Council Post: How The Most Dangerous Identities In Your Enterprise Aren’t Human
Damon Fleury is the Chief Product Officer of SpyCloud, a leader in identity threat protection.

getty
Last year, attackers stole OAuth tokens from a vendor integration and used them to access the Salesforce environments of more than 700 companies. Once inside, they harvested additional credentials—including embedded API keys, AWS access keys and Snowflake tokens buried in support tickets, integrations and internal notes—allowing them to access multiple systems.
Such an attack exposed a deeper issue. Identity has quickly become the dominant attack vector in modern environments with exposed credentials no longer just being tied directly to a person. Last year alone, we recaptured nearly 24 million exposed API keys, tokens and credentials and authentication tokens spanning payment platforms, cloud infrastructure providers, developer ecosystems, collaboration tools and AI services.
This shift to non-human identities (NHIs), a digital credential that authenticates and accesses resources without direct human involvement, demands a fundamental reassessment in how organizations approach cybersecurity. Organizations must not only work to secure their users but also understand and control the NHIs that connect them to vendors, partners and the broader digital ecosystem.
An Outdated Approach To Security
Most cybersecurity programs were built for a different era: one where identities were human, access was interactive and risk could be managed through authentication events like logins. But those ramifications no longer hold. Today’s cyber environments are dynamic, API-driven and highly automated. Systems don’t just exchange data; they authenticate into each other continuously, often without any human involvement. And the identities enabling that access are overwhelmingly non-human.
Every application, integration and workflow introduces new credentials: API keys embedded in code, OAuth tokens granted to services and service accounts powering automation across systems. These identities are designed to keep operations running smoothly and efficiently—but in doing so, they also expand the attack surface.
What makes NHIs particularly risky isn’t just their scale, but how they operate. They are often provisioned with broad permissions to avoid detection. They often have longer periods of persistence and once deployed, they are rarely visible. At the same time, they lack many of the safeguards applied to human users.
There’s no multi-factor authentication prompt. No behavioral friction when something looks unusual. In many cases, possession of the credential alone is enough to gain access. If an attacker has an API key, they can access the system—often with no additional verification required.
Can’t Secure What You Can’t See
The challenge isn’t just that NHIs exist; it’s that most organizations don’t have any visibility into them. Unlike human users, which are typically managed through centralized identity providers, NHIs are created and managed across disparate systems. Development teams generate API keys, DevOps pipelines create service accounts and SaaS platforms issue OAuth tokens. Each system maintains its own view, with little coordination (or governance) across the environment.
The result is fragmentation. In many organizations, there is not a single inventory of non-human identities. At best, there are partial lists maintained by individual teams: spreadsheets, configuration files or application-level records that quickly become outdated; this lack of visibility, and thus management, makes it difficult to answer even basic questions:
• What machine identities exist across the environment?
• What access do they have?
• Which vendors are using them—and how?
Without those answers, it’s nearly impossible to assess risk, let alone contain it.
What Needs To Change
Addressing this challenge requires a shift in how organizations think about identity and access. The first step is visibility. Organizations need a comprehensive inventory of non-human identities across cloud, on-premises and third-party environments. Without that baseline, risk cannot be effectively managed.
From there, governance becomes critical. Every NHI should have a defined owner, a clear purpose and a lifecycle, from creation to rotation to decommissioning. Access also needs to be re-evaluated. Many NHIs are overprivileged by default, and reducing permissions to the minimum necessary can significantly limit potential impact.
Technical controls can further reduce risk. Binding credentials to specific systems or environments—such as restricting API keys to known IP ranges—can prevent their misuse if they are exposed. Continuous monitoring of behavior is also critical to detecting anomalies, such as unexpected spikes in access or usage patterns that deviate from the norm.
This approach has already proven effective. In the aforementioned breach, some organizations avoided impact by constraining how their OAuth tokens could be used—for example, limiting them to specific IP ranges or trusted systems. Even when credentials were stolen, they couldn’t be reused outside their intended environment.
Additionally, it is important to monitor the criminal underground for threats, such as malware infections, that also happen to harvest critical API keys that connect to your users. These API Keys may be assigned to NHI’s that are managed directly by your user. Understanding which API’s are in the hands of bad actors can allow you to respond and remediate before the next attack can occur.
The Bottom Line
The rise of automation, cloud services and AI-driven tools has fundamentally changed how systems interact and how attackers gain access. Non-human identities are now central to that shift. They enable the speed and scale of modern business operations. But they also introduce a new class of threats: one that is often invisible, highly privileged and increasingly targeted.
The implication is clear. Securing human users is no longer enough. The next phase of identity security will be defined by how well organizations understand, manage and protect the non-human identities operating across their environments and across their vendor ecosystems.
In today’s threat landscape, the easiest way in isn’t only through your people. It’s also through your machines.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?