TL;DR: More than 80% of breaches now involve identity compromise, with attackers increasingly using account creation, dormant accounts, weak MFA, and machine identities to stay hidden for days or weeks, according to Hydden. The real issue is not login failure, but continuous identity visibility and behavioural detection across human and machine identities.
At a glance
What this is: This analysis argues that identity compromise is now a continuous detection problem, because attackers often hide in account creation, dormant access, MFA abuse and machine identity misuse instead of relying on obvious login failures.
Why it matters: IAM, PAM and NHI teams need behavioural visibility because point-in-time reviews miss the earliest signs of compromise across human accounts, service identities and privileged access paths.
By the numbers:
- More than 80% of breaches now involve some form of identity compromise.
Context
Identity compromise has become a detection problem as much as an access problem. In practice, attackers often blend into normal authentication, privilege and account activity instead of forcing a clear perimeter event, which means traditional IAM and PAM controls can miss the earliest signs.
The article frames the gap as one of continuous visibility. Human accounts, machine identities, MFA changes, privilege shifts and shadow accounts all become part of the same governance surface when attackers use identity behaviour to persist, move and delay detection.
Key questions
Q: What breaks when identity reviews happen only on a fixed schedule?
A: Fixed-schedule reviews miss access that is created, used and abused between review cycles. They also leave orphaned accounts and excessive privileges in place long enough for attackers or rogue automation to exploit them. Continuous validation is needed because identity risk changes faster than quarterly governance can see.
Q: Why do dormant accounts and weak MFA paths increase compromise risk?
A: Dormant accounts often retain valid trust, old permissions or recovery paths that attackers can exploit without raising obvious alarms. Weak MFA fallback paths create similar risk because they give an attacker a lower-friction way to satisfy authentication once credentials are stolen or prompted from the user. Together, they create quiet routes into trusted access.
A: Teams should baseline normal invocation patterns across human and non-human identities, then alert when a token is used by an identity or context it has not previously been paired with. The signal is relational, not just permission-based. A valid credential can still be suspicious if the caller, workload, or device is unfamiliar. This supports earlier detection of misuse and lateral movement.
Q: What should IAM and PAM teams do when identity ownership is unclear?
A: They should treat ownership ambiguity as a governance issue, not an inventory issue. If no one can explain why an account, token or certificate exists and who is responsible for it, that identity should be reviewed for removal, reassignment or PAM control. Unowned identities are prime places for stealthy attacker activity.
Technical breakdown
Why account creation and role changes matter
Attackers frequently create new accounts or alter existing roles to establish persistence and widen access without triggering immediate suspicion. In an identity programme that only checks who exists at a point in time, those changes can look legitimate unless they are correlated with unusual timing, ownership gaps or privilege expansion. The control failure is not just missing alerts. It is the absence of continuous monitoring for identity lifecycle drift, especially when account ownership is unclear or when changes happen outside normal provisioning paths.
Practical implication: watch for out-of-band account creation and role escalation as early persistence indicators.
How dormant accounts and MFA misuse expose compromise
Dormant accounts are attractive because they often carry valid trust, cached permissions or weakly governed recovery paths. MFA abuse follows the same pattern: repeated prompts, fallback methods and downgraded factors can signal theft, phishing or session takeover attempts. These behaviours matter because the attacker is not trying to break authentication in a single moment. They are trying to find the least visible route through a legitimate identity into a trusted session.
Practical implication: treat long-idle accounts and unusual MFA behaviour as compromise signals, not routine noise.
Why machine identities need behavioural governance
Machine identities, including tokens, service accounts and certificates, can outnumber human identities by a wide margin and are often governed with less scrutiny. When one is used from an unexpected location, to access a new system, or with privileges that do not match its declared role, that is a sign of identity abuse rather than simple misconfiguration. Behaviour-based monitoring matters here because static inventory alone cannot show whether the identity is acting within its intended purpose.
Practical implication: baseline machine identity behaviour and flag privilege or access patterns that diverge from role.
Threat narrative
Attacker objective: The attacker wants to remain inside the environment under the cover of trusted identity activity long enough to persist, escalate and complete their mission without detection.
- Entry begins when an attacker obtains a valid identity path through compromised credentials, a created account, or an abused fallback MFA method.
- Escalation follows when the attacker expands privilege through role changes, dormant accounts, service accounts or machine identities with excessive permissions.
- Impact emerges as the attacker stays below the radar for days or weeks, using trusted identity behaviour to persist and operate inside the environment.
Breaches seen in the wild
- Storm-2949 Azure Breach: Storm-2949 social engineering attack turns one cloud identity compromise into full Azure tenant breach.
- Amazon Q Developer extension compromise 2025: An over-scoped CI token let an attacker ship a prompt telling Amazon Q's AI coding agent to wipe files and AWS resources (CVE-2025-8217).
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Continuous identity security is now a detection discipline, not a periodic review exercise. The article shows that attackers are using identity behaviour, not just login events, to remain hidden. That changes the practical meaning of IAM visibility: the control boundary must extend across account creation, factor changes, machine identities and privileged sessions. For practitioners, identity monitoring now belongs in the same operational lane as detection engineering.
