+
Fight AI-driven phishing and malware attacks
AI-powered phishing kits. Industrial-scale infostealer operations. The identity access theft economy isn’t evolving – it’s exploding.
SpyCloud recaptures stolen identity data straight from the criminal underground. Together with Ping Identity, we turn that intelligence into automatic action inside the workflows you already own.
Block. Reset. Escalate. The moment an exposed identity is detected.
Join SpyCloud CPO, Damon Fleury, and Ping Identity Senior Integrations Engineer, Tyler Gelinas, to learn how SpyCloud and Ping Identity enables your team to automatically block, reset, or escalate the moment a compromised identity is detected – across both PingOne Advanced Identity Cloud and PingOne DaVinci.
Okay, let's go ahead and get started. Hello and welcome to Fight AI Driven Phishing and Malware Attacks, brought to you by SpyCloud in partnership with Ping Identity. Before we get started, here's what we've got store today. We've got twenty five minutes of content with five minutes reserved at the end for your questions. Please feel free to drop your questions in the chat throughout the session, and where it makes sense, I'll ask them during the presentation. Otherwise, expect your questions to be answered at the very end. I'm excited to introduce our speakers. Please welcome SpyCloud Chief Product Officer, Damon Flory, and Senior Lead Integrations Engineer from Ping Identity, Tyler Galinas. I'm your host, Katherine Allen, Senior Product Marketing Manager here at SpyCloud. And with that, I will hand it off to Damon. Thanks, Scott. Good morning, everyone. Thanks for taking the time to join us today. Today, we're gonna walk through what we see as the reality of the threat landscape and how we see data being collected by that are then that's then being used to attack enterprises. We're gonna talk about some of those attacks that we have seen in the wild, real stories that hopefully we can all learn a little bit from, and then really how that connects to the things that are being stolen, credentials and cookies that are being used in in all forms of account takeover attacks, traditional ones using credentials, but also some of the the current industry kind of leading attacks that we're seeing quite a bit being used. We're gonna then talk about how the integration of SpyCloud and Ping together can immediately protect you from the types of things that criminals have learned about your organization. And then we're gonna look at a specific example of a customer that's doing this today, and they're able to protect their their entire critical consumer application with this type of information directly connected to the Ping application. So let's start by talking about the data, the kind of information that we see that criminals are stealing that is being used to directly attack enterprises through their infrastructure or through their consumer facing application. These are numbers that were published in the twenty twenty six SpyCloud Identity Exposure Report. We saw almost sixty six billion distinct identity records in total that have been stolen throughout the years that are the the total number of records that we saw with a twenty three percent year over year growth. We saw five and a half billion credential pairs that were specifically collected in twenty twenty five, we see those numbers growing already past that level here in twenty twenty six. And then we saw almost nine billion, about eight and a half billion stolen sessions. This means a stolen session cookie or stolen authentication refresh token that can then be used by the actor to gain access to enterprise infrastructure or consumer facing web session that doesn't require credentials and doesn't require MFA. You can use that session to directly log in. This is the scale of information that we've seen, and and quite frankly, these numbers are actually growing really dramatically here in twenty twenty six. We see the exposure spreading out at machine speed. I know we always get the question of, well, how is AI changing the threat landscape? And what we've seen in the data that we've collected is that it's not making a direct change in the types of attacks, but it's making a change in the scale and the speed at which the actors are moving. And so we've seen the total number of unique infostellar infections at thirteen point two million. We actually see way more, but many of them are reinfections. So thirteen point two million infostellar infections. We see those infostellar infections exposing on average about fifty credential sets. And these are very damaging credential sets because they're not only the username and password, but they also include the login URL that those that username and password can be used on. That exposed more than six hundred and forty two million credentials last year, and again, bigger numbers this year. Then the phish records, we saw twenty eight and a half million phish records. About fifty percent of those, just under fifty percent of those, were tied to corporate victims. I think some folks think that phishing has a consumer focused crime. We definitely see the actors now targeting directly enterprise users and enterprise email addresses. And so we see the data that they've stolen directly after the point of the phish itself. And so those numbers are are very interesting and growing, unfortunately. And then we saw forty five hundred distinct to the data breaches. We think of these as third party breaches. Thirty nine of those had more than fifty million records, and a few of them had more than a billion records. So the total number of credential sets and identity records stolen just continues to scale. An interesting kind of side point here is that six point two million of those credentials are specifically able to access AI tools. These are this is another way that AI is kind of being impacted by the threat landscape is that they are stealing access to the AI tools themselves and then using them as free tokens and free capabilities that they're then using for malicious purposes. So let's look at a couple of incidents in real life, and these are more focused around phish events and specifically phish events that include not only credential theft, but access to an environment that came through stolen cookies as well. So in this first example, we have a northern European city government where a city leader fell prey to a phish attack, and that phish attack resulted in the exposure of that leader's credentials as well as the exposure of their access details, specifically their session cookies that were then able to be used by the actor to directly access city infrastructure such as this leader's email address and their general their general authentication environment. And so that lead led to a very broad immediate exposure for that organization for a person with an elevated level of privilege. That data, though, was detected by SpyCloud. At the same time that it was stolen from the individual, we were able to see that the credentials and the session were taken, and then that information was able to be routed back to that organization where they're able to take action directly to stop, not just reset the passwords, but reset the sessions and then proceed with the investigation of what was accessed by the actor. But because that time window, that time horizon was quite short, the the damage was really quite limited. In this second example, we wanna talk about a global energy company where one of their business leaders fell prey to a similar type of attack. In that case, the phish attack stole the credentials but also stole the session cookie and was also able to gain access to the email infrastructure of that enterprise. In this case, the organization had infrastructure and had the capability set up to respond to the password immediately. They immediately reset the password. But because they did not remediate the issue with stolen access, with stolen stolen session cookies, the criminal still had access to the environment even after the password was reset, and only one only once the enterprise understood that these attacks have shifted, these attacks are now stealing access beyond credentials, where they're able to understand and go reset all relevant sessions and then to oust the actor from that specific leader's account. So now we're going to talk a little bit about what kind of data can be collected and be seen in the dark net that you can immediately respond to if you have the right integration, if you have the right automation within your enterprise. So we like to understand that when you're looking at data for the dark net from the dark net, you really do wanna understand not just the information that can be connected to your enterprise. So when you're searching for data about an individual like myself, you could just search for, you know, my corporate email address, and you will learn the little bits of information that the dark net has about about me through my through the information in the dark net. But you need to go a little deeper than that. You need to understand the holistic identity, and that means that you need connectivity to understand what are the personal email addresses, what are some of the past work addresses, what are some other credentials that may be used by the actor that may be a pattern in my life that you can see if you look at some of these other email addresses, and that same credential set could be used by could be used by that user at work or in their consumer facing application. So getting a broad view of the holistic identity all from the data that criminals have collected about these identities is really important in understanding the full attack surface and and protecting your business from this type of information. And it's important to understand that credentials, passwords are not the main target anymore. We definitely credential theft is not going away, so I don't mean to imply that at all. There still is a lot of credential theft, and we are still seeing credentials being used to log in to environments. But we are seeing the next generation attack both in malware and in phishing be the theft of that session cookie or that authentication token, and there are many strategies to do so. You see stolen session stolen session data, just in pure quantity, has actually overtaken the number of passwords being stolen by malware and by phish. And so protecting against both of those is really important. We saw two billion new credent renew recaptured records that are phish credentials and our malware records. Those are a part of those as well as the sorry, the phish credentials and the phish sessions as well as the malware credentials and malware sessions just that are all being used to access your enterprise. And as we've just discussed, these next gen phishing kits are doing the same thing that malware infestalers have been doing and that they're targeting not only the credentials, they're targeting the sessions, the refresh tokens, and the information that can be used to bypass MFA or bypass passwordless solutions. So the key to actually stopping this is to understand that this type of attack has managed to steal information that's relevant to your business. Could be from an unmanaged device. It often is. It could be from something that has slipped through other controls, but the the information is out there. So you need to be able to get that information extremely quickly from the point that it is stolen from your employee or from your consumer, and then you need to tie it to Ping's leading orchestration and enforcement capabilities. And then with that, the closing that loop, you're able to immediately protect your business from the type of information that the criminals have and specific from the specific data elements that the criminals have. So this type of integration is really critical to have a fast turnaround and to protect your business in the near term and in the long term. So now let's take a closer look at what these integrations look like within your own infrastructure. European customer, you'll you'll be very familiar with the types of interfaces that Tyler's about to show you, and then he'll show you how it can very easily be tied into your SpyCloud subscription. So I'm excited to show off some integrations we have between Ping and SpyCloud to help prevent these attacks. So we have a couple of integrations. The first integration I want to discuss is the integration we have with our PingOne Advanced Identity Cloud platform. So this is a consumer focused integration. So the way the integration works is the integration is triggered by a user. So that's if they're trying to register or authenticate. We'll collect their username and password, then we'll we will query SpyCloud to determine if those credentials are compromised or not. And then from there, we can take action based off that result. So we can either do step up MFA, block the action, force a password reset. And if the password is not compromised, we will allow the action and the user capability can proceed as normal. So I'll show off this demo here with AIC. So the first demo I wanna show here is a registration journey. So what we're in here is we're in our advanced identity cloud platform. This is basically just a workflow that a user or a device can go through. So this workflow here is a collection of nodes that can do individual things such as collect usernames, collect passwords, and this one here is a registration journey. So what we've done here is we built a Spy Cloud node. So on the left hand side here, we can search for nodes, and we see now we have the Spy Cloud node built into the platform. So it's very easy to start using. You can just take the Spy Cloud node, drag into the journey, and start configuring your workflow. So once you drag the SpyCloud node in, there'll be a few configurations such as API URL, API key, and severity. These can be provided by SpyCloud. And then from there, you can start using the node. You can choose, like like, time out, configuration and, what you wanna use, either mail or username for the credential check. And then and what this journey will do is it will collect the username of the user, password, and some attributes such as mail, and then it'll validate those, query SpyCloud. If we determine that the if SpyCloud determines that the credential is compromised, we can take action based off that. This journey, we will ask for the user to enter a new password. If the if the credential is not compromised, then we will go ahead and create the user and complete registration. In this case, if the user is compromised, we'll come to the subjourney here to ask the user to create a new password, then we'll query SpyCloud again to make sure that new password is not compromised, and then we can continue on with the registration. If the second password they enter is still compromised, we we'll go ahead and deny the the registration attempt. So I'll go through here and show what this looks like to the end user. So here, we'll collect those attributes such as username, email, and password. And then after we enter in these credentials and click next, that's when we query SpyFab. In this case, I'm entering in an uncompromised password. So you can see here it goes in, logs in, and completes registration, so no friction to the user. So it's a very seamless user experience. We check SpyCloud for compromised credentials. SpyCloud determined that those credentials were good, so we continued on as normal. This case, I'll be showing the registration attempt with a different user who has a compromised credential that they are entering. So in this case, this password has been determined to be compromised by SpyCloud. So when we make the call to SpyCloud here, SpyCloud returns that it is compromised, and it will say password cannot be used. Choose a different password. Then we'll go into that sub journey here to enter the new password, do another check against SpyCloud to see if this new password is compromised or not, and, continue on to registration. So these journeys are very configurable. The important thing is that the SpyCloud determines if it's compromised or not compromised, and then you can set up your workflow however you want after that. Whether you wanna do a password reset and or a step up MFA, ask you to choose a new password, like in this case, or just outright deny the user. So now I wanna show another demo here. This one will be an authentication workflow. So this will be a user trying to sign in. So in this flow, we will collect, the mail attributes and a password. We'll validate that user exists in ping, and then we'll call it to the Spot Cloud node to determine if those credentials are compromised or not. If they are not compromised, we'll validate the password and log the user in. If they are compromised, then we will in this case, we're gonna lock the user out. So this just just shows different things we can do when it's compromised. The previous demo, we ask for a new password. This demo, we lock the user out. So it all depends on what the administrator wants to configure. So I'll go through this flow here to see, how it looks again. So in this case, we'll prompt the user for their mail attribute and password, and then we will call out to SpyCloud here. This one is a not compromised password, so let's go ahead and sign the user in, very easily. A very seamless user experience, which is very nice. So here, we'll enter in a, compromised password. And you can see here we get this account lockout message and deny low login. So this just shows different ways we can use the SpyCloud node in Ping AIC, Advanced Identity Cloud Journey. And we can see that it's just one node, so it's very easy to add into the workflow and start using. And if everything's good on the user account, there's no friction to the user at all. So it's very very, very nice integration to have. Awesome. So now again to our next demo here with