Machine Accounts Are Now the Likeliest Way Into Your Company, and Almost Nobody Is Watching Them
A new SpyCloud survey of 750 security leaders finds that automated accounts and AI agents have become the single most common entry point for attackers, yet fewer than four in ten organisations are actively monitoring them.

Key points
- Compromised non-human identities, meaning automated accounts and AI agents rather than human employees, were the leading way attackers entered organisations in 2025, cited by 31% of respondents.
- Only 36% of organisations actively monitor these machine accounts, even though 95% say they believe they have full visibility into them.
- 68% of surveyed organisations experienced at least one identity-based security event in the period covered, with affected organisations averaging eight separate incidents each.
- 91% of organisations use AI tools with access to internal systems, but only 56% have formal rules about who owns the access those tools hold.
- Organisations using automated fixes for exposed identities reported meaningfully lower incident costs than those relying on manual responses, 32% versus 39%.
Most companies keep careful records of every person on the payroll. They know who started, who left, and whose access badge to deactivate on the last day. What they are far less careful about is a different kind of account entirely: the automated accounts that software systems, AI agents, and third-party tools use to log in and move data around without any human touching a keyboard.
A new report from identity-security firm SpyCloud puts a number on how badly that gap is being exploited.
What exactly is a 'machine identity', and why should I care?
A machine identity is simply a set of login credentials that belongs to a piece of software rather than a person. Think of the automated account a payroll system uses to pull employee records at midnight, or the digital key a vendor's app uses to connect to your internal database. These are sometimes called service accounts, API keys (essentially a password for software-to-software connections), or authentication tokens.
Unlike human accounts, they rarely get switched off when they are no longer needed. They cannot be sent a multi-factor authentication prompt, where a user confirms a login by approving a notification on their phone. And they often carry significant access privileges inside the systems they connect to. Once one is stolen, an attacker can use it quietly for months.
"Every one of these identities is a standing invitation that renews itself until someone notices," said Trevor Hilligoss, SpyCloud's Chief Intelligence Officer.
How serious is the problem right now?
Quite serious, and growing. SpyCloud surveyed 750 cybersecurity leaders at organisations with more than 500 employees across North America, the UK, and several European countries. The results, published in the SpyCloud 2026 Identity Threat Report, show that a stolen or misused machine identity was the primary way attackers got in during 31% of reported incidents, nearly twice the rate of phishing (17%), which traditionally tops these rankings.
| Finding | Figure |
|---|---|
| Orgs that experienced an identity-based event | 68% |
| Average events per affected organisation | 8 |
| Machine identity misuse as leading event type | 42% |
| Orgs that believe they monitor machine identities | 95% |
| Orgs that actually monitor machine identities | 36% |
| Orgs using AI tools with access to internal systems | 91% |
The confidence gap in that table is striking. Nearly every organisation thinks it has the situation covered. A fraction of them actually do.
Session cookies, small files a browser saves after a successful login, have become a prized target because stealing one lets an attacker skip the login process entirely. SpyCloud found that organisations without visibility into stolen session cookies suffered identity-related incidents at a rate of 50%, compared with 37% for those that could see when cookies were compromised.
What should ordinary employees and customers watch for?
For most employees, the practical takeaway is simple: phishing emails and malicious software that records what you type are still the tools criminals use to steal the credentials that eventually become machine-account breaches. Forty percent of surveyed organisations admitted incomplete visibility into which phishing attacks actually succeeded against their staff.
If you receive an unexpected email asking you to log in somewhere, verify it through a separate channel before clicking anything. Report anything suspicious to your IT team. Those small actions reduce the stock of stolen credentials available to attackers.
For organisations, the report is a call to treat machine accounts with the same discipline applied to human ones: catalogue them, assign an owner to each, rotate their credentials on a schedule, and watch them continuously for unusual activity. Automation helps. Organisations with highly automated remediation processes spent less on incident response and lost less customer trust than those still handling breaches case by case.



