SpyCloud aleader in identity threat protection, today released its annual 2026 Identity Exposure Report, one of the most comprehensive analyses of stolen credentials and identity exposure data, highlighting a sharp expansion in non-human identities (NHI) exposure. Last year, SpyCloud saw a 23% increase in identity data recovered, now totaling 65.7 billion distinct identity records.
See also: US takes down sites linked to Iranian cyberattacks

The report shows that attackers are increasingly targeting mechanical identities and authentic session artifacts in addition to traditional username and password combinations and personally identifiable information (PII). “We are seeing a structural shift in how identity is exploited,” said Trevor Hilligoss, Chief Information Officer at SpyCloud.
SpyCloud recovered 18,1 million exposed API keys and tokens in 2025, covering payment platforms, cloud infrastructure providers, developer ecosystems, collaboration tools and AI services.
The report also identified 6.2 million credentials or authentication cookies associated with AI tools, reflecting the rapid adoption of AI platforms by enterprises and the corresponding expansion of machine‑based access paths. In contrast to human credentials, these NHI often lack MFA enforcement, rotate rarely, and operate with broad permissions. When exposed, they can provide attackers with persistent access to production systems, software supply chains, and cloud infrastructure.
See also: Is AppleCare One coming to EU markets?

Significantly, almost half of these identities were corporate users, underscoring that phishing remains a persistent threat to businesses. This trend aligns with SpyCloud's research showing that successful phishing attacks have increased by 400% on an annual basis. The result is a clear warning to enterprises: their workforce is now three times more likely to be targeted by phishing attacks than by malicious infostealer software.
The modern phishing data sets contain increasingly more credentials. Many include session cookies, authentication tokens, and MFA workflow data, allowing attackers to take over authentic sessions without triggering traditional alerts. With an influx of malicious actors using AI to craft more realistic lures and automate campaigns, this problem is not going to disappear soon and enterprise security teams need to go beyond employee training for a more realistic preventive approach.
The automated identity threat protection solutions use advanced analytics and AI to proactively prevent ransomware and account takeover, detect internal threats, protect employee and consumer identities, and accelerate cybercrime investigations. SpyCloud data from breaches, malware-infected devices, and successful phishing also feed many popular dark-web monitoring and identity theft protection offerings.
See also: Fancy Bear Hits Greece: Russian Espionage Breaches the Hellenic National Defense General Staff

Based in Austin, TX, SpyCloud hosts more than 200 cybersecurity experts tasked with protecting businesses and consumers from stolen identity data that criminals use to target them now.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
