Non-human identities now top enterprise attack vector

Non-human identities, from API keys and tokens to service accounts and AI agents, have emerged as the primary way attackers gain initial access to corporate systems, according to new data from SpyCloud’s 2026 Identity Exposure Report.[10][15] The company’s latest analysis of billions of recaptured credentials from criminal marketplaces shows a sharp expansion in exposed machine identities and authenticated sessions that can be weaponized for stealthy intrusions.[15]

Non-human identities are digital credentials used by software, services, scripts and devices to authenticate to APIs, databases, cloud workloads and other resources without a human logging in.[1][5][14] Because modern enterprises rely on thousands or even millions of these identities to power automation and AI-driven workflows, they now outnumber human accounts and frequently hold broad, long-lived privileges.[7][9][14]

SpyCloud reports recapturing 18.1 million exposed API keys and tokens in 2025, spanning payment platforms, cloud infrastructure, developer ecosystems, collaboration tools and AI services.[15] The same dataset revealed 6.2 million credentials and authentication cookies tied to AI tools, alongside a 23% year-over-year increase that pushed SpyCloud’s identity datalake to 65.7 billion distinct records.[15] Unlike human logins, these machine identities often lack multifactor authentication, rarely rotate and operate continuously in production environments, giving attackers persistent, low-noise access once compromised.[9][15]

Industry groups focused on non-human identity management warn that NHIs have become the number one identity threat in enterprises, citing widespread exposure, weak controls and the ease with which attackers can discover and exploit orphaned machine credentials.[2][6][4] Research from the Cloud Security Alliance finds that all major NHI types—including service accounts, workload identities, automation bots, third‑party integrations and AI agents—introduce meaningful security risk through hidden access paths, excessive privilege and limited visibility.[14] OWASP’s emerging Top 10 risks for non-human identities highlight improper offboarding and lingering ghost accounts as critical weaknesses that quietly preserve access long after a system or integration is retired.[4][12]

The rise of agentic AI further amplifies the problem, as autonomous software agents routinely spin up new API keys, tokens and service accounts in security blind spots, often with broad, persistent access to sensitive data and systems.[3][11] Non-human identity experts warn that compromised machine credentials are increasingly leveraged for lateral movement and supply chain attacks, allowing adversaries to pivot through interconnected vendors and cloud services without tripping traditional user‑centric monitoring.[2][7][9]

Defenders are being urged to treat NHI security as a first‑class discipline within identity and access management, starting with a comprehensive inventory of machine identities across cloud, on‑prem and third‑party environments.[7][8][14] Guidance from major vendors and standards bodies emphasizes enforcing least‑privilege access for NHIs, centralizing policy enforcement, rotating keys and tokens on strict schedules, and applying strong authentication and behavioral monitoring wherever feasible.[1][5][4][14] Organizations that can rapidly detect exposed machine credentials in criminal ecosystems and revoke or re‑issue them, SpyCloud argues, will be far better positioned to blunt the growing wave of attacks that begin not with a phished user but with a silently abused non‑human identity.[10][15][9]

References

  1. What are Non-Human Identities (NHIs)?
  2. The NHI Challenge
  3. Non-human identities: Agentic AI’s new frontier of …
  4. OWASP’s Top 10 Security Risks for Non-Human Identities
  5. What Are Non-human Identities? | Microsoft Security
  6. Non-Human Identity Management Group
  7. The State of Non-Human Identity Security
  8. The Practitioner’s Guide to Non-Human Identities
  9. Non-Human Identities As The Next Big Security Risk
  10. SpyCloud Annual Identity Exposure Report 2026
  11. The Rise of Non-Human Identities: A New Cybersecurity Frontier
  12. OWASP’s Top 10 NHI Risks: A Wake-Up Call For Modern Cybersecurity
  13. Defining Non-Human Identity (NHI) – Cloud Security Alliance (CSA)
  14. SpyCloud’s 2026 Identity Exposure Report Reveals …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply