Insight Articles: Identity Security Risks Series – 53 Billion Reasons to Fix Identity Sprawl

For Business Owners, CIOs & CISOs [8-minute read]

53 Billion Reasons to Fix Identity Sprawl

Your employees are using hundreds of apps you don’t know about. Their credentials from those apps are already on the dark web. Attackers are connecting the dots.

Ask your IT team how many SaaS applications your employees are using. They’ll give you a number. That number is probably wrong.

The real number is often two to three times higher because many of the applications employees use every day were never approved by IT, never reviewed by security, and never integrated into your identity management infrastructure. They were signed up for using a corporate email address, a personal credit card, and no organizational oversight.

Every one of those applications creates another identity. Another username. Another password. Another potential path into your business.

This is identity sprawl: the uncontrolled growth of accounts, credentials, and access rights across systems that no one has fully inventoried or manages consistently. It is no longer just an IT management problem. It has become one of the fastest-growing contributors to modern data breaches.

The Scale of What’s Already Exposed

$53.3B

Identity records – usernames, passwords, and email addresses – stolen and available on the dark web in 2024 alone

3.1 B

Exposed passwords collected in 2024 – a 125% increase year over year. Your employee’s passwords are in this list.

17.3B

Stolen session cookies available to attackers – allowing them to bypass passwords and MFA entirely

80%

Of organizations lack visibility into 40% or more of the SaaS applications their employees are actively using

The 53.3 billion figure is not just another cybersecurity statistic. It represents billions of compromised credentials that criminal organizations actively use to attack businesses every day.

Attackers purchase breach databases and use automated tools to test stolen usernames and passwords against Microsoft 365, Google Workspace, VPNs, SaaS platforms, and enterprise applications. They do this continuously, around the clock.

The question is not whether your employees have created accounts outside IT’s visibility. They almost certainly have. The question is whether the credentials they used for that Notion workspace, Figma account, AI tool, or project management platform have already appeared in one of those breach databases. Statistically, some of them have.

How Identity Sprawl Happens

Identity sprawl is not caused by careless employees. It is the result of productivity outpacing security.

Teams need tools to do their jobs. When procurement or IT approval takes too long, they find their own solutions. They sign up for a project management platform, a design tool, a data visualization service, or an AI assistant. They use their work email, create an account, and move on. That account often remains active for years, unmonitored and unmanaged.

Where Identity Sprawl Lives in the Average Organization

Sanctioned IT Apps

~30%

Shadow IT / SaaS

~50%

Orphaned Accounts

~70%

No SSO Enforcement

~60%

Every application that doesn’t use single sign-on (SSO) creates another password to manage. Every password is another potential entry point for an attacker. And every unmanaged account exists outside your security monitoring, offboarding processes, and access reviews.

This is how organizations end up with hundreds, or even thousands, of identities they never knew they had.

The Attacker’s Playbook

Here’s what a credential-based attack fueled by identity sprawl looks like in practice.
An attacker purchases a database containing millions of stolen email and password combinations from a dark web marketplace. Using automated tools, they test those credentials against Microsoft 365, Salesforce, GitHub, HubSpot, and dozens of other enterprise applications. Because employees often reuse passwords across multiple accounts, some of those login attempts succeed.
The attacker now has a legitimate session inside one of your business applications. From there, they can access customer data, intellectual property, financial information, or other sensitive records without exploiting a single vulnerability.

To your security tools, they don’t look like an attacker. They look like one of your employees.

“The attacker doesn’t break in. They log in. With valid credentials. To an app your security team doesn’t know exists.”

Case Studies

The Session Cookie Problem Makes It Worse

Stolen passwords are dangerous. Stolen session cookies are often worse.

A session cookie represents an already-authenticated user. If an attacker steals it, they can often bypass both passwords and MFA, gaining access without ever logging in.

Modern infostealer malware is designed to steal both credentials and browser-stored session cookies. It runs silently on an infected device, collects the data, and uploads it to attacker infrastructure, where it is often sold on dark web marketplaces within hours.

For organizations struggling with identity sprawl, stolen session cookies create another path into business applications, especially those that lack SSO, maintain long-lived sessions, or aren’t monitored for unusual access.

The Solution: Visibility, Then Control

You cannot secure identities you don’t know exist. The first step is discovery: building a complete inventory of all application employees are using, including the ones IT never approved.

SaaS discovery tools analyze network traffic, OAuth grants, and browser activity to reveal your true identity surface. For most organizations, it’s significantly larger than expected.
Once you know what’s there, you can bring it under control by enforcing single sign-on (SSO), eliminating orphaned accounts, regularly reviewing access, and creating an approval process that is secure without slowing the business down.

The Question to Ask Right Now

How many SaaS applications are your employees accessing with credentials that are not managed by your identity provider? The answer is almost certainly in the hundreds, and some of those accounts have already been compromised.

Find Out How Much of Your Identity Surface You Can’t See

Our Identity Security Gap Analysis includes a dedicated section on identity sprawl and SaaS governance. Five questions reveal whether you have the visibility and controls to govern your actual identity footprint.

Security Assessment

How Exposed Is
Your Company?

Uncover hidden risks across privileged accounts, credentials, vendor access, MFA, session monitoring, and compliance controls. Take our 5 minute Gap Assessment to see where your biggest security gaps may be hiding.

Start Free Assessment →

Privileged access management gap assessment results showing 4 critical security gaps, 3 partial controls, and 5 controls in place across identity management, access control, secrets management, session monitoring, endpoint security, and compliance.
5 MinutesQuick & Easy
14 Critical AreasComprehensive Coverage
Instant ResultsKnow Your Risks
Stronger SecurityBetter Protection