Security

Stolen Sessions Overtook Passwords, and 53% of Organizations Only Watch Managed Devices for Malware

SpyCloud's survey of 750 security leaders found session data has replaced the password as the prize, while most teams see malware only on the laptops they manage. On the Mac, the stealers that harvest those sessions now stay behind as backdoors.

September 29, 2026 · Security
A laptop on a white desk against a whitewashed brick wall, its screen showing a login form with username and password fields, beside a pencil pot, notebooks, tulips in a glass vase and a black desk clock

Key Takeaways

  • SpyCloud's 2026 Identity Threat Report, a survey of 750 security leaders, found 68% of organizations had an identity-based event in the past year, averaging eight events each.
  • Organizations without visibility into stolen session cookies had a 50% event rate, against 37% for those that monitor them, and 53% see malware exposures only on managed devices.
  • Compromised non-human identities were named the primary entry point by 31% of respondents, nearly twice the 17% who named phishing and social engineering.
  • Moonlock counted 67% growth in new macOS backdoor variants against 17% for stealers, and Kaspersky found the latest MacSync stealer planting persistence in shell profiles and Git hooks.

For most of the past decade, the stolen password was the currency of intrusion, and the industry answered it with multifactor authentication. Attackers adjusted. The newest data shows they now go after the thing that exists after a user has already passed MFA: the authenticated session. And the devices those sessions are stolen from are, for most organizations, the ones their security tools cannot see.

The Session Is the New Password

SpyCloud's 2026 Identity Threat Report surveyed 750 cybersecurity leaders and practitioners at organizations with 500 or more employees across North America, the UK and five European countries. Sixty-eight percent had experienced an identity-based event in the past year, and those that had averaged eight. SpyCloud says its own recaptured criminal data now includes more than 17 billion session cookies and more than 63 million API keys and tokens.

According to coverage of the report's release on September 9, session data has overtaken passwords as the top target. The survey puts a number on what that means. Organizations with no visibility into stolen session cookies reported a 50% event rate. Those that could see them reported 37%. A stolen session cookie lets an attacker resume a signed-in browser session without ever facing a password prompt or an MFA challenge, which is why defenses built around the login screen do not stop it.

The same gap shows up for devices. Fifty-three percent of respondents said their malware visibility is limited to managed devices. Organizations without visibility into personal devices had a 52% event rate, against 40% for those that monitor them. The implication is uncomfortable: the unmanaged laptop that an employee uses to check corporate email or a contractor uses to reach a SaaS console is exactly where a stealer can run unnoticed and export a working session. SpyCloud found 23% of organizations traced identity events to malware-infected third-party devices, and 40% have no consistent process for confirming that a third party's exposure has been fixed.

Machine Identities Are the Wider Door

Sessions belong to people. A growing share of the credentials attackers use belong to software. Thirty-one percent of SpyCloud's respondents named compromised non-human identities, such as service accounts, API keys and tokens, as the single most common initial access vector, nearly twice the 17% who named phishing and social engineering. Forty-two percent said misuse of these identities was their most commonly reported identity event.

AI tools are adding to the pile. Ninety-one percent of organizations use AI tools with access to internal systems, but only 56% have formal governance and ownership for the privileges those tools hold. Ninety-five percent believe they have visibility into AI and machine identity exposures, yet only 36% actually monitor them. "Every one of these identities is a standing invitation that renews itself until someone notices," said Trevor Hilligoss, SpyCloud's chief intelligence officer.

On the Mac, the Stealer Now Stays Behind

The malware that harvests sessions and tokens is changing too, most visibly on macOS. Moonlock's mid-2026 macOS threat report counted 67% growth in new backdoor variants against 17% for stealer variants, and describes a new class of threat as "a persistent, remotely controlled implant that starts with stealing." Odyssey accounted for 62.7% of stealer detections and Atomic Stealer for 29.8%. One stealer family it examined carries a developer-focused module that sweeps SSH keys, cloud credentials and package manager tokens, precisely the non-human identities SpyCloud's respondents rank as the leading way in.

Kaspersky's analysis of a new MacSync version, published September 24, shows what that looks like in practice. The stealer collects browser cookies and passwords, keychain files, and SSH, AWS, Kubernetes and Git configuration. It then persists through a LaunchAgent named to resemble a Finder component, commands injected into the user's shell profile, and Git hooks that run on every commit and checkout. In at least one sample, the link to the next-stage downloader pointed to a public iCloud calendar, so the traffic looks like a Mac talking to Apple.

The delivery method is consistent. Moonlock cites Microsoft's finding that ClickFix, which tricks users into pasting commands into Terminal themselves, accounted for 47% of observed initial access. 9to5Mac's September review of the Mac threat landscape describes a Group-IB discovery, ClickLock, that talks users into handing over their system password and leaves a backdoor for a second visit, and notes Jamf Threat Labs' July find of a stealer disguised as Apple's crash reporting framework.

Put the two datasets together and the pattern is clear. A single infected Mac, often a developer's and often not fully managed, can now yield live browser sessions, cloud keys and repository access, and keep yielding them. Resetting a password does nothing to a stolen session or an unrotated API key, and removing the stealer does nothing if its persistence survives in a shell profile or a Git hook.

MFA solved the problem it was built for. Attackers simply moved to what comes after it, the session and the token, and to the devices that security teams cannot see. The fix is not a stronger login screen. It is treating every session, every machine credential and every endpoint as something that can be stolen, and being able to revoke it when it is.

Share

More in Security

All Resources →