Non-Human Identities Emerge as Top Corporate Entry Point for Attackers
Compromised non-human identities, including AI agents and service accounts, have surpassed phishing as the primary entry vector for cyberattacks targeting organizations.

A new report from SpyCloud reveals a significant shift in the threat landscape, with compromised non-human identities (NHIs) now representing the leading entry point for attackers into corporate networks. The SpyCloud Identity Threat Report, which surveyed 750 cybersecurity leaders and practitioners across North America and Europe, found that NHIs accounted for 31% of intrusions, nearly double the 17% attributed to social engineering tactics like phishing.
This finding is particularly alarming given the widespread belief among organizations that they possess adequate visibility into their NHI landscape. The study indicates that while 95% of organizations believe they have sufficient oversight, only 36% actively monitor these identities. This discrepancy leaves machine identities as the least-watched category of identity risk, creating a fertile ground for exploitation.
NHIs encompass a broad range of automated and machine-based credentials, including AI agents, service accounts, API keys, and authentication tokens. These identities are often granted elevated privileges necessary for system operations. However, they frequently suffer from poor lifecycle management, with credentials not being rotated and identities not being properly offboarded when no longer needed. This creates persistent security risks that attackers are actively exploiting.
"That asymmetry is what attackers are exploiting," stated Trevor Hilligoss, SpyCloud's chief intelligence officer. "Every one of these identities is a standing invitation that renews itself until someone notices." This highlights a critical governance gap where automated systems, designed for efficiency, inadvertently create long-standing vulnerabilities.
The report also uncovered a significant mismatch between AI adoption and governance. While nearly all surveyed organizations utilize AI tools or agents with access to internal systems, applications, or data, only 56% have formal processes to govern their privileges. A substantial portion, 41%, rely on informal processes or lack clear ownership, further exacerbating the risks associated with these powerful tools.
Visibility into identity-related risk is paramount for maintaining a strong security posture. The report noted that organizations with insight into stolen session cookies experienced identity-based events at a considerably lower rate (37%) compared to those without such visibility (50%). This underscores the importance of comprehensive identity monitoring across all types of accounts, human and non-human.
Supply chain attacks also remain a significant concern, with malware-infected third-party devices (23%) and exposed API keys involving vendors (22%) cited as primary causes of identity-related events. Despite the recognized threat, nearly two-fifths of respondents admitted to lacking a consistent process for confirming third-party identity exposure, even as many plan to focus more on supply chain risk management in the coming years.
As organizations harden traditional defenses like passwords and employee account security, attackers are increasingly shifting their focus to less-monitored areas like NHIs. The report's findings serve as a critical call to action for organizations to prioritize the security and governance of their machine identities to effectively defend against the evolving threat landscape.
SpyCloud's latest report further quantifies this trend, revealing that 95% of organizations believe they have visibility into non-human identity (NHI) exposures, yet only 36% actively monitor them. This significant gap allows compromised NHIs, such as service accounts and API keys, to remain exploitable for extended periods due to their lack of human oversight and typical security controls like MFA.