Skip to content
NHIs Now the Number One Corporate Entry Point for Hackers

NHIs Now the Number One Corporate Entry Point for Hackers

Infosecurity-Magazine September 9, 2026

Compromised non-human identities (NHIs) including AI agents are nearly twice as likely to be a primary entry point into the enterprise than phishing, a new study from SpyCloud has claimed.

The threat protection firm’s SpyCloud Identity Threat Report is based on a survey of 750 cybersecurity leaders and practitioners at organizations with 500+ employees in North America the UK, Spain, Germany, the Netherlands, Austria and Switzerland.

It revealed that NHIs such as AI agents, service accounts, API keys and authentication tokens accounted for 31% of intrusions, versus 17% for social engineering.

The findings are particularly concerning given that, while most (95%) organizations think they have adequate visibility into NHIs, only 36% actually monitor them. SpyCloud said this makes machine identities the least-watched category of identity risk studied.

Some 68% of respondents said they suffered an identity-based event in the reporting period, with NHI-related misuse at 42%.

While NHIs are often granted elevated privileges, they frequently don’t get offboarded, and related credentials aren’t rotated, making them a persistent security risk, SpyCloud claimed.

"That asymmetry is what attackers are exploiting," said Trevor Hilligoss, SpyCloud's chief intelligence officer. "Every one of these identities is a standing invitation that renews itself until someone notices."

Governance, Blind Spots and Supply Chain Exposure

Elsewhere, the report revealed a mismatch between AI governance and adoption. While nearly all responding organizations said they use AI tools or agents which have access to internal systems, applications, or data, only 56% claimed to have formal processes in place to govern their privileges.

Two-fifths (41%) said they rely on informal processes or partial ownership.

Visibility into identity-related risk was highlighted as a critically important part of maintaining a good security posture, the report also found.

Organizations that had insight into stolen session cookies experienced identity-based events at a significantly lower rate (37%) than those that could not (50%).

Malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%) were the main causes of supply chain identity events, respondents claimed.

However, nearly two-fifths admitted to not having a consistent process in place to confirm third-party identity exposure. That’s despite a third (32%) claiming that they will focus on supply chain risk management over the coming 12-18 months.

Hilligoss argued that organizations can’t afford to leave any part of the attack surface unmanaged.

"Every control that works pushes attackers toward what it doesn't cover. We hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections," he said.

Most Organizations Now Use AI Agents for Sensitive Security Tasks News 14 May 2026

Most Organizations Now Use AI Agents for Sensitive Security Tasks

Crafting Scams with AI: a Devastating New Vector Blog 29 March 2023

Crafting Scams with AI: a Devastating New Vector

SpyCloud Raises $30m in Funding to Tackle Surge in Online Fraud During #COVID19 News 19 August 2020

SpyCloud Raises $30m in Funding to Tackle Surge in Online Fraud During #COVID19

Phishing Dominates EU-Wide Intrusions, says ENISA News 2 October 2025

Phishing Dominates EU-Wide Intrusions, says ENISA

#RSAC Innovation Sandbox Crowns Latest and Greatest New Vendors News Feature 25 February 2020

#RSAC Innovation Sandbox Crowns Latest and Greatest New Vendors

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

NCSC Warns Shadow AI Creates New Security Risks

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

Multiple Class Action Lawsuits Filed Against IDScan

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era

NCSC Warns Shadow AI Creates New Security Risks

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

How to Manage Enterprise Cyber Resilience in the Age of AI

How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

Attack Types (1)

Campaigns (1)

MITRE ATT&CK (1)

Ransomware Groups (1)