- 1 trillion recovered assets in SpyCloud's data lake, recaptured from breaches and illicit marketplaces.
- 17 billion compromised cookies identified in 2024 alone, highlighting the shift from password theft to session hijacking.
- Seven of the Fortune 10 companies are among SpyCloud's clients, demonstrating widespread adoption by global enterprises.
Experts would likely conclude that SpyCloud's decade of innovation underscores the critical shift in cybersecurity from password protection to safeguarding broader digital identities, including non-human entities, as cybercriminals evolve their tactics.
SpyCloud at 10: The Data War Shifts from Passwords to Digital Souls
AUSTIN, TX – August 20, 2026 – Ten years ago, a cybersecurity startup in Austin was founded on a radical premise: to fight cybercriminals, you must first think like them, and then use their own tools against them. That company, SpyCloud, is now marking its tenth anniversary. But this milestone is more than a corporate celebration; it’s a revealing barometer of how the battle for our digital lives has fundamentally changed. The perimeter has vanished, the password is a relic, and the very concept of "identity" is the new front line.
SpyCloud’s journey from a niche idea to a major player in the cybersecurity ecosystem offers a compelling look into the escalating sophistication of digital threats and the innovative defenses required to counter them.
From the Darknet to the Boardroom
SpyCloud’s origin story is rooted in the murky depths of the darknet. The founding mission, as articulated by CEO and co-founder Ted Ross, was to "turn criminals’ own data against them to disrupt the cybercrime economy." The company began systematically recapturing data from breaches, malware logs, and illicit marketplaces, building what it now claims is the world's largest data lake of its kind, with over one trillion recovered assets.
This massive repository of stolen information isn't for hoarding; it's for action. By analyzing this data, SpyCloud provides intelligence to its clients on which of their employees or customers have had their credentials, cookies, or other identity markers compromised. This allows organizations to act proactively, often before a compromised account can be used to inflict damage.
The impact has been significant. The company has grown to over 250 employees and serves a client roster that includes hundreds of global enterprises and government agencies, including a remarkable seven of the Fortune 10. This level of adoption by the world's largest companies speaks volumes.
"I’ve built security programs at massive global organizations, and I’ve brought SpyCloud with me each time," noted Mike Slavick, a Vice President of Cybersecurity at a Fortune 10 company and a long-time customer, in a statement. "Their recaptured identity data gives us a window into exposure that’s genuinely hard to replicate elsewhere." This sentiment is echoed in industry reviews, where clients praise the unique and actionable nature of the data, which allows them to move from a reactive to a proactive security posture.
The Evolution of the Breach: Beyond the Password
Perhaps the most critical insight from SpyCloud’s decade of data collection is the clear and dramatic shift in attacker methodology. For years, the primary target was the password. Now, the battle has moved past the login screen.
According to SpyCloud, stolen session cookies and authentication tokens now constitute nearly half of all identity assets recaptured from the criminal underground, making them the fastest-growing category of exposure. This is a tectonic shift. Cybercriminals, armed with sophisticated infostealer malware, are no longer just trying to guess or phish for a password. They are stealing the active, authenticated session itself.
This technique, known as session hijacking, effectively renders many traditional security measures, including multi-factor authentication (MFA), moot. If an attacker can steal a valid session cookie from an employee's browser, they can insert it into their own browser and gain access to corporate applications as that authenticated user, with no password or MFA prompt required. SpyCloud’s research from 2024 alone identified 17 billion compromised cookies.
This evolution in tactics demonstrates a core principle of the "Beyond the Launch" column: innovation is not limited to the defenders. The cybercrime economy is a hotbed of relentless, market-driven innovation. As defenses for passwords improved, criminals pivoted to a new, more vulnerable layer of the identity stack. SpyCloud's ability to track this shift in real-time has allowed its clients to begin closing a security gap that many didn't even know they had.
The Unseen Partner in Cybercrime Takedowns
While protecting corporate clients is its primary business, SpyCloud's impact extends into a more clandestine realm: the global fight against organized cybercrime. The company actively leverages its vast intelligence repository to assist law enforcement, a role that often goes unpublicized.
SpyCloud is a key contributor to initiatives like the World Economic Forum's Cybercrime Atlas and maintains working relationships with agencies such as the FBI and Europol. The press release credits their intelligence as a factor in several major takedowns, including the disruption of the Tycoon 2FA phishing kit and operations like Euroboss and Serengeti.
While law enforcement agencies are typically the public face of these successes, the role of private-sector intelligence partners is indispensable. They provide the ground-truth data—the stolen credentials, the malware artifacts, the communication logs—that allows investigators to connect the dots, attribute attacks, and build cases that lead to arrests and infrastructure dismantlement. This symbiotic relationship between private innovation and public enforcement is a critical, yet often overlooked, component of modern crime-fighting. It’s the embodiment of SpyCloud's mission to not just defend against cybercrime, but to actively disrupt it.
Securing the Unseen: The Next Frontier of Non-Human Identity
As SpyCloud looks to its next decade, its focus is already shifting to the next horizon of identity—one that is increasingly non-human. The modern enterprise is a sprawling ecosystem of APIs, service accounts, cloud workloads, and, increasingly, autonomous AI agents. Each of these "non-human identities" (NHIs) has credentials, permissions, and access rights. And each represents a potential target.
Industry analysts confirm this is the next major battlefield. A recent report from Forrester on workforce identity security highlighted the explosion of non-human identities as a primary driver of risk and complexity. As organizations adopt AI and automation at a breakneck pace, they are creating a vast new attack surface that traditional, human-centric security models are ill-equipped to handle.
SpyCloud's strategy is to extend its automated protection to this new class of identity. The same principles apply: recapture intelligence on compromised NHI credentials (like API keys or service account tokens) from the criminal underground and use it to automatically revoke access and remediate the threat.
This forward-looking approach underscores a crucial reality: the definition of "identity" in a security context is expanding rapidly. It's no longer just about protecting employee logins. It’s about securing the intricate web of automated processes and digital agents that now power the global economy. A decade in, SpyCloud’s real advantage may not be the size of its data lake, but its proven ability to see where the identity war is heading next and build the tools to fight it.
Topics & Related
Threat Landscape
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →