SpyCloud’s cover photo
SpyCloud

SpyCloud

Security and Investigations

Austin, Texas 16,281 followers

The leader in identity threat protection solutions on a mission to disrupt cybercrime.

About us

SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from the threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings. Customers include 7 of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now. To learn more and see insights on your company's exposed data, visit spycloud.com.

Website
https://spycloud.com/
Industry
Security and Investigations
Company size
201-500 employees
Headquarters
Austin, Texas
Type
Privately Held
Founded
2016
Specialties
Account Takeover Prevention, Active Directory Protection, Cybersecurity, Compromised Credential Monitoring, ransomware prevention, post-infection remediation, identity threat protection, malware remediation, dark web monitoring, phishing, insider threat, and session hijacking prevention

Products

Employees at SpyCloud

View 288 employees at SpyCloud

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

Updates

  • Even when you know exactly what you're looking for, digging through mountains of data takes far too long. With SpyCloud Research Agent, you get speed, context, and control: expert-level answers, signals across thousands of records, and hours back in every investigation. ✔️ Research Agent works alongside the analyst, self-contained, with nothing leaking out to the web. ✔️ You have the ability to ask a question in plain language like, "tell me everything you have in the SpyCloud data for this selector," and it goes and gets the answer.  ✔️ Criminals race to profit from stolen data, and investigators race to stop them. Research Agent saves hours and shrinks the window those criminals get. Hear how our experts are using Research Agent and how it can help you find what you’re looking for – fast. https://lnkd.in/gURGTbPg

  • Attention OSINT Analysis Symposium attendees! Here's your chance to connect with the SpyCloud Fed team TOMORROW at Event Space 2 from 8:00 AM to 2:00 PM ET. Let's discuss how SpyCloud helps federal agencies and their contractors stay ahead of cybercrime by delivering globally sourced darknet data, automated remediation, and identity attribution tools, empowering the most critical OCO/DCO missions.

  • This Cybersecurity Awareness Month, we’ll touch on a few topics. Today, we’re spreading awareness about the identity threats traditional Zero Trust misses. As companies move toward continuous authentication, they need to monitor for exposed identities. But the problem is that most Zero Trust implementations don't actually check whether employee credentials are floating around on the darknet when making access decisions. That leaves you vulnerable to attackers bypassing your MFA and hijacking sessions. Your Zero Trust policies need to keep verifying identity throughout the session – not just at login – because attackers compromise accounts between login events. Learn more about how SpyCloud helps you solve the modern Zero Trust challenge: https://lnkd.in/enQG_3TZ

  • View organization page for SpyCloud

    16,281 followers

    Here's the winning combination for today: ✔️ You're a member of CyberRisk Alliance ✔️ You're at the Seattle/Bellevue Official Cybersecurity Summit ✔️ You attend SpyCloud Solution Engineer James Rulison's presentation at 2PM At his session, "Inside the Criminal Underground: Post-Authentication Identity Threats," James will speak about how identity assets form attack surfaces beyond traditional defenses, and gain practical insights from SpyCloud's criminal investigations to protect your organization. Our team is fueled up for some great conversations, so be sure to connect with us if you're here! And even if you're not at the conference, you can still get that demo: https://bit.ly/3VpyiCf

    • No alternative text description for this image
  • There’s something painfully human about feeling confident in something until reality hits and reveals all the things you don’t know. And when it comes to protecting your organizations from identity threats, the data clearly shows that confidence doesn’t equal coverage. SpyCloud’s 2026 Identity Threat Report contains a UK case study that demonstrates what happens when you can’t see what’s actually compromised.  UK respondents reported higher confidence in their NHI visibility than any other region we surveyed (53%), showing security teams there felt like they understood their threat landscape better than their counterparts elsewhere. And yet, 77% of those organizations experienced an identity-based event in the past year. That’s a huge blind spot. But this disconnect isn’t limited to the UK – we surveyed 750 cybersecurity leaders and practitioners, and the pattern repeats everywhere. Organizations surveyed that reported they got hit by an identity event in the last 12 months were significantly less likely to have visibility into two things: stolen session cookies and personal devices with corporate access, two of the most common entry points attackers use. Attackers don’t need to be clever anymore, they just need to sit outside the normal visibility workflow and find what you can’t see (like a contractor’s laptop). And by the time you realize they’re compromised, the damage is done. So to fix this, start with visibility. You don’t need a separate tool or program, just extend the identity management you already have to include the identities you're not currently seeing, and watch for behavior that looks different. If organizations treat all identities – human and non-human, managed and distributed – with equal scrutiny, they avoid being compromised. Read our full 2026 Identity Threat Report – no sign up required: https://lnkd.in/exZZZnR8

  • We're nearing the end of National Insider Threat Awareness Month, so let's take a look at how North Korean IT workers are actively infiltrating U.S. organizations: They're applying through HR systems, getting hired as remote contractors, and siphoning salaries back to fund the regime. Not exactly employee of the month material. SpyCloud investigators are identifying these Democratic People’s Republic of Korea (DPRK) campaigns by analyzing infostealer malware logs – uncovering the fraud tactics and exposing the identities behind them. Operations and security teams need aligned playbooks and workflows to catch what traditional defenses miss. Sometimes a coworker isn't who they say they are, and that alignment is critical to protecting your organization. Read our blog on how to identify fake North Korean IT workers: https://lnkd.in/eAHnepyb

  • View organization page for SpyCloud

    16,281 followers

    You’ve heard us say it before, but attackers aren't after your passwords anymore. Anthropic said it themselves in a threat report describing what we’ve been monitoring all year. The clearest example of criminals re-setting their sights: A state-linked group ran a device code phishing campaign that abused a legitimate cloud email sign-in flow. No trickery with a fake login page, no passwords were stolen, the victim just logs in normally. Everything is seemingly normal because the MFA clears…and the attacker walks away with a session token that can outlast a password reset and even MFA re-enrollment. The session is the target – and it has been for a while now. Another finding in Anthropic’s report was an instance of a single hacktivist using AI-assisted coding and agent frameworks reaching what Anthropic called advanced-persistent-threat-level capability – on its own. The gap between a lone actor and a nation-state is closing fast. And we're not just reading about this, our researchers are seeing it happen in real time. Just last week, SpyCloud Labs data helped Microsoft's DCU, Health-ISAC, and law enforcement dismantle EvilTokens – the phishing-as-a-service platform that commercialized this exact technique – exposing 8,700+ compromised accounts across 79 countries. Firewalls and MFA are still important when defending the perimeter. But once attackers steal credentials or sessions, those defenses stop working. You need visibility into what's actually exposed and compromised. That's what we give organizations. 🔗 Read how we helped take down EvilTokens: https://bit.ly/4yf8B5L

  • SpyCloud's Donovan Stevens helps unpack the recent threat report from Anthropic which highlights how cybercriminals are using AI agents to automate and scale device code phishing attacks, among other topics. "Think of one criminal administrator that has hundreds of AI agents that are working collectively to do this," Donovan said. "So the speed at which an average criminal can now build this and do this at scale has really just lowered the bar tremendously in terms of the level of sophistication that's involved." Watch our conversation to learn why criminals are focused on stealing session tokens and are using AI to scale their operations: https://lnkd.in/ectC8XW8

    • No alternative text description for this image

Similar pages

Browse jobs