another one of our products at Ping. So that is going to be with PingOne DaVinci. So this integration is workforce focused. So I'll go ahead and show what that looks like here. It works very similarly to the previous node. So it'll start by the flow being triggered, by a user, such as an employee, Then we'll collect that employee's username and password. We'll query Spy Cloud to determine if it's compromised or not, and then we will take action based off that blocking, forcing resets, stepping up step up MFA. And then if there's if it's not compromised, we'll allow the user to proceed as normal. So it works similarly to the previous integration. This is just in a different paying product and employee focused. Awesome. So now I'll get into a demo of what this looks like. So similar to Advanced Identity Cloud, DaVinci also has a similar concept to of orchestration. So in this case, instead of nodes, we have connectors, and instead of journeys, we have flows. So what we've done in DaVinci is we built a SpyCloud connector. So you'll come to your connectors here, search for the connector, and add the SpyCloud connector. We have a couple of capabilities such as checking credentials based on email or username. And then we go ahead, add this connector, and then we can start using it in a flow here. So if we come to a DaVinci flow, have a similar UI here where we where we have different connectors here that we could route based off of. So this here is a registration workflow. We'll start with a registration connected to collect the user attributes such as username, email, and password, and it'll we'll come to the spy cloud connector here. To add the connector, you come to this add connector u UI, add the spy cloud node, and they can start using it. We do have this one configuration here, which is the API key. So you'll just grab that API key that SpyCloud provides and enter it in here and choose your capability, and then you'll select your attributes you want passed in to SpyCloud. In this case, it'll be the email and password from the previous registration form. So here in this flow, we'll collect the these are the attributes we're collecting, the username, password, and email. And then after we make the call to SpyCloud, if we determine that the credential is compromised, then we'll just display an error to the user. If we determine that the pass that the credentials are not compromised, then we will go to the registration flow to complete registration as normal. So similar to Advanced Identity Cloud, DaVinci is very customizable. We can do passer resets, step up MFA, deny account lockouts. Just depends on on the exact use case and and flow that we're trying to implement. So but this Slack Cloud enterprise connector is available within the platform. So anyone who has DaVinci can go ahead and start adding a Slack Cloud node into their journeys, into their existing existing flows, new flows, and start using it. Awesome. So now I'll go through a flow here to show what that looks like. So this first attempt here, we will enter in a compromise credential. So this will be a credential that SpyCloud recognizes as compromised, and we should see that that error message that the user is denied registration. Awesome. So now we'll we'll do that flow again, I will enter in a credential that is not compromised, and then we should see that the user can continue on to registration. And we see here that the registration is successful and the account has been created. So that's how it looks for DaVinci. Very similar to to Advanced Identity Cloud. If things are successful, there's no friction to the user. And if the credentials are compromised, then we take additional action based off what the administrator configures. Awesome. So this is some new upgrades we're looking to make to the integrations. So we what I showed here was our DaVinci connector and our PingOne IAM and AIC node. So we're also going to be adding some integrations into PingFed as well. Now we're gonna add some additional features such as checking the session cookie and their and refresh token and taking recommended actions based off of infected devices such as having a terminate session directly in the node itself just to make it easier to to configure in the in the journey or flow. Awesome. So I think those were oh, so now I hand it back over to Damon to discuss some customer stories. Thanks, Tyler. It was a great demonstration of both the consumer and enterprise applications despite cloud data directly within the Ping environment. It's awesome to see how easy it is to integrate that data into your existing login flow as well as your your change password mechanism as well. And so let's look at a specific customer of Ping and SpyCloud. It's a Fortune five hundred global retailer with more than two thousand retail locations with millions of dollars in transactions happening daily through this ecommerce site. And so this this organization was able to very quickly leverage their deployment of Ping to add SpyCloud directly into their login workflow and gain immediate protection on every single login to make sure that the credentials being used are not credentials that are available on the dark net and that their customers are protected from that kind of ATO. It's fully automated, and it didn't did not require any code to be written by the customer. It was all able to be implemented directly within the authentication flow or the journey that that Tyler just demonstrated for you. So they were able to handle the exposed credential, deliver the automated response immediately, and the result is protected accounts and much reduced account takeover and much reduced loss to their application. So at the end of the day, this is built for the next generation of identity attacks. It's protecting against credential theft, but it's protecting against session and and refresh token, as Tyler mentioned, coming in the next version of this integration. The combination of SpyCloud's exposure intelligence