What's Happening?
A new study by SpyCloud, the 'SpyCloud Identity Threat Report,' indicates that compromised non-human identities (NHIs), including AI agents, are now the leading entry point for hackers into enterprise systems. The report, based on a survey of 750 cybersecurity
leaders and practitioners across North America and Europe, found that NHIs account for 31% of intrusions, nearly double the rate of social engineering and phishing attacks (17%). Despite 95% of organizations believing they have adequate visibility into NHIs, only 36% actually monitor them, making machine identities the least-watched category of identity risk. This oversight is critical, as 68% of surveyed organizations experienced an identity-based event, with NHI-related misuse being the most common type at 42%. Trevor Hilligoss, SpyCloud's chief intelligence officer, highlighted that NHIs often retain elevated privileges and are not properly offboarded or have their credentials rotated, creating persistent security vulnerabilities that attackers exploit.
Why It's Important?
The shift to non-human identities as the primary vector for cyberattacks represents a significant challenge for U.S. businesses and national security. As organizations increasingly integrate AI tools and automated systems, the proliferation of NHIs creates a vast and often unmonitored attack surface. The report underscores a critical governance gap: while nearly all organizations use AI tools with access to internal systems, only 56% have formal processes to govern their privileges. This lack of oversight means that sensitive data and critical infrastructure are vulnerable to breaches through compromised AI agents, service accounts, and API keys. The economic impact could be substantial, with potential for data theft, operational disruption, and reputational damage. Companies that fail to adapt their security strategies to address NHI risks stand to lose intellectual property, customer trust, and face regulatory penalties, while those that invest in robust NHI monitoring and governance will gain a competitive advantage in cybersecurity resilience.
What's Next?
Organizations will likely need to re-evaluate and strengthen their identity and access management (IAM) strategies to specifically address non-human identities. This includes implementing formal processes for governing NHI privileges, ensuring proper offboarding, and regularly rotating credentials. Increased investment in tools and platforms that provide comprehensive visibility and monitoring of machine identities will be crucial. Cybersecurity leaders and practitioners will need to prioritize training and awareness programs to educate their teams on the unique risks associated with NHIs. Furthermore, the report suggests a focus on supply chain risk management, as malware-infected third-party devices and exposed API keys from vendors contribute significantly to identity-based events. Over the next 12-18 months, a third of organizations plan to focus on supply chain risk management, indicating a growing recognition of the interconnectedness of enterprise security.
Beyond the Headlines
The rise of non-human identities as a primary attack vector highlights a deeper systemic issue in cybersecurity: the evolving nature of 'identity' in a digital, AI-driven world. Traditionally, security has focused on human users, but the increasing autonomy and integration of AI agents and automated systems mean that identity management must expand to encompass these entities. This shift raises ethical and legal questions about accountability when an AI agent is compromised and used for malicious purposes. It also points to a potential long-term trend where the lines between human and machine identities blur, requiring a fundamental rethinking of security architectures. The challenge extends beyond technical solutions to organizational culture, demanding that businesses recognize and manage the 'digital workforce' with the same rigor applied to human employees, ensuring that every 'identity' within the enterprise is secure and governed.











