"That asymmetry is what attackers are exploiting," said Trevor Hilligoss, SpyCloud's chief intelligence officer.
Non-human identities (NHIs) now lead corporate intrusions
A new SpyCloud survey of 750 cybersecurity leaders and practitioners at organizations with 500+ employees in North America, the UK, Spain, Germany, the Netherlands, Austria and Switzerland found that compromised non-human identities (NHIs) — including AI agents, service accounts, API keys and authentication tokens — were cited as the primary entry point in 31% of intrusions. By contrast, social engineering and phishing were named as the primary vector in 17% of incidents.
The report frames NHIs as a growing and distinct category of identity risk: machine identities frequently hold elevated privileges, are not routinely offboarded, and related credentials are often not rotated, creating persistent access that “renews itself until someone notices,” the report notes.
Visibility — believed versus practiced
Most organizations surveyed (95%) said they believe they have adequate visibility into NHIs, yet only 36% actually monitor them. SpyCloud characterizes machine identities as the least-watched category of identity risk studied. That gap between confidence and operational monitoring is central to the report’s thesis: perceived visibility does not equal true control.
SpyCloud quantified the payoff for genuine visibility: organizations that could detect stolen session cookies experienced identity-based events at a significantly lower rate (37%) than organizations that could not (50%).

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAI agents and governance gaps
Nearly all respondents reported using AI tools or agents with access to internal systems, applications, or data. Yet only 56% said they have formal processes to govern those privileges; two-fifths (41%) rely on informal processes or partial ownership. That mismatch between adoption and governance elevates NHIs as a policy and operational problem, according to the study.
Supply chain identity exposure: devices and API keys
Supply chain identity events were attributed mainly to malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%). Despite that exposure, nearly two-fifths of respondents admitted they do not have a consistent process to confirm third-party identity exposure. A third (32%) of organizations said they will focus on supply chain risk management over the coming 12–18 months.
What this means for technologists, procurement leaders, and security teams
- Technologists and security teams: expect the report’s data to prioritize monitoring and rotation practices for service accounts, API keys and tokens, and to place stolen session visibility high on detection priorities — the survey links that visibility to a lower rate of identity events.
- Procurement leaders: vendor and partner application access and exposed API credentials were named causes of supply chain identity events (22%), a metric that underlines a need for consistent third‑party validation processes when buying or integrating services.
- Security operations and governance owners: nearly all organizations use AI agents that touch internal resources but only 56% have formal privilege-governance processes; that gap points to governance as a concrete control to close.
SpyCloud’s chief intelligence officer framed the shift as a predictable consequence of defenders hardening one set of controls and attackers probing another: "Every control that works pushes attackers toward what it doesn't cover. We hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections," he said. The data in the report ties that observation to measurable outcomes: high levels of NHI misuse (42% of respondents reported NHI-related misuse) and a majority (68%) reporting an identity-based event during the reporting period.
The report’s central finding is stark and specific: NHIs are not a future problem — they are now the leading corporate entry point measured in this survey — and many organizations still lack the continuous controls needed to detect and remediate misuse. Whether through monitoring stolen sessions, enforcing credential rotation, or formalizing governance for AI-enabled agents, the choices organizations make in the next 12–18 months will determine whether that standing invitation becomes an active breach vector or a managed risk.
https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/




