
AUSTIN, Tex., Sept. 9, 2026, CyberNewswire – SpyCloud, the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report, a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems – have become the most common route attackers take into the enterprise.
The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer. NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organizations aren’t watching for them. While 95% of organizations believe they have adequate visibility into AI- and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report. Further amplifying the problem, 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events each.
Organizations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day. These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn’t get off-boarded, doesn’t rotate its own credentials, and doesn’t fail an MFA challenge, so once one is exposed it can stay usable for months.


