SPYCLOUD has released its 2026 Identity Threat Report, which finds that non-human identities (NHIs) — including AI agents, service accounts, API keys and authentication tokens — are now the leading route into the modern enterprise.
In the survey of 750 cybersecurity leaders and practitioners at organisations with 500+ employees across North America, the United Kingdom and select European markets, compromised NHIs were identified as the primary entry point in 31% of cases, nearly double the 17% attributed to phishing and social engineering.
NHI-related misuse was also the most commonly reported identity-based event type, at 42%, while 95% of organisations believed they had visibility into AI- and NHI-related exposures, only 36% actually monitor them. Attacks via NHIs are coupled with a broader exposure problem: 68% of organisations experienced an identity-based event in the period studied, with affected entities averaging eight events each.
The report highlights that organisations typically maintain thorough human-identity inventories but lack equivalent visibility for NHIs such as service accounts and API keys, which are often provisioned for convenience and can hold real privileges.
The resulting asymmetry is underlined by SpyCloud’s chief intelligence officer, Trevor Hilligoss, who describes NHIs as “a standing invitation that renews itself until someone notices.” Additional findings indicate AI adoption is widespread (91%) but governance is lagging (56%), creating shadow access.
The study also notes that continuous identity monitoring paired with automated remediation correlates with lower incident impact, and SpyCloud introduces an Identity Threat Protection Maturity Model to benchmark progress from Reactive to Optimised.