Compromised Non-Human Identities Pose Significant Threat to Enterprises: A Study by SpyCloud
In a recently released study, SpyCloud—a company specializing in threat protection—has uncovered alarming data regarding compromised non-human identities (NHIs), including AI agents, which serve as critical entry points for cyberattacks. The findings reveal that NHIs are almost twice as likely to be the primary vector of intrusion into enterprises compared to traditional phishing methods.
The insights are drawn from the SpyCloud Identity Threat Report, which analyzed the responses of 750 cybersecurity leaders and practitioners from organizations with over 500 employees across several countries: North America, the UK, Spain, Germany, the Netherlands, Austria, and Switzerland. The study indicates a substantial shift in the landscape of cyber threats, with NHIs accounting for a significant 31% of all intrusions. In comparison, social engineering methods—including phishing—are responsible for 17% of such attacks.
Despite the evident risks, the report highlights a troubling discrepancy: while 95% of organizations believe they possess adequate visibility into their NHIs, only 36% actively monitor these identities. This stark gap indicates that machine identities have become the least scrutinized component of identity risk, leaving organizations vulnerable to exploitation.
Notably, the report found that 68% of respondents experienced an identity-based event within the reporting period, with 42% of those incidents linked specifically to NHIs. These identities often have elevated privileges, yet many do not undergo proper offboarding when no longer needed, and associated credentials typically remain unchanged. SpyCloud’s Chief Intelligence Officer, Trevor Hilligoss, emphasized the severe implications of this lapse, asserting, "That asymmetry is what attackers are exploiting. Every one of these identities is a standing invitation that renews itself until someone notices."
Governance Challenges and Visibility Gaps
The report further sheds light on governance issues surrounding AI and NHIs. It finds a notable disconnection between the adoption of AI technologies and the governance measures implemented to oversee them. Almost all responding organizations indicated they employ AI tools or agents with access to sensitive internal systems, data, or applications. Yet, only 56% of organizations reported having formalized protocols to regulate these privileges effectively. Alarmingly, 41% rely solely on informal processes or share partial ownership of the responsibility.
The study underscores the importance of maintaining visibility into identity-related risks as a fundamental aspect of robust security practices. Organizations demonstrating insight into stolen session cookies encountered identity-based events at a considerably lower rate of 37%, compared to 50% for those lacking such visibility. This suggests that enhanced monitoring and awareness can significantly mitigate risks.
The supply chain also surfaces as a critical area of vulnerability, with 23% of respondents citing malware-infected third-party devices as significant contributors to identity-related incidents. Furthermore, 22% indicated that exposed API keys or unauthorized access via vendors and partners were prevalent issues. This reliance on third parties can create additional complexities, as nearly two-fifths of organizations admitted to having no consistent strategy to verify third-party identity exposures. This lack of diligence contrasts sharply with the 32% of respondents who reported an intention to focus on supply chain risk management within the next 12 to 18 months.
Hilligoss cautioned organizations against neglecting any aspect of their attack surface. He explained, "Every control that works pushes attackers toward what it doesn’t cover. We hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections."
Conclusion
In conclusion, the findings of SpyCloud’s Identity Threat Report expose significant vulnerabilities within organizations regarding non-human identities. As NHIs become increasingly prevalent in cyber intrusions, the need for comprehensive monitoring and robust governance measures cannot be overstated. Organizations must bridge the gap between perception and reality, ensuring they have the necessary visibility and processes in place to protect against this evolving threat landscape. Without such measures, they risk inviting future incidents that could compromise both data integrity and organizational trust. SpyCloud’s critical insights serve as a wake-up call for enterprises to reevaluate their security practices, particularly as AI technologies continue to play a more significant role in the modern workplace.

