Theresa HouckHost
How non-human identities are becoming a top enterprise attack path, written by Rodney Bosch, September tenth, two thousand and twenty-six, published to tech.endeavoredge.com. Non-human identities such as AI agents, servants accounts, API keys, and authentication tokens have become the most common initial access route into enterprise environments, according to new research from SpyCloud, which points to widening gaps between organizations' confidence in their identity visibility and what they're actually monitoring.

The twenty twenty-six SpyCloud Identity Threat Report, released September ninth, is based on a survey of seven hundred and fifty cybersecurity leaders and practitioners at organizations with at least five hundred employees across the United States, Canada, the United Kingdom, and select European markets.

Among organizations that experience identity-related security events, thirty-one percent identified compromised or overprivileged non-human identities, or NHIs, as their most common initial access vector.

That was nearly twice the seventeen percent that cited phishing and social engineering.

NHI-related misuse was also the most frequently reported type of identity-based event at forty-two percent.

Overall, sixty-eight percent of organizations experienced an identity-based event during the previous year, which affected organizations averaging eight events.

The findings reflected an attack surface that is expanding well beyond the traditional employee identities and endpoints, according to Trevor Hilligoss, SpyCloud chief intelligence officer and a former FBI and Department of Defense cyber investigator.

How non-human identities are becoming a top enterprise attack path, written by Rodney Bosch, September tenth, two thousand and twenty-six, published to tech.endeavoredge.com. Non-human identities such as AI agents, servants accounts, API keys, and authentication tokens have become the most common initial access route into enterprise environments, according to new research from SpyCloud, which points to widening gaps between organizations' confidence in their identity visibility and what they're actually monitoring.

The twenty twenty-six SpyCloud Identity Threat Report, released September ninth, is based on a survey of seven hundred and fifty cybersecurity leaders and practitioners at organizations with at least five hundred employees across the United States, Canada, the United Kingdom, and select European markets.

Among organizations that experience identity-related security events, thirty-one percent identified compromised or overprivileged non-human identities, or NHIs, as their most common initial access vector.

That was nearly twice the seventeen percent that cited phishing and social engineering.

NHI-related misuse was also the most frequently reported type of identity-based event at forty-two percent.

Overall, sixty-eight percent of organizations experienced an identity-based event during the previous year, which affected organizations averaging eight events.

The findings reflected an attack surface that is expanding well beyond the traditional employee identities and endpoints, according to Trevor Hilligoss, SpyCloud chief intelligence officer and a former FBI and Department of Defense cyber investigator.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.