Identity threat protection firm SpyCloud has released its annual Identity Threat Report, a survey of 750 cybersecurity leaders and practitioners at organizations with 500 or more employees across North America, the UK, and several European markets. The headline finding is that non-human identities, meaning AI agents, service accounts, API keys, and authentication tokens, have overtaken phishing and social engineering as the single most common way attackers get into an enterprise. Compromised NHIs accounted for 31% of intrusions in the survey, nearly double the 17% attributed to social engineering, which had long been treated as the default entry point security teams plan around.

The report frames this shift as a structural asymmetry rather than a one-off statistic. Organizations typically maintain a reasonably clear inventory of their human workforce, tracking who joined, who left, and rotating their credentials on some schedule, but few extend that same discipline to the service accounts, API keys, and AI agents authenticating into their systems every single day. These machine identities are usually provisioned for convenience and often carry real privilege, yet in most environments nobody clearly owns them: a service account doesn’t get formally offboarded when a project ends, doesn’t rotate its own credentials on a schedule, and doesn’t fail an MFA challenge the way a human login would. Once such an identity is exposed, it can remain usable for months without anyone noticing, which SpyCloud’s Chief Intelligence Officer Trevor Hilligoss described as each one functioning as a standing invitation that renews itself until someone finally notices.

The scale of the visibility gap is the report's most concrete finding. Ninety-five percent of surveyed organizations believe they have adequate visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them in practice, making non-human identities the single least-watched category of identity risk the study examined. This gap has real consequences: 68% of organizations experienced at least one identity-based security event during the reporting period, and those affected averaged eight separate events each, with NHI-related misuse the most commonly reported event type at 42%. The report also ties this directly to how fast AI adoption has outpaced governance, finding that 91% of organizations now use AI tools or agents with access to internal systems or data, but only 56% have formal governance and clear ownership over the privileges those agents carry, leaving the rest operating on informal processes or partial ownership that the report calls shadow access.

Beyond the headline numbers, the report surfaces a pattern worth flagging for security leadership specifically: every control that closes one door pushes attackers toward whatever door it doesn't cover. As organizations hardened passwords, attackers moved to stealing authenticated session cookies and tokens, which let them resume an already-logged-in session and bypass MFA entirely; session-related exposure now tracks with meaningfully different incident rates, with organizations that have visibility into stolen sessions experiencing identity events at 37% versus 50% for those that don't. The same dynamic plays out in the supply chain, where malware-infected third-party devices and exposed vendor API keys are the leading causes of supply chain identity events, and nearly 40% of organizations have no consistent process to confirm a third-party exposure was actually resolved once it's found. The report's practical conclusion, backed by its own maturity model, is that organizations relying on manual, case-by-case remediation report higher incident response costs and greater loss of customer trust than those with automated, continuous monitoring in place, suggesting that the real differentiator for CISOs isn't whether an exposure happens (at enterprise scale, some exposure is inevitable) but how long it stays usable before it's caught and shut down.