Identity ownership gaps are the real governance weak point. The article’s most important signal is not that identities exist, but that many identities cannot be clearly tied to accountable ownership. When cloud admin accounts, local accounts or API tokens sit outside a reliable ownership chain, the programme loses the ability to determine whether a change is expected or malicious. Practitioners should treat ownership ambiguity as a governance defect, not an administrative inconvenience.
Identity blind spots create an identity blast radius. Legacy IAM, static PAM discovery and siloed IGA can produce a false sense of coverage while shadow accounts, orphan identities and unmanaged machine credentials keep expanding the attack surface. That is why continuous discovery is not just inventory hygiene. It is the only way to shrink the blast radius created when attacker activity hides inside normal identity churn.
Behavioural detection must sit above role-based access assumptions. The article makes clear that role models alone do not reveal when an identity is acting inconsistently with its purpose. What matters is identity usage over time, including timing, frequency, device context and resource patterns. For IAM and NHI programmes, the decisive shift is from asking who has access to asking whether that access is being used like it should be used.
Machine identity governance is part of breach detection, not a separate programme. The piece ties together human accounts, machine identities and privileged sessions as one operational problem. That means identity security teams cannot leave service accounts, tokens and certificates in a different governance tier from employee identities. The practical conclusion is that continuous identity security must span all identity types that can be abused for persistence or stealth.
What this signals
Identity visibility has become the deciding control plane for breach detection. Organisations that still rely on periodic access reviews are effectively detecting after the attacker has already adapted. Continuous discovery across accounts, tokens, certificates and privileged sessions is now the minimum viable posture for spotting identity compromise early.
Identity blast radius: when ownership is unclear and discovery is incomplete, every stale account, fallback factor and unmanaged machine credential expands the space an attacker can hide in. The practical consequence is that IAM, PAM and NHI governance can no longer be run as separate queues; they have to be managed as one detection surface.
For practitioners
- Implement continuous identity discovery Replace quarterly visibility checks with continuous discovery across human accounts, machine identities, local accounts and cloud admin paths so new or changed identities surface as they happen.
- Correlate identity and vulnerability signals Join CVE exposure data with identity context so a compromised system can be evaluated for account creation, credential abuse, impersonation and privilege changes at the same time.
- Baseline identity behaviour over time Track frequency, time of access, resource usage and factor changes so the team can detect when an identity starts behaving outside its normal operating pattern.
- Harden MFA fallback paths Remove weak fallback methods where possible, especially SMS and email recovery, and monitor repeated prompts or factor downgrades as compromise indicators.
- Audit shadow and orphan accounts Find identities that cannot be tied to a clear owner or business process, then decide whether they belong under PAM, IGA or removal because visibility without ownership is not governance.
Key takeaways
- Identity compromise now shows up first as subtle changes in account behaviour, not as obvious login failures.
- The article cites more than 80% of breaches as involving identity compromise, which makes visibility into identity activity a core detection requirement.
- Continuous discovery, ownership clarity and behavioural baselines are the controls that matter when attackers use trusted identities to stay hidden.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Orphan and stale identities are a core blind spot in the article's detection model. |
| NHI-05 — Overprivileged NHI | The article flags machine identities with excessive permissions as a hidden compromise signal. | |
| NHI-07 — Long-Lived Secrets | Dormant accounts, tokens and fallback paths become easier to abuse when credentials persist too long. | |
| Recommendation — Continuously remove or reassess identities that no longer have an accountable owner or business purpose. Review machine identity entitlements for privilege creep and revoke access that exceeds the declared role. Shorten credential lifetimes and monitor long-idle identities for unexpected reactivation. | ||
| MITRE ATT&CK | TA0003;TA0004;TA0006 — Persistence; Privilege Escalation; Credential Access | The article describes attackers using identity abuse to persist, escalate and hide after initial compromise. |
| Recommendation — Map identity-compromise telemetry to persistence, privilege escalation and credential-access tactics in detection engineering. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and network services are monitored to detect events | The article argues for continuous monitoring of identity behaviour as a detection requirement. |
| PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article ties early warning to entitlement drift, role changes and privilege misuse. | |
| Recommendation — Extend continuous monitoring to identity events, not just network telemetry, so compromise signals surface earlier. Continuously validate access permissions and entitlements against the identity's actual usage pattern. | ||
Key terms
- Identity compromise: Identity compromise is the abuse of valid credentials, tokens, or delegated access to perform actions as a trusted identity. It is dangerous because it often bypasses perimeter controls and looks like normal activity. In cloud and AI-heavy environments, it is one of the easiest ways to move laterally without obvious alarms.
- Shadow account: A shadow account is an identity used for work that is not managed under normal organisational controls. It may lack approved MFA, monitoring, retention, and revocation processes. In practice, it creates a parallel trust zone where sensitive activity can occur without the same governance applied to corporate identities.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Behavioral Identity Monitoring: Behavioral identity monitoring is the practice of evaluating logins, devices, timing, and access patterns to determine whether an identity is acting as expected. It is useful when credentials alone are no longer enough to prove legitimacy, especially for vendors, contractors, and remote users.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org