[weglot_switcher]
SpyCloud report on identity threat trends for 2026 with security insights.

The Identity Security Challenges Most Organizations Aren’t Prepared For

Table of Contents

Check your exposure

Key takeaways from the 2026 Identity Threat Report

Identity threats have moved beyond the identities most teams were built to manage

The identity attack surface has expanded well beyond employee credentials. That’s made clear by the 65.7 billion unique identity records SpyCloud has recaptured from the criminal underground, which include:

8.6 BILLION
stolen session cookies
18.1 Million
exposed API keys and tokens
6.2 Million
authentication cookies and credentials for AI tools

Those exposures show how much identity risk now lives outside traditional username-and-password controls. As organizations adopt AI, automate more workflows, and rely on APIs, service accounts, and third-party connections, they’re creating more surface area for attackers to exploit.

Against this backdrop, the annual SpyCloud Identity Threat Report, based on survey responses from 750 cybersecurity leaders and practitioners within enterprise organizations, found that 68% experienced an identity-based event in the past year, averaging eight incidents among those affected. With identity-based events this widespread and recurring, the priority now is finding and remediating exposed identity assets, from credentials and session cookies to API keys and tokens, before attackers can exploit them.

Beyond measuring the current state of identity security, SpyCloud’s findings show what that resilience looks like in practice, including the visibility, monitoring, governance, automation, and remediation capabilities that distinguish more mature security programs. The findings give security leaders a benchmark for evaluating their own programs and identifying where they need to improve.

The 2026 Identity Threat Map

68% of surveyed organizations experienced an identity-based event in the past year

Industries with highest event rates

92%
Government
81%
Education
78%
Financial Services / Banking
77%
Healthcare

Regional event rates

77%
United Kingdom
68%
North America
63%
Select European Markets

Non-human identities are now the leading initial access path

The identity environment is expanding fastest where many organizations have the least operational control. Non-human identities (NHIs) like AI agents, APIs, service accounts, and bots increasingly hold access to internal systems and data, often without the same ownership, monitoring, or remediation workflows applied to human users.

Expanding attack terrain

AI- and NHI-related exposure is the least-monitored identity risk

Although 95% believe they have adequate visibility into NHI exposures tied to AI tools, agents, applications, service accounts, and bots, only 36% actively monitor them. The consequences for this misalignment are already visible:

NHIs operate quickly by design, which makes rapid detection and remediation especially important when they’re compromised. The same speed and automation that make NHIs valuable to the business can give attackers an opportunity to act quickly once they gain access.

Phishing and malware still create the main access routes

Despite the identity landscape continuing to evolve, attackers still rely on familiar routes to gain an initial foothold. Phishing and malware remain the foundation of many identity-based attacks, granting access to credentials, session cookies, refresh tokens, API keys, and other identity assets attackers can use to move through an environment undetected.

Persistent access paths

Attackers use these familiar techniques, but what they can gain from them has changed. Today’s phishing campaigns and infostealer malware can expose session cookies, tokens, API keys, and other identity assets that allow attackers to bypass authentication controls, hijack active sessions, and enter systems with access that already appears trusted. Instead of having to break through the front door, attackers can increasingly steal the access needed to walk right in.

Explore your identity exposure landscape

Stolen credentials are only part of today’s identity risk. Compromised session cookies, tokens, API keys, and non-human identities can all create opportunities for attackers to gain trusted access.

Check your organization’s identity exposure and see what attackers may already have.

Visibility is improving, but the terrain is still difficult to navigate

Most organizations have visibility into traditional credential exposures. The bigger challenge is extending that visibility across a growing range of identity assets and knowing whether that visibility is actually enough.

Organizations experiencing no identity-based events monitored an average of 3.4 identity exposure types, compared to 2.8 among those that experienced attacks. The biggest differences weren’t in traditional credentials, where monitoring is now common, but in newer identity assets such as session cookies and personal devices with corporate access.

Stolen session cookies

Organizations that avoided an identity-based event in the past year were 35% more likely to have visibility into stolen session cookies than those that suffered incidents (50% vs. 37%).

Personal devices

Organizations that remained security event-free were 30% more likely to monitor personal devices with corporate access than organizations that experienced events (52% vs. 40%).

Confidence doesn’t equal coverage

Broader visibility also requires knowing where gaps remain. Organizations in the United Kingdom reported both the highest confidence in identity visibility (53%) and the highest identity-based event rate (77%), proving that confidence in visibility doesn’t necessarily translate into fewer events.

