SpyCloud's survey of 750 security leaders found session data has replaced the password as the prize, while most teams see malware only on the laptops they manage. On the Mac, the stealers that harvest those sessions now stay behind as backdoors.
Key Takeaways
For most of the past decade, the stolen password was the currency of intrusion, and the industry answered it with multifactor authentication. Attackers adjusted. The newest data shows they now go after the thing that exists after a user has already passed MFA: the authenticated session. And the devices those sessions are stolen from are, for most organizations, the ones their security tools cannot see.
SpyCloud's 2026 Identity Threat Report surveyed 750 cybersecurity leaders and practitioners at organizations with 500 or more employees across North America, the UK and five European countries. Sixty-eight percent had experienced an identity-based event in the past year, and those that had averaged eight. SpyCloud says its own recaptured criminal data now includes more than 17 billion session cookies and more than 63 million API keys and tokens.
According to coverage of the report's release on September 9, session data has overtaken passwords as the top target. The survey puts a number on what that means. Organizations with no visibility into stolen session cookies reported a 50% event rate. Those that could see them reported 37%. A stolen session cookie lets an attacker resume a signed-in browser session without ever facing a password prompt or an MFA challenge, which is why defenses built around the login screen do not stop it.
The same gap shows up for devices. Fifty-three percent of respondents said their malware visibility is limited to managed devices. Organizations without visibility into personal devices had a 52% event rate, against 40% for those that monitor them. The implication is uncomfortable: the unmanaged laptop that an employee uses to check corporate email or a contractor uses to reach a SaaS console is exactly where a stealer can run unnoticed and export a working session. SpyCloud found 23% of organizations traced identity events to malware-infected third-party devices, and 40% have no consistent process for confirming that a third party's exposure has been fixed.
Sessions belong to people. A growing share of the credentials attackers use belong to software. Thirty-one percent of SpyCloud's respondents named compromised non-human identities, such as service accounts, API keys and tokens, as the single most common initial access vector, nearly twice the 17% who named phishing and social engineering. Forty-two percent said misuse of these identities was their most commonly reported identity event.
AI tools are adding to the pile. Ninety-one percent of organizations use AI tools with access to internal systems, but only 56% have formal governance and ownership for the privileges those tools hold. Ninety-five percent believe they have visibility into AI and machine identity exposures, yet only 36% actually monitor them. "Every one of these identities is a standing invitation that renews itself until someone notices," said Trevor Hilligoss, SpyCloud's chief intelligence officer.
The malware that harvests sessions and tokens is changing too, most visibly on macOS. Moonlock's mid-2026 macOS threat report counted 67% growth in new backdoor variants against 17% for stealer variants, and describes a new class of threat as "a persistent, remotely controlled implant that starts with stealing." Odyssey accounted for 62.7% of stealer detections and Atomic Stealer for 29.8%. One stealer family it examined carries a developer-focused module that sweeps SSH keys, cloud credentials and package manager tokens, precisely the non-human identities SpyCloud's respondents rank as the leading way in.
Kaspersky's analysis of a new MacSync version, published September 24, shows what that looks like in practice. The stealer collects browser cookies and passwords, keychain files, and SSH, AWS, Kubernetes and Git configuration. It then persists through a LaunchAgent named to resemble a Finder component, commands injected into the user's shell profile, and Git hooks that run on every commit and checkout. In at least one sample, the link to the next-stage downloader pointed to a public iCloud calendar, so the traffic looks like a Mac talking to Apple.
The delivery method is consistent. Moonlock cites Microsoft's finding that ClickFix, which tricks users into pasting commands into Terminal themselves, accounted for 47% of observed initial access. 9to5Mac's September review of the Mac threat landscape describes a Group-IB discovery, ClickLock, that talks users into handing over their system password and leaves a backdoor for a second visit, and notes Jamf Threat Labs' July find of a stealer disguised as Apple's crash reporting framework.
Put the two datasets together and the pattern is clear. A single infected Mac, often a developer's and often not fully managed, can now yield live browser sessions, cloud keys and repository access, and keep yielding them. Resetting a password does nothing to a stolen session or an unrotated API key, and removing the stealer does nothing if its persistence survives in a shell profile or a Git hook.
MFA solved the problem it was built for. Attackers simply moved to what comes after it, the session and the token, and to the devices that security teams cannot see. The fix is not a stronger login screen. It is treating every session, every machine credential and every endpoint as something that can be stolen, and being able to revoke it when it is.
Guide
MacSync persists through LaunchAgents, shell profiles and Git hooks on Macs that are often only partly managed. This checklist sets the enforced baseline that makes those changes visible and auditable.
Download
Whitepaper
A stolen session skips the login and lands straight in the content. This whitepaper covers the least-privilege access, classification and exposure response that limit what a hijacked session can reach.
Download
Guide
SpyCloud found 91% of organizations run AI tools with internal access but only 56% govern those privileges. This guide lays out the access controls and monitoring that close that gap.
Download
Unit 42 found only 12 of 405 AI-enabled malware samples on a real production endpoint.
WatchGuard found endpoint ransomware detections down 68% even as public extortion claims hit a record pace.
Cisco Talos found authentication abuse in 65% of Q2 2026 engagements, nearly double the prior quarter.