Even when you know exactly what you're looking for, digging through mountains of data takes far too long. With SpyCloud Research Agent, you get speed, context, and control: expert-level answers, signals across thousands of records, and hours back in every investigation. ✔️ Research Agent works alongside the analyst, self-contained, with nothing leaking out to the web. ✔️ You have the ability to ask a question in plain language like, "tell me everything you have in the SpyCloud data for this selector," and it goes and gets the answer. ✔️ Criminals race to profit from stolen data, and investigators race to stop them. Research Agent saves hours and shrinks the window those criminals get. Hear how our experts are using Research Agent and how it can help you find what you’re looking for – fast. https://lnkd.in/gURGTbPg
SpyCloud
Security and Investigations
Austin, Texas 16,281 followers
The leader in identity threat protection solutions on a mission to disrupt cybercrime.
About us
SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from the threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings. Customers include 7 of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now. To learn more and see insights on your company's exposed data, visit spycloud.com.
- Website
-
https://spycloud.com/
External link for SpyCloud
- Industry
- Security and Investigations
- Company size
- 201-500 employees
- Headquarters
- Austin, Texas
- Type
- Privately Held
- Founded
- 2016
- Specialties
- Account Takeover Prevention, Active Directory Protection, Cybersecurity, Compromised Credential Monitoring, ransomware prevention, post-infection remediation, identity threat protection, malware remediation, dark web monitoring, phishing, insider threat, and session hijacking prevention
Products
SpyCloud
Threat Intelligence Platforms
For close to a decade, SpyCloud has automated identity threat protection for more than 4+ billion employee and consumer accounts. Our focus is making darknet data actionable to protect businesses from cyberattacks, safeguard employee and consumer identities, and streamline cybercrime investigations. Customers globally – including 7 of the Fortune 10 – count on SpyCloud to thwart identity-based attacks including ransomware, account takeover, session hijacking, and online fraud.
Employees at SpyCloud
Locations
-
Primary
Get directions
2130 Congress Ave S
Austin, Texas 78704, US
Updates
-
Attention OSINT Analysis Symposium attendees! Here's your chance to connect with the SpyCloud Fed team TOMORROW at Event Space 2 from 8:00 AM to 2:00 PM ET. Let's discuss how SpyCloud helps federal agencies and their contractors stay ahead of cybercrime by delivering globally sourced darknet data, automated remediation, and identity attribution tools, empowering the most critical OCO/DCO missions.
-
This Cybersecurity Awareness Month, we’ll touch on a few topics. Today, we’re spreading awareness about the identity threats traditional Zero Trust misses. As companies move toward continuous authentication, they need to monitor for exposed identities. But the problem is that most Zero Trust implementations don't actually check whether employee credentials are floating around on the darknet when making access decisions. That leaves you vulnerable to attackers bypassing your MFA and hijacking sessions. Your Zero Trust policies need to keep verifying identity throughout the session – not just at login – because attackers compromise accounts between login events. Learn more about how SpyCloud helps you solve the modern Zero Trust challenge: https://lnkd.in/enQG_3TZ
-
Send some virtual high-fives to SpyCloud's newest investigators – Harrison M. and Michael Cunningham. 🎉 Glad to have you both on our mission and can't wait to see what you bring to the team!
