Ask most CISOs how they secure their workforce and you will get a confident, detailed answer: phishing-resistant MFA, single sign-on, conditional access, regular access reviews. Ask the same CISOs how they secure their service accounts, API keys and AI agents, and the confidence usually drops. It should. A new survey-based report from SpyCloud puts a number on the gap, and the number should worry every security leader who thinks zero trust is a project they already finished.
The SpyCloud 2026 Identity Threat Report, based on a survey of 750 cybersecurity leaders and practitioners across North America, the UK and Europe, found that compromised non-human identities, meaning AI agents, service accounts, API keys and authentication tokens, are now nearly twice as likely to be an organization’s primary entry point as phishing and social engineering: 31% versus 17%. Ninety-five percent of respondents believe they have adequate visibility into these identities. Only 36% actually monitor them.
The obvious objection
SpyCloud sells identity threat protection, so a report from SpyCloud concluding that identity is the problem invites an easy dismissal: of course they would say that. But the specific claim worth scrutinizing here is not “identity matters,” which no vendor needed a survey to establish. It is the shape of the gap: a 59-point spread between organizations that believe they have visibility and organizations that actually monitor what they are watching. That spread is not a sales pitch. It is a description of how security programs allocate attention, and it matches a pattern any CISO can verify against their own environment without buying anything.
An old game, a new board
Non-human identities did not become the leading entry point by accident. They became it because every other door got harder to open. “Every control that works pushes attackers toward what it doesn’t cover,” said Trevor Hilligoss, SpyCloud’s chief intelligence officer. “We hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections.” That is not a new insight about attacker behavior in the abstract. What is new is how far behind identity governance has fallen on the specific category attackers have now rotated toward. Human accounts get onboarded and offboarded through a defined process. Service accounts, API keys and increasingly AI agents get provisioned for convenience, granted real privilege, and then left alone, because in most organizations nobody owns them the way a manager owns a departing employee’s access.
Hilligoss frames the consequence bluntly: “That asymmetry is what attackers are exploiting. Every one of these identities is a standing invitation that renews itself until someone notices.” The report’s own numbers back the description. Sixty-eight percent of organizations experienced an identity-based event in the survey period, and non-human-identity misuse was the single most commonly reported type, at 42%, ahead of phishing-related compromise. Nearly all organizations, 91%, say they use AI tools or agents with access to internal systems, but only 56% have formal governance over the privileges those agents hold. This publication has previously argued that AI agents are fundamentally an identity problem that most enterprises are not treating as one. SpyCloud’s numbers suggest that argument was not an outlier concern but a measurable, majority condition.
What CISOs are actually getting wrong
The failure is not a lack of tooling. It is a category error. Zero trust programs were built to answer “is this human who they claim to be, on every request.” That question does not translate cleanly to a service account authenticating with a static key it has held for two years, or an AI agent that was granted broad read access to a data store during a proof of concept and never revisited. This publication has also warned that treating an AI system’s sandbox as a safety boundary is a mistake, and the same instinct is at work here: teams assume that because an identity is machine-controlled rather than human-controlled, it is somehow lower-risk by default. The report’s data says the opposite. Machine identities carry real privilege, rarely get rotated, and are the least-watched category of risk the survey measured.
There is a second finding worth a security leader’s attention: organizations with visibility into stolen session cookies experienced identity-based events at a meaningfully lower rate, 37%, than those without that visibility, 50%. Session data, not just credentials, is now what attackers are after, because a live session lets them skip authentication entirely rather than defeat it. A non-human identity program that only rotates API keys and ignores session-token exposure is solving last year’s version of this problem.
What it means for the security leader
Extend the same lifecycle discipline given to human accounts to every service account, API key and AI agent credential in the environment: an owner, an expiration, a rotation schedule, and an offboarding trigger. Inventory non-human identities with the same rigor as the employee directory, because 95% of organizations already believe they have done this and only 36% have. And add stolen-session monitoring to that inventory, not just credential exposure, since the report’s own data shows that gap correlates directly with how often organizations get breached through it.
None of this requires waiting for a better AI-governance framework to arrive. It requires treating the machine identities already running in production with the same suspicion security teams learned, over two decades, to apply to human ones.
Source: SpyCloud
