prioritizing the access that matters, and remediating exposures proactively.
Government identity threats create consequences beyond security
When identity-based events recur, the damage does not stay contained in security operations. Government organizations reported higher rates of regulatory and legal consequences, leadership changes, operational downtime, and fraud than organizations overall.
Among government organizations that experienced an identity-based event:
faced regulatory or legal consequences vs. 38% overall
saw leadership changes or organizational restructuring vs. 36% overall
reported productivity or operational downtime vs. 39%
experienced unauthorized transactions or fraud vs. 40%
These impacts show how identity exposure can create consequences that reach well beyond the security team. With identity-based events recurring across government agencies, proactively reducing the window between exposure and remediation becomes even more important.
Government’s identity attack surface has moved beyond employee credentials
Seeing exposure early depends on knowing where to look, but the traditional identity security map for government agencies is increasingly out of date. Identity programs built around usernames and passwords now have to account for session cookies, tokens, API keys, cloud app access, third-party systems, and AI-enabled tools. SpyCloud’s 2026 Identity Exposure Report shows how these identity assets can provide trusted access without traditional login activity and span employees, contractors, vendors, applications, and non-human identities.
Defending against that exposure means accounting for the full identity ecosystem: human and non-human identities, managed and unmanaged devices, third parties, authenticated sessions, and the access paths automation creates.
Government's non-human identities have outgrown its governance
Government security teams rate non-human identity risks higher than almost any other sector. Nearly half (49%) rate AI-generated threats as high risk vs. 27% of organizations overall. Another 41% say the same of misconfigured or overprivileged non-human identities vs. 28% overall.
AI access is outpacing governance
of government organizations use AI tools or agents with internal access.
rely on informal, partial, or ad hoc processes for AI- and NHI-related privileges.
have formal ownership and policy, compared with 56% overall.
That gap is hard to close because non-human identities don’t fit neatly into controls built for people. API keys, service accounts, bots, and AI agents can operate continuously, carry broad or long-lived privileges, and lack clear ownership.
When an NHI is exposed or compromised, it can provide persistent, trusted access while remaining difficult to govern and remediate. Yet the paths that expose them are often familiar: phishing and malware remain common access paths, but in government they now expose far more than passwords.
Phishing and malware are exposing more than government passwords
Among government organizations that experienced an identity event, 47% traced credential or session exposure to phishing vs. 30% overall. Another 22% experienced session hijacking vs. 16% overall.
A phishing attack no longer has to capture a password to create risk. Modern phishing kits can collect session cookies, authentication tokens, and other artifacts that allow attackers to bypass traditional login protections and hijack authenticated sessions.
Malware creates similar exposure. Infostealers can extract credentials, cookies, and browser-stored tokens from infected devices, creating identity exposure that persists beyond the initial infection. In both cases, exposed session material can give attackers a path into an authenticated session even when passwords remain secure.
Session identity protection extends visibility beyond usernames and passwords to the session material attackers use to gain trusted access.
Broader visibility helps agencies stay ahead of recurring identity events
Most organizations can see traditional credential exposure. The difference now is whether teams can see the broader range of identity assets attackers can exploit. Across the full SpyCloud benchmark, event-free organizations monitored an average of 3.4 identity exposure types, compared with 2.8 among organizations that experienced an event.
The clearest gaps were in areas many programs still treat as secondary:
of event-free organizations monitored stolen session cookies, vs. 37% of organizations that experienced an event
monitored personal devices with corporate access, vs. 40% of organizations that experienced an event
For government agencies dealing with recurring identity exposure, broader visibility can help teams identify exposed assets sooner and remediate them proactively. But finding exposure only helps if teams can act on it, which is the next measure of maturity.
Government identity security is still building operational maturity
Seeing more exposure only helps if a program can respond consistently. More than half (51%) of government organizations fall into SpyCloud’s Building tier, where foundational identity security processes exist but response remains inconsistent, compared with 29% overall. Only 10% have reached the Optimized tier, characterized by continuous monitoring, automated remediation, and clear governance, compared with 22% overall.
The remediation data shows a similar maturity gap. Nearly a quarter (23%) of government organizations still work case by case with no repeatable process, nearly twice the 12% overall rate.
Government identity security maturity
government vs. 22% overall
government vs. 12% overall
See which identity exposures may be tied to your organization
Check your exposure to see what identity threats may already be tied to your organization’s domain.
Case-by-case response becomes harder to sustain as identity events recur because each exposure requires manual investigation and remediation. More mature programs build repeatable processes to prioritize exposures, remediate the access they create, and verify that the exposure has been resolved. That need extends beyond the agency’s own environment to the contractors and vendors that connect to it.
