CrowdStrike has announced the acquisition of identity management startup SGNL for approximately $740 million, aiming to strengthen its capabilities in dynamic, real-time access control for both human and AI-driven identities. The deal, led by CrowdStrike's executive team, highlights the growing importance of continuous identity enforcement as organizations increasingly rely on cloud services and deploy AI agents with broad system privileges. SGNL, founded in 2021 and led by a former Google product manager, is recognized for its unique approach to granting and revoking access based on real-time intelligence, addressing the security challenges posed by non-human identities and automated agents.
The integration of SGNL's technology will allow CrowdStrike to offer a runtime enforcement layer that dynamically manages access rights, reducing risks associated with static policies and standing privileges. This move reflects a broader industry trend toward automating identity security to respond to evolving threats, suspicious behaviors, and compromised devices. By acquiring SGNL, CrowdStrike positions itself to better protect enterprise environments where the proliferation of machine identities and AI agents demands more sophisticated, adaptive access controls.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
In announcing the transaction, CrowdStrike said the SGNL acquisition is expected to close during the company's first quarter of fiscal 2027. The company said SGNL's technology would be integrated into the Falcon platform after closing.
CrowdStrike said it intends to acquire identity security startup SGNL in a cash-heavy deal valued at roughly $740 million. The acquisition is aimed at expanding CrowdStrike's identity protection capabilities, especially around real-time access control for human, machine, and AI identities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
cio.com
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.