In addition, visibility is only part of the equation. While identity threats arrive continuously, only 21% of organizations have automated and optimized remediation workflows across systems, leaving most dependent on slower, manual response processes. More resilient identity security requires both broader visibility into emerging exposures and the ability to act on what teams find quickly.

Measure your maturity in identity security and map your path to improvement

How does your organization’s identity security program compare?

The SpyCloud Identity Threat Protection Maturity Assessment helps security teams benchmark their program across five critical areas:

Visibility
Monitoring
Governance
Automation
Remediation

In just a few minutes, you’ll receive a personalized maturity rating, see where your program stands relative to your peers, and identify next steps for strengthening your identity security posture.

The most resilient organizations follow a different path

While identity-based threats affect organizations of every size and industry, the survey shows that the most resilient identity security programs operate differently. It comes down to operational maturity. Rather than relying on individual tools or point solutions, these organizations have built repeatable processes for identifying, governing, prioritizing, and remediating identity exposures before attackers can exploit them.

The route to resilience

The organizations best positioned to reduce risk won’t be those trying to eliminate every exposure, but those that can detect, prioritize, and remediate identity threats faster than attackers can exploit them.
Explore the full identity threat landscape

See how your organization's identity security practices compare with 750 cybersecurity leaders and practitioners across North America and Europe. The 2026 SpyCloud Identity Threat Report includes detailed benchmarks, industry and regional findings, and a maturity framework that shows how identity security programs evolve – from foundational capabilities to the operational practices that distinguish the most resilient organizations.

FAQs

Non-human identities (NHIs) include AI agents, APIs, service accounts, bots, machine identities, and other automated accounts that authenticate to systems and data. As organizations accelerate AI adoption and automation, these identities often receive privileged access but don’t always receive the same governance, monitoring, or remediation as human users. That makes them an increasingly attractive target for attackers seeking persistent, trusted access to enterprise environments.

AI agents expand the identity attack surface by introducing new privileged identities that interact with internal applications, APIs, and sensitive data. The challenge isn’t AI itself it’s ensuring the identities that power AI are properly governed, continuously monitored, and quickly remediated if they’re exposed or compromised. Organizations that treat AI identities as part of their broader identity security program are better positioned to reduce risk.

The survey suggests many organizations have strengthened traditional identity defenses but continue to face growing exposure from session cookies, API keys, tokens, AI agents, third-party identities, and other identity assets. Security investments are most effective when they extend beyond prevention to include continuous visibility, rapid remediation, and governance across the full identity ecosystem.

The most mature organizations don’t rely on point solutions alone. They continuously monitor a broader range of identity exposures, establish formal governance for both human and non-human identities, prioritize high-risk exposures, automate remediation where possible, and verify that compromised identities and third-party exposures have been remediated. These operational practices consistently distinguish organizations experiencing fewer identity-based events.

Improving visibility starts with looking beyond employee credentials. Organizations should continuously monitor identity assets such as session cookies, API keys, access tokens, malware-related exposures, personal devices, and non-human identities. Broader visibility allows security teams to identify exposed identities earlier, prioritize the highest-risk exposures, and reduce the time attackers have to exploit them.

The SpyCloud Identity Threat Protection Maturity Assessment helps organizations evaluate how effectively they manage identity risk across five operational areas: visibility, monitoring, governance, automation, and remediation. By comparing current practices against the behaviors of more mature identity security programs, security leaders can identify strengths, uncover gaps, and prioritize the operational improvements that have the greatest impact on reducing identity-based risk.

Keep reading

SpyCloud report on most active phishing kits in 2026 for cybersecurity.
The Most Active Phishing-as-a-Service Kits of 2026
Phishing-as-a-service kits like Tycoon 2FA and Kali365 now steal live sessions and OAuth tokens instead of passwords, letting attackers bypass MFA entirely – here's a breakdown of 2026's most active kits and how to stop them.
FBI Internet Crime Report 2025 with digital globe and cybersecurity theme.
FBI IC3 Report: Losses Hit $20.9 Billion Due to ATO, Phishing, Fraud
The FBI's 26th annual Internet Crime Report documents record-breaking cybercrime losses, but the numbers only tell part of the story. SpyCloud's security research team unpacks the biggest findings across phishing, account takeover, BEC, ransomware, and the first-ever AI crime category, and connects the data to the identity exposures that made these attacks possible.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.

NEW RESEARCH: Over 2/3 of orgs had an identity event last year – NHIs were the top cause. Read on

X