News alert: SpyCloud study reveal stolen tokens, session data fuel surge in non-human identity attacks
ID: 2e4d7e12-5621-5560-84f6-082fa4f689af
STIX ID: report--2e4d7e12-5621-5560-84f6-082fa4f689af
Feed Name: Security Boulevard
SpyCloud’s 2026 Identity Exposure Report documents a sharp expansion in identity exposure across human and non-human identities, reporting billions of exposed assets (including 65.7B recaptured identity records overall, 8.6B stolen cookies/session artifacts, 5.3B credential pairs, 18.1M exposed API keys/tokens, and 642.4M credentials from infostealer infections). The report highlights growing targeting of machine identities and API keys, large-scale phishing and MFA-bypass campaigns (including session replay/AitM kits), persistent infostealer activity, poor password hygiene, and the need for continuous automated identity threat protection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
