Security News

Machine Identities, Not Phishing, Now the Top Way Hackers Break In

Infosecurity Magazine · 9 Sept 2026
Key Takeaway Small businesses should maintain an up-to-date inventory of all service accounts, API keys and AI tool permissions, and remove or rotate credentials for any that are no longer actively needed.

A new study from SpyCloud has found that non-human identities (NHIs), including AI agents, service accounts, API keys and authentication tokens, are now nearly twice as likely to be an attacker's primary entry point into a business than phishing. The Identity Threat Report, based on a survey of 750 cybersecurity professionals at large organisations, found NHIs accounted for 31% of intrusions compared to 17% for social engineering.

The report highlights a dangerous gap: while 95% of organisations believe they have good visibility into their non-human identities, only 36% actually monitor them. These accounts are often given elevated privileges but rarely get removed or have their credentials rotated when no longer needed, leaving businesses exposed for long periods. Some 68% of respondents said they had experienced an identity-related security incident, with 42% involving misuse of a non-human identity.

The research also found a mismatch between AI adoption and governance: almost all organisations use AI tools with access to internal systems or data, but only 56% have formal processes to manage their permissions. Organisations with visibility into stolen session cookies experienced far fewer identity-related incidents (37%) than those without (50%), underscoring the value of monitoring these often-overlooked accounts.

non-human identities AI security identity management API security cyber threats
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.