Machine Identities, Not Phishing, Now the Top Way Hackers Break In
A new study from SpyCloud has found that non-human identities (NHIs), including AI agents, service accounts, API keys and authentication tokens, are now nearly twice as likely to be an attacker's primary entry point into a business than phishing. The Identity Threat Report, based on a survey of 750 cybersecurity professionals at large organisations, found NHIs accounted for 31% of intrusions compared to 17% for social engineering.
The report highlights a dangerous gap: while 95% of organisations believe they have good visibility into their non-human identities, only 36% actually monitor them. These accounts are often given elevated privileges but rarely get removed or have their credentials rotated when no longer needed, leaving businesses exposed for long periods. Some 68% of respondents said they had experienced an identity-related security incident, with 42% involving misuse of a non-human identity.
The research also found a mismatch between AI adoption and governance: almost all organisations use AI tools with access to internal systems or data, but only 56% have formal processes to manage their permissions. Organisations with visibility into stolen session cookies experienced far fewer identity-related incidents (37%) than those without (50%), underscoring the value of monitoring these often-overlooked accounts.