Published 1 day ago • loading... • Updated 17 hours ago
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
The report says 31% of organizations name compromised non-human identities as the primary entry point, nearly twice the share for phishing and social engineering.
SpyCloud released the 2026 SpyCloud Identity Threat Report on September 9, identifying non-human identities—service accounts, API keys, and AI agents—as the leading path attackers take into the enterprise.
While Ninety-five percent of Organizations believe they have visibility into NHI-related exposures, only 36% monitor them; 91% of Organizations use tools with system access but lack formal governance for resulting privileges.
Compromised NHIs are nearly 2x as likely to be the primary entry point compared to Phishing , while NHI-related misuse remains the most commonly reported identity-based event type at 42%.
Further amplifying the problem, 68% of Organizations experienced an identity-based event, with those relying on manual remediation reporting higher incident response costs than Organizations using automation .
Organizations are prioritizing vendor risk management, with 32% planning investments for the next 12 to 18 months. "That asymmetry is what attackers are exploiting," said Trevor Hilligoss, SpyCloud Chief Intelligence Officer.