Non-Human Identities Lead to Increased Cybersecurity Risks

Non-Human Identities Lead to Increased Cybersecurity Risks

First seen 9 Sep 2026, 13:13 UTC CsoonlineMarkets.BusinessinsiderInfosecurity-Magazinespycloud.com 51.9

Article Content

Browse articles
ThreatCluster

The SpyCloud 2026 Identity Threat Report reveals that non-human identities (NHIs), such as AI agents and service accounts, are now the primary entry point for cyber attackers, accounting for 31% of breaches compared to 17% from phishing. Despite 95% of organizations believing they have visibility into these risks, only 36% actively monitor them. The report indicates that 68% of organizations experienced identity-based events, with NHI misuse reported at 42%. Governance of AI tools is lacking, with only 56% of organizations having formal processes in place. The study surveyed 750 cybersecurity leaders across North America and Europe, highlighting a significant gap in monitoring and governance of machine identities. The findings suggest that organizations are vulnerable due to the lack of ownership and oversight of NHIs, which can remain active for extended periods once compromised.

Key Points: • Non-human identities are now the leading entry point for cyber attacks, surpassing phishing. • Only 36% of organizations monitor their non-human identities despite high perceived visibility. • 68% of organizations reported experiencing identity-based events in the past year.

Ask AI about this cluster

Timeline

2026-09-09
SpyCloud releases 2026 Identity Threat Report
The report reveals that non-human identities are the primary entry point for cyber attacks, based on a survey of 750 cybersecurity leaders.
Csoonline
2026-09-09
Key findings published on NHI risks
The report highlights that 68% of organizations experienced identity-based events, with NHI misuse at 42%.
Markets.Businessinsider
2026-09-09
Governance issues identified
Only 56% of organizations have formal governance for AI tools, leading to potential security risks.
Infosecurity-Magazine