Key takeaways from the 2026 Identity Threat Report
-
Identity-based attacks are now routine:
More than two-thirds (68%) of organizations experienced an identity-based event in the past year, averaging eight incidents among those affected. -
Non-human identities have become a primary attack path:
NHI misuse was the most common identity-based event (42%), while 31% identified NHIs as their most common initial access vector. -
AI adoption is outpacing governance:
Nearly every organization (91%) uses AI tools or agents with internal access, but only 56% have formal governance for AI- and NHI-related privileges. -
Visibility drives resilience:
Organizations with no identity-based events monitor more identity exposure types (3.4 vs. 2.8), reinforcing that broader visibility leads to better outcomes. -
Remediation maturity remains a major gap:
Only 21% of organizations automate and optimize remediation across systems, meaning that visibility alone is not enough to reduce identity risk.
Identity threats have moved beyond the identities most teams were built to manage
The identity attack surface has expanded well beyond employee credentials. That’s made clear by the 65.7 billion unique identity records SpyCloud has recaptured from the criminal underground, which include:
Those exposures show how much identity risk now lives outside traditional username-and-password controls. As organizations adopt AI, automate more workflows, and rely on APIs, service accounts, and third-party connections, they’re creating more surface area for attackers to exploit.
Against this backdrop, the annual SpyCloud Identity Threat Report, based on survey responses from 750 cybersecurity leaders and practitioners within enterprise organizations, found that 68% experienced an identity-based event in the past year, averaging eight incidents among those affected. With identity-based events this widespread and recurring, the priority now is finding and remediating exposed identity assets, from credentials and session cookies to API keys and tokens, before attackers can exploit them.
Beyond measuring the current state of identity security, SpyCloud’s findings show what that resilience looks like in practice, including the visibility, monitoring, governance, automation, and remediation capabilities that distinguish more mature security programs. The findings give security leaders a benchmark for evaluating their own programs and identifying where they need to improve.
The 2026 Identity Threat Map
Industries with highest event rates
Regional event rates
Non-human identities are now the leading initial access path
The identity environment is expanding fastest where many organizations have the least operational control. Non-human identities (NHIs) like AI agents, APIs, service accounts, and bots increasingly hold access to internal systems and data, often without the same ownership, monitoring, or remediation workflows applied to human users.
Expanding attack terrain
- 91% say they use AI tools or agents with internal access
- 56% have formal policies and clear ownership for AI- and other NHI-related privileges
- 41% rely on informal processes or partial ownership
AI- and NHI-related exposure is the least-monitored identity risk
Although 95% believe they have adequate visibility into NHI exposures tied to AI tools, agents, applications, service accounts, and bots, only 36% actively monitor them. The consequences for this misalignment are already visible:
- 42% reported NHI-related misuse
- 50% cited exposed, compromised, or overprivileged NHIs as a common access path
- 31% identified NHIs as their single most common initial access vector
NHIs operate quickly by design, which makes rapid detection and remediation especially important when they’re compromised. The same speed and automation that make NHIs valuable to the business can give attackers an opportunity to act quickly once they gain access.
Phishing and malware still create the main access routes
Despite the identity landscape continuing to evolve, attackers still rely on familiar routes to gain an initial foothold. Phishing and malware remain the foundation of many identity-based attacks, granting access to credentials, session cookies, refresh tokens, API keys, and other identity assets attackers can use to move through an environment undetected.
Persistent access paths
- 37% cite phishing and social engineering as a common access path for identity-based attacks
- 40% report incomplete visibility into successful phishing events
- 53% have visibility into malware exposures on managed devices, leaving many organizations without a complete view of compromised identities
Attackers use these familiar techniques, but what they can gain from them has changed. Today’s phishing campaigns and infostealer malware can expose session cookies, tokens, API keys, and other identity assets that allow attackers to bypass authentication controls, hijack active sessions, and enter systems with access that already appears trusted. Instead of having to break through the front door, attackers can increasingly steal the access needed to walk right in.
Explore your identity exposure landscape
Stolen credentials are only part of today’s identity risk. Compromised session cookies, tokens, API keys, and non-human identities can all create opportunities for attackers to gain trusted access.
Check your organization’s identity exposure and see what attackers may already have.
Visibility is improving, but the terrain is still difficult to navigate
Most organizations have visibility into traditional credential exposures. The bigger challenge is extending that visibility across a growing range of identity assets and knowing whether that visibility is actually enough.