with Ping Identity's orchestration and enforcement capabilities gives you the industry's best solution for automated and proactive protection. So together, you can very quickly roll out a solution that can protect your consumer application or protect your enterprise. Awesome. Thank you so much, Damon and Tyler, for such a great session. Great news as a limited time exclusive offer. We are offering a fourteen day free trial of Ping1, DaVinci, and SpyCloud. If you're running Ping already, you have the platform in place to do exactly what we showed you. If not, you can also try Ping1 DaVinci for free. As I mentioned, you can start a fourteen day free trial of Spy Cloud data inside of Ping1 DaVinci. Quick note, this is not self-service. So for security reasons, our team is going to enable the data on your behalf. So there will be a quick white glove guided setup rather than a flip of a switch. But it does move really fast once we're able to connect. So go ahead and head over to that landing page that's located on the screen. I will also drop the link in chat for those who are interested. Again, thank you so much, Damon and Tyler. It was such a great session. And now let's move into the Q and A portion. Please drop your questions in the chat if you haven't done so already. Let me go ahead and pull those up. Let me drop in the chat the free trial link. There we go. Yeah. I see someone's Sorry. Go ahead, Tyler. So I was gonna say I see someone someone asked if the message was customizable for the when we ask for a different password. And, yes, that that message is customizable, so you can customize the UI and the message however you would like to to display to the user. Awesome. Thank you so much. Okay. First question, is the integration available with Twilio as well? I don't know if Ping directly has an integration with Twilio, but SpyCloud, at this moment, does not yet have an integration with Twilio. We're happy to talk about that further if that's of interest. Tyler, if you wanna cover that from a Ping perspective. Yeah. From the Ping side, we have an integration with Twilio for their, like, OTP OTP codes. So, that is one integration we have with with Twilio, from the Ping side. So then in that case, that integration could leverage the SpyCloud data to then trigger the OTP integration with Twilio? Yeah. Yeah. Exactly. So in that journey, for the compromise, you can go from the compromise path in the SpyCloud node route that to a Twilio node. We have a Twilio node that the user can route to. So so yeah. And they can they can route those together pretty pretty easily in a in a journey. K. Excellent. The next question, think, is probably for you, Tyler. When would you reset the password via push MFA, or when would you reset the password versus a push MFA step up? Or or would you do both? Yeah. I think that's that's up to the administrator, what they wanna do. But, yeah, doing both doing doing it either way is possible. They can do both in the journey. They can do one or the other. So so the journeys are very customizable, so it just depends. Yeah. Probably recommend doing doing both, though, if they want to, but we we leave that to the the administrator. Yeah. The majority of our customers do SpyCloud customers end up doing both when you get a match on that credential set. Let's see. Is there a benefit that we can get from SpyCloud for AWS and Google? There certainly is. It's not directly tied to this Ping integration, but certainly there are ways to protect against your AWS it's credential theft or sessions for your AWS or Google environment. Be happy to talk about that further in a direct conversation. How would you test this integration with test accounts or service accounts before going to production? My thoughts on that, Tom? Yes. So when you're doing your development in DaVinci or or AIC, we have the those test flows options. So so you can test your flow beforehand, and you can you can go ahead and do some tests with with some test accounts in there if you would like. They can see the result from the spy cloud if it's compromised, not compromised. Yeah. So that that that's that's one way one way you could do it. Yeah. Excellent. And then on the data, how long does it take for SpyCloud to recapture exposed credential data when they're found or discovered? It depends on the type of data, but in the case of malware infections and phish events, typically within minutes of the discovery, we're able to pull it down, process it, deliver it through our ecosystem to the integration from Ping so that he can take so that Ping can take immediate action on it. It can be from an hour. It can be up to an hour depending on the specific ecosystem that we've gotten it from. And then there's sometimes delays in, you know, from the point of infection to how long before it's published on the dark net. But as soon as it's available, we gather it and put it immediately through. And then, Kathy, always, their question for these sessions is can I get the recording? Yes, absolutely. So thank you everybody for joining today's session. Everyone will get an email in the next twenty four to forty eight hours with a link to this recording. So you can rewatch it and check out those demos again. And we will also send out that link to the free trial if you would like to raise your hand and try Ping1 DaVinci with SpyCloud data in it. Thank you everyone so much for attending. Have a wonderful day.
- In this session
What you’ll learn
The new threat reality
The invisible attack path
The integration that changes everything
SpyCloud identity data embedded directly into PingOne DaVinci and PingOne Advanced Identity Cloud – automated protection for workforce and consumer identities.
Proof it works
- OUR SPEAKERS
Damon Fleury
Chief Product Officer, SpyCloud
Tyler Gelinas
Senior Integrations Engineer, Ping Identity
Cat Allen
Senior Product Marketing Manager, SpyCloud
Your fastest path to identity threat protection is already in your stack.
This is how you activate it.