-
Here's the winning combination for today: ✔️ You're a member of CyberRisk Alliance ✔️ You're at the Seattle/Bellevue Official Cybersecurity Summit ✔️ You attend SpyCloud Solution Engineer James Rulison's presentation at 2PM At his session, "Inside the Criminal Underground: Post-Authentication Identity Threats," James will speak about how identity assets form attack surfaces beyond traditional defenses, and gain practical insights from SpyCloud's criminal investigations to protect your organization. Our team is fueled up for some great conversations, so be sure to connect with us if you're here! And even if you're not at the conference, you can still get that demo: https://bit.ly/3VpyiCf
-
-
There’s something painfully human about feeling confident in something until reality hits and reveals all the things you don’t know. And when it comes to protecting your organizations from identity threats, the data clearly shows that confidence doesn’t equal coverage. SpyCloud’s 2026 Identity Threat Report contains a UK case study that demonstrates what happens when you can’t see what’s actually compromised. UK respondents reported higher confidence in their NHI visibility than any other region we surveyed (53%), showing security teams there felt like they understood their threat landscape better than their counterparts elsewhere. And yet, 77% of those organizations experienced an identity-based event in the past year. That’s a huge blind spot. But this disconnect isn’t limited to the UK – we surveyed 750 cybersecurity leaders and practitioners, and the pattern repeats everywhere. Organizations surveyed that reported they got hit by an identity event in the last 12 months were significantly less likely to have visibility into two things: stolen session cookies and personal devices with corporate access, two of the most common entry points attackers use. Attackers don’t need to be clever anymore, they just need to sit outside the normal visibility workflow and find what you can’t see (like a contractor’s laptop). And by the time you realize they’re compromised, the damage is done. So to fix this, start with visibility. You don’t need a separate tool or program, just extend the identity management you already have to include the identities you're not currently seeing, and watch for behavior that looks different. If organizations treat all identities – human and non-human, managed and distributed – with equal scrutiny, they avoid being compromised. Read our full 2026 Identity Threat Report – no sign up required: https://lnkd.in/exZZZnR8
-
We're nearing the end of National Insider Threat Awareness Month, so let's take a look at how North Korean IT workers are actively infiltrating U.S. organizations: They're applying through HR systems, getting hired as remote contractors, and siphoning salaries back to fund the regime. Not exactly employee of the month material. SpyCloud investigators are identifying these Democratic People’s Republic of Korea (DPRK) campaigns by analyzing infostealer malware logs – uncovering the fraud tactics and exposing the identities behind them. Operations and security teams need aligned playbooks and workflows to catch what traditional defenses miss. Sometimes a coworker isn't who they say they are, and that alignment is critical to protecting your organization. Read our blog on how to identify fake North Korean IT workers: https://lnkd.in/eAHnepyb
-
You’ve heard us say it before, but attackers aren't after your passwords anymore. Anthropic said it themselves in a threat report describing what we’ve been monitoring all year. The clearest example of criminals re-setting their sights: A state-linked group ran a device code phishing campaign that abused a legitimate cloud email sign-in flow. No trickery with a fake login page, no passwords were stolen, the victim just logs in normally. Everything is seemingly normal because the MFA clears…and the attacker walks away with a session token that can outlast a password reset and even MFA re-enrollment. The session is the target – and it has been for a while now. Another finding in Anthropic’s report was an instance of a single hacktivist using AI-assisted coding and agent frameworks reaching what Anthropic called advanced-persistent-threat-level capability – on its own. The gap between a lone actor and a nation-state is closing fast. And we're not just reading about this, our researchers are seeing it happen in real time. Just last week, SpyCloud Labs data helped Microsoft's DCU, Health-ISAC, and law enforcement dismantle EvilTokens – the phishing-as-a-service platform that commercialized this exact technique – exposing 8,700+ compromised accounts across 79 countries. Firewalls and MFA are still important when defending the perimeter. But once attackers steal credentials or sessions, those defenses stop working. You need visibility into what's actually exposed and compromised. That's what we give organizations. 🔗 Read how we helped take down EvilTokens: https://bit.ly/4yf8B5L
-
Cool people alert! And they just so happen to be the newest members of #TeamSpyCloud. 😎 Please welcome Ryan Clark, Kit Fach, and Mareka Glaza as they embark on their new adventure!
-
SpyCloud's Donovan Stevens helps unpack the recent threat report from Anthropic which highlights how cybercriminals are using AI agents to automate and scale device code phishing attacks, among other topics. "Think of one criminal administrator that has hundreds of AI agents that are working collectively to do this," Donovan said. "So the speed at which an average criminal can now build this and do this at scale has really just lowered the bar tremendously in terms of the level of sophistication that's involved." Watch our conversation to learn why criminals are focused on stealing session tokens and are using AI to scale their operations: https://lnkd.in/ectC8XW8
-