"Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them." — Ashley D’Andrea, Content Writer at Keeper Security
What fabricated machine identities are and why they matter
The article describes a machine-side analogue to synthetic identity fraud: fabricated Non-Human Identities (NHIs) that were never legitimately provisioned but are accepted by an environment as if they were real. Rather than hijacking an existing service account, an attacker can create a new account that blends real environmental attributes with invented ones. Because the fabricated identity has no real human owner, there is nobody to notice unusual logins, leaked credentials, or other alerts that typically reveal stolen accounts. As NHIs proliferate faster than organizations can track them, a fabricated identity can “slip into the mix” and quietly accumulate privileges.
How fabricated machine identities are built: rogue accounts, DCShadow, and shadow credentials
The source outlines three concrete techniques attackers use to establish illegitimate machine identities. A “rogue service account” is created by an intruder who registers an account that mirrors legitimate naming conventions and holds standing access. DCShadow operates at the infrastructure level: an attacker with domain administrator rights temporarily registers a rogue domain controller so malicious changes look like legitimate replication traffic from a trusted peer. “Shadow credentials” are implanted authentication material added to an existing object so the attacker can authenticate as that object at will. Though the mechanics differ, each method yields an illegitimate identity that the environment has accepted as one of its own.
Why these identities evade existing defences
Fabricated NHIs succeed in large part because they are constructed to look convincing. They inherit naming conventions, exist in the correct domain, carry plausible metadata and request the same permissions other NHIs hold. The article emphasizes that most organizations concentrate on stolen credentials, which raise alarms tied to a real owner; fabricated identities trigger none of those owner-centric signals. If an administrator is “skimming a directory of tens of thousands of service accounts,” a convincing fake looks like routine workload — and without human ownership it may not be noticed as an outlier.
Agentic AI: lowering the friction to fabricate identities
The piece warns that agentic AI is making fabrication easier. Where previously attackers had to manually create fake accounts and assign privileges, AI agents already acquire credentials dynamically at runtime and increasingly can spin up other agents. As machine identity creation becomes an automated background activity, the boundary between a legitimately created identity and a fabricated one “begins to blur.” The implication is clear: automated agents can scale identity creation and reduce the manual work an attacker needs to insert illegitimate NHIs into an environment.
Practical defenses: ownership, secrets, least privilege, and continuous verification
The recommended defenses focus on governance and changing where trust is placed. Every NHI should have a registered human owner, a documented purpose and an expiration date so identities cannot remain permanent by default. Centralized secrets management with automated rotation is advised to prevent attackers from anchoring access via implanted “shadow credentials.” Enforcing least privilege and Just-in-Time (JIT) access reduces what any identity — real or fake — can reach and for how long. Finally, continuous verification of behavior moves trust from one-time provisioning checks to ongoing assessment of what an identity actually does; that makes it easier to surface identities that were convincing at creation but behave abnormally over time. The article points to an identity security platform like KeeperPAM® as a tool for managing ownership, secrets and privileged access.
What this means for security teams, enterprise IT leaders, and adversaries
- Security teams and technologists: Expect to extend identity hygiene beyond credential protection to inventory and ownership controls. They must track who owns each NHI, enforce short-lived secrets and implement behavioral monitoring so illegitimate identities can be detected after provisioning.
- Enterprise IT and procurement leaders: Governance choices matter. Systems that permit indefinite service accounts, decentralized secret handling, or broad standing privileges create fertile ground for fabricated NHIs; procurement decisions for identity platforms and secrets rotation tooling will shape exposure.
- Adversaries and threat actors: The guidance signals that automated account creation and agentic workflows reduce the manual cost of inserting fabricated identities — actors seeking persistence may favor techniques that mimic environment conventions to blend into large NHI populations.
Fabricated machine identities are not a new toolbox of techniques so much as a new lens on a stubborn gap: organizations assume every identity in their environment belongs there. The article concludes that closing that gap requires human ownership, short-lived secrets, least privilege and continuous behavioral verification — steps designed to ensure nothing can quietly accumulate access. For defenders who accept that premise, platforms that manage ownership, secrets and privileged access become central instruments for preventing the most dangerous fakes from ever taking root.
https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html