Third-party identities extend exposure beyond the agency
An agency can remediate its own exposures and still inherit identity risk from vendors, contractors, and suppliers that connect into government environments with their own credentials, devices, sessions, and API access.
Across the SpyCloud benchmark, 23% of government agencies named malware-infected third-party devices as the leading cause of supply-chain identity incidents, and 22% pointed to exposed API keys or application access tied to vendors or partners.
A vendor’s compromised session or leaked API key can create trusted access much like an internal exposure, but the agency may have less visibility into the compromise and less control over the response. That makes verifying remediation especially important. Rather than relying on notification alone, agencies can confirm that exposed credentials, sessions, tokens, devices, or privileges have actually been addressed.
Among federal government organizations, 52% validate vendor remediation rather than relying on vendor confirmation alone, a practice that extends identity security beyond the agency’s own environment.
Continuous vendor identity exposure monitoring
SpyCloud Supply Chain Threat Protection monitors vendor employee domains against recaptured breach records, infostealer logs, phishing captures, and combolists, surfacing active identity exposure across third-party ecosystems rather than relying on static vendor risk scores. The Supply Chain Threat Protection overview explains how that approach helps teams identify active identity risk across vendor ecosystems.
For agencies, visibility only reduces risk when remediation follows
Once an agency can see an exposure, how quickly and consistently can it close it?
Government teams are already prioritizing the answer: 46% plan to automate identity-related incident response over the next 12 to 18 months, compared with 35% overall, and 39% plan to improve malware visibility, compared with 29% overall. Yet across the benchmark, only 21% of organizations automate and optimize remediation across systems. For government agencies experiencing identity events at particularly high rates, repeatable remediation becomes increasingly important.
Closing an exposure means more than resetting a password. It means rotating compromised credentials, revoking exposed sessions and tokens, reducing unnecessary privileges, and confirming the fix held across human and non-human identities alike.
Automation makes that repeatable, turning each recurring class of exposure into a defined response rather than a fresh investigation. Reducing unnecessary privileges also limits the access an exposed identity can provide, particularly for service accounts, APIs, and AI agents with broad permissions.
- What identity asset was exposed, such as a credential, session token, API key, service account, AI agent, or third-party identity
- What access that asset provides across systems, data, applications, or vendor environments
- Whether the active access path has been removed through the right remediation action
- Whether unnecessary privileges have been reduced, especially for service accounts, APIs, and AI agents
- Whether remediation has been verified across internal systems and any affected vendors, contractors, or suppliers
Automated credential and session remediation
SpyCloud Identity Guardians integrates with Active Directory, Entra ID, and Okta Workforce to detect and remediate compromised credentials and stolen sessions, moving teams from manual case- handling to automated identity response.
The route to more resilient government identity security
Reducing identity risk requires visibility across the full identity ecosystem and the ability to act on what teams find. Government agencies should prioritize:
- Broader monitoring across human, non-human, and third-party identities
- Repeatable and automated remediation
- Verification that exposed credentials, sessions, tokens, devices, and privileges have actually been addressed
Together, these capabilities help teams move beyond case-by-case response to continuously identify, prioritize, and remediate the exposures that matter most. For government agencies, effective identity protection strategies increasingly depend on this kind of continuous visibility and proactive remediation across the identity ecosystem.
Go deeper on the identity threats facing public-sector teams
Read the full 2026 SpyCloud Identity Threat Report to explore benchmark data on identity events, AI and NHI governance, third-party exposure, visibility gaps, and remediation maturity.
FAQs
Identity threats in government are exposed or compromised identity assets that attackers can use to gain trusted access to government systems. These can include employee and contractor credentials, session cookies, refresh tokens, API keys, third-party identities, service accounts, AI agents, and other non-human identities.
Government organizations reported the highest identity-based event rate of any industry in SpyCloud’s 2026 study. 92% of government organizations experienced an identity-based event in the past year, compared with 68% of organizations overall.
AI agents, APIs, service accounts, bots, and other non-human identities often authenticate to internal systems and data. Many carry privileged access or connect into sensitive workflows, but they may not have the same ownership, governance, monitoring, and remediation processes applied to human users.
Government agencies can improve identity security by expanding visibility beyond employee credentials, monitoring both human and non-human identities, prioritizing exposures that give attackers trusted access, reducing unnecessary privileges, automating remediation where possible, and verifying that compromised internal and third-party identities have actually been addressed.
Vendors, contractors, and suppliers connect into government systems with their own credentials, devices, and access, any of which can be compromised outside the agency’s control while still providing a path to trusted access. Verifying that exposed credentials, sessions, tokens, devices, or privileges have been remediated helps government agencies reduce identity risk across their third-party ecosystems.