Back Infosecurity-Magazine NHIs Now the Number One Corporate Entry Point for Hackers
Compromised non-human identities (NHIs) including AI agents are nearly twice as likely to be a primary entry point into the enterprise than phishing, a new study from SpyCloud has claimed.
The threat protection firm’s SpyCloud Identity Threat Report is based on a survey of 750 cybersecurity leaders and practitioners at organizations with 500+ employees in North America the UK, Spain, Germany, the Netherlands, Austria and Switzerland.
It revealed that NHIs such as AI agents, service accounts, API keys and authentication tokens accounted for 31% of intrusions, versus 17% for social engineering.
The findings are particularly concerning given that, while most (95%) organizations think they have adequate visibility into NHIs, only 36% actually monitor them. SpyCloud said this makes machine identities the least-watched category of identity risk studied.
Some 68% of respondents said they suffered an identity-based event in the reporting period, with NHI-related misuse at 42%.
While NHIs are often granted elevated privileges, they frequently don’t get offboarded, and related credentials aren’t rotated, making them a persistent security risk, SpyCloud claimed.
"That asymmetry is what attackers are exploiting," said Trevor Hilligoss, SpyCloud's chief intelligence officer. "Every one of these identities is a standing invitation that renews itself until someone notices."
Governance, Blind Spots and Supply Chain Exposure
Elsewhere, the report revealed a mismatch between AI governance and adoption. While nearly all responding organizations said they use AI tools or agents which have access to internal systems, applications, or data, only 56% claimed to have formal processes in place to govern their privileges.
Two-fifths (41%) said they rely on informal processes or partial ownership.
Visibility into identity-related risk was highlighted as a critically important part of maintaining a good security posture, the report also found.
Organizations that had insight into stolen session cookies experienced identity-based events at a significantly lower rate (37%) than those that could not (50%).
Malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%) were the main causes of supply chain identity events, respondents claimed.
However, nearly two-fifths admitted to not having a consistent process in place to confirm third-party identity exposure. That’s despite a third (32%) claiming that they will focus on supply chain risk management over the coming 12-18 months.
Hilligoss argued that organizations can’t afford to leave any part of the attack surface unmanaged.
"Every control that works pushes attackers toward what it doesn't cover. We hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections," he said.
Most Organizations Now Use AI Agents for Sensitive Security Tasks News 14 May 2026
Most Organizations Now Use AI Agents for Sensitive Security Tasks
Crafting Scams with AI: a Devastating New Vector Blog 29 March 2023
Crafting Scams with AI: a Devastating New Vector
SpyCloud Raises $30m in Funding to Tackle Surge in Online Fraud During #COVID19 News 19 August 2020
SpyCloud Raises $30m in Funding to Tackle Surge in Online Fraud During #COVID19
Phishing Dominates EU-Wide Intrusions, says ENISA News 2 October 2025
Phishing Dominates EU-Wide Intrusions, says ENISA
#RSAC Innovation Sandbox Crowns Latest and Greatest New Vendors News Feature 25 February 2020
#RSAC Innovation Sandbox Crowns Latest and Greatest New Vendors
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
NCSC Warns Shadow AI Creates New Security Risks
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
Multiple Class Action Lawsuits Filed Against IDScan
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
NCSC Warns Shadow AI Creates New Security Risks
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How to Manage Enterprise Cyber Resilience in the Age of AI
How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