Organizations experiencing no identity-based events monitored an average of 3.4 identity exposure types, compared to 2.8 among those that experienced attacks. The biggest differences weren’t in traditional credentials, where monitoring is now common, but in newer identity assets such as session cookies and personal devices with corporate access.
Organizations that avoided an identity-based event in the past year were 35% more likely to have visibility into stolen session cookies than those that suffered incidents (50% vs. 37%).
Organizations that remained security event-free were 30% more likely to monitor personal devices with corporate access than organizations that experienced events (52% vs. 40%).
Confidence doesn’t equal coverage
Broader visibility also requires knowing where gaps remain. Organizations in the United Kingdom reported both the highest confidence in identity visibility (53%) and the highest identity-based event rate (77%), proving that confidence in visibility doesn’t necessarily translate into fewer events.
In addition, visibility is only part of the equation. While identity threats arrive continuously, only 21% of organizations have automated and optimized remediation workflows across systems, leaving most dependent on slower, manual response processes. More resilient identity security requires both broader visibility into emerging exposures and the ability to act on what teams find quickly.
How does your organization’s identity security program compare?
The SpyCloud Identity Threat Protection Maturity Assessment helps security teams benchmark their program across five critical areas:
In just a few minutes, you’ll receive a personalized maturity rating, see where your program stands relative to your peers, and identify next steps for strengthening your identity security posture.
The most resilient organizations follow a different path
While identity-based threats affect organizations of every size and industry, the survey shows that the most resilient identity security programs operate differently. It comes down to operational maturity. Rather than relying on individual tools or point solutions, these organizations have built repeatable processes for identifying, governing, prioritizing, and remediating identity exposures before attackers can exploit them.
The route to resilience
- Continuously monitor identity exposures beyond just credentials, including session cookies, malware, phished data, and NHIs.
- Establish clear ownership and governance for AI agents, service accounts, APIs, and other NHIs.
- Prioritize high-risk exposures from malware infections or successful phishes and automate remediation wherever possible.
- Verify that compromised identities have been remediated rather than assuming risks have been addressed.
Explore the full identity threat landscape
See how your organization's identity security practices compare with 750 cybersecurity leaders and practitioners across North America and Europe. The 2026 SpyCloud Identity Threat Report includes detailed benchmarks, industry and regional findings, and a maturity framework that shows how identity security programs evolve – from foundational capabilities to the operational practices that distinguish the most resilient organizations.
FAQs
Non-human identities (NHIs) include AI agents, APIs, service accounts, bots, machine identities, and other automated accounts that authenticate to systems and data. As organizations accelerate AI adoption and automation, these identities often receive privileged access but don’t always receive the same governance, monitoring, or remediation as human users. That makes them an increasingly attractive target for attackers seeking persistent, trusted access to enterprise environments.
AI agents expand the identity attack surface by introducing new privileged identities that interact with internal applications, APIs, and sensitive data. The challenge isn’t AI itself – it’s ensuring the identities that power AI are properly governed, continuously monitored, and quickly remediated if they’re exposed or compromised. Organizations that treat AI identities as part of their broader identity security program are better positioned to reduce risk.
The survey suggests many organizations have strengthened traditional identity defenses but continue to face growing exposure from session cookies, API keys, tokens, AI agents, third-party identities, and other identity assets. Security investments are most effective when they extend beyond prevention to include continuous visibility, rapid remediation, and governance across the full identity ecosystem.
The most mature organizations don’t rely on point solutions alone. They continuously monitor a broader range of identity exposures, establish formal governance for both human and non-human identities, prioritize high-risk exposures, automate remediation where possible, and verify that compromised identities and third-party exposures have been remediated. These operational practices consistently distinguish organizations experiencing fewer identity-based events.
Improving visibility starts with looking beyond employee credentials. Organizations should continuously monitor identity assets such as session cookies, API keys, access tokens, malware-related exposures, personal devices, and non-human identities. Broader visibility allows security teams to identify exposed identities earlier, prioritize the highest-risk exposures, and reduce the time attackers have to exploit them.
The SpyCloud Identity Threat Protection Maturity Assessment helps organizations evaluate how effectively they manage identity risk across five operational areas: visibility, monitoring, governance, automation, and remediation. By comparing current practices against the behaviors of more mature identity security programs, security leaders can identify strengths, uncover gaps, and prioritize the operational improvements that have the greatest impact on reducing identity-based risk.