[weglot_switcher]
Camp SpyCloud logo with silhouettes of people climbing a hill at Black Hat USA 2026.

Identity Isn’t Going Anywhere: What We Saw at Black Hat USA 2026

Table of Contents

Check your exposure

Black Hat USA is one of the security industry’s largest annual conferences, bringing researchers, vendors, and practitioners to Las Vegas each summer to compare notes on what’s changed since last year and where the industry goes next. 

SpyCloud set up camp this year – literally. Camp SpyCloud brought a little wilderness to the show floor while we talked identity threat protection with everyone who stopped by.

SpyCloud booth at Black Hat USA 2026 cybersecurity conference.
Group photo of SpyCloud team at Black Hat USA 2026 conference.

Our “camp counselors” gearing up for a busy day of talking shop at the Camp SpyCloud booth.

Post- is having a moment

Walking the floor at Black Hat USA 2026, you could put “post-” in front of almost anything.

Post-SIEM. Post-SOAR. Post-DLP. Even Post-Mythos.

But one phrase you didn’t hear? Post-identity.

If anything, identity has expanded further into the security conversation. What counts as an identity, who owns it, and how organizations should protect it are becoming harder questions – especially as non-human identities (NHIs) and AI agents multiply across enterprise environments.

Everyone wants to own identity​

The growing attention on NHIs was impossible to miss. Acquisitions, new offerings, and expanded product categories all point to vendors trying to solve for service accounts, API keys, tokens, workload identities, and other machine-based access.

But there’s an interesting ownership debate underneath that activity.

Identity security teams have traditionally governed access. Yet NHIs are often born somewhere else entirely: Kubernetes clusters, CI/CD pipelines, cloud infrastructure, developer environments, and other workloads. Increasingly, the teams managing those workloads are asking a reasonable question: If we create and manage these identities, shouldn’t we own their security, too?

There isn’t a settled answer yet. What is clear is that the identity attack surface is no longer limited to employees logging into applications. Identity now extends across people, machines, applications, services, and, increasingly, autonomous agents.

Last year, agents were built. This year, they’re controlled.​

The AI conversation changed noticeably from Black Hat 2025.

Last year was dominated by how organizations could build agents and use AI to accelerate development, SecOps, and productivity. This year, the conversation moved downstream: How do we manage those agents? What can they access? How do we govern them? And perhaps most fundamentally, what exactly is the identity of an AI agent?

Security teams are still working from zero-to-one on many of those questions.

Zero trust hasn’t gone anywhere either. It’s expanding to cover agents and machine identities alongside human users. Attendees kept returning to one phrase to describe that expansion – AI trust.

Meanwhile, the familiar identity problems haven’t disappeared. Employees, contractors, vendors, and suppliers still create exposure that IAM, endpoint controls, and traditional threat intelligence don’t always reveal. Security teams need powerful signals that show not simply who should have access, but what exposed access is currently in the hands of criminals.

Attendees exploring cybersecurity booths at Black Hat USA 2026 conference.

Camp SpyCloud saw a steady rotation of new faces at the booth.

Amid the AI noise, customers wanted answers​

That distinction came through clearly in our conversations at the SpyCloud booth. Visitors weren’t looking for another generic AI story.

They came with concrete problems: 

For threat hunters and red teams, another priority was speed – getting from an alert about workforce exposure to useful context and action faster.

That’s where SpyCloud’s approach to identity threat protection stood apart.

This year, SpyCloud marked ten years of disrupting cybercrime and surpassed one trillion recaptured identity assets from the criminal underground. In a recent 30-day period, we recaptured 25 billion identity assets – nearly 10,000 every second. Nearly half of the assets in our collection are now stolen session cookies and tokens, illustrating how quickly criminal tradecraft is moving beyond passwords.

Our 2026 Identity Exposure Report also identified 18.1 million exposed API keys and tokens, and 6.2 million credentials or authentication cookies associated with AI tools.

The takeaway from Black Hat isn’t that every security problem has suddenly become an AI problem. It’s that identity keeps expanding – while criminals keep finding new ways to steal and exploit access.

As the industry figures out how to govern the next generation of identities, organizations still have to protect the ones being exploited today.

And for that, fresh, actionable data about what criminals actually possess remains one of the most powerful defenses we have. See what criminals already know about your organization.

Two men smiling at a cybersecurity event with badges and a banner.
Polaroid-worthy moments from Camp SpyCloud this year. See you next year!
SpyCloud booth at Black Hat USA 2026 cybersecurity conference.

Identity isn't going anywhere

See how SpyCloud detects exposed credentials, sessions, and machine identities before criminals use them.

Keep reading

SpyCloud logo with network lines and text 'Identity Guardians'.
How to Detect and Remediate Stolen Sessions Automatically with Your IdP + SpyCloud
SpyCloud Identity Guardians detect and revoke compromised sessions for Entra ID and Okta, stopping session hijacking where password resets fall short. Here’s how to remediate stolen sessions automatically with your IdP and SpyCloud.
Illustration of a research agent with network connections for cybersecurity.
Introducing Research Agent: Your Investigations Team Just Got An Unfair Advantage
SpyCloud’s Research Agent is an agentic investigation tool that plans pivots, correlates identities, and returns finished intelligence grounded in over one trillion recaptured criminal-source assets. Every finding cites a specific verifiable record.
SpyCloud and Okta integration alert for enhanced security monitoring.
SpyCloud + Okta Identity Threat Protection: Closing the Gap Between Identity Exposure and Attack
SpyCloud’s integration with Okta Identity Threat Protection (ITP) levels up your defenses with darknet identity intelligence that automatically remediates exposed identity data, including stolen sessions and tokens. See how it works.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.

X