Non-Human Identities Overtake Phishing as Top Enterprise Attack Vector
Share
Non-human identities (NHIs), including AI agents, service accounts, and API keys, have become the primary entry point for attackers targeting enterprises. According to the SpyCloud 2026 Identity Threat Report, compromised NHIs account for 31% of identity-based breaches, nearly double the 17% rate attributed to phishing and social engineering.
While organisations typically maintain strict inventories of their human workforce, many fail to extend that same oversight to the machine identities that connect to their internal systems. This lack of visibility creates a significant security gap. Although 95% of organisations believe they have adequate visibility into AI and machine identity exposures, only 36% are actively monitoring them.
The Risk of Unmanaged Machine Identities
NHIs present a unique challenge for security teams because they are often provisioned for convenience and hold high levels of privilege. Unlike human employees, service accounts do not undergo standard off-boarding processes, cannot complete multi-factor authentication (MFA) challenges, and rarely rotate their own credentials. Once an NHI is exposed, it can remain usable by an attacker for months.
Trevor Hilligoss, Chief Intelligence Officer at SpyCloud, noted that attackers are specifically exploiting this asymmetry. As organisations harden defences around human accounts and passwords, threat actors are shifting their focus toward service accounts and vendor connections.
AI Adoption Outpaces Governance
The rapid integration of artificial intelligence is further complicating the identity landscape. The report finds that 91% of organisations now use AI tools or agents that have access to internal applications and data. However, only 56% of these organisations have established formal governance or ownership for the privileges these AI tools hold.
This lack of oversight has resulted in “shadow access,” where privileged connections operate outside of normal monitoring and governance frameworks. Another 41% of organisations rely on informal processes, leaving a substantial portion of their AI-driven infrastructure unmonitored.
Session Hijacking and Supply Chain Vulnerabilities
Attackers are also increasingly bypassing traditional authentication controls by targeting session data. Session cookies and tokens allow attackers to resume already-authenticated sessions, effectively circumventing MFA. Organisations with visibility into stolen session cookies experienced identity-based events at a rate of 37%, whereas those without visibility saw event rates as high as 50%.
Supply chain risks remain a significant factor, with malware-infected third-party devices and exposed API keys involving vendors and partners cited as the leading causes of identity-related supply chain events. Nearly 40% of organisations reported having no consistent process to confirm whether a third-party identity exposure had been successfully resolved.
The report suggests that the most resilient programmes are moving away from manual, case-by-case remediation. Organisations that utilise high levels of automation reported lower incident response costs and a reduced loss of customer trust compared to those relying on manual processes.




Leave a Reply