TL;DR: December 2025 incidents showed that valid credentials, tokens, and service accounts let attackers bypass perimeter controls, persist quietly, and monetize later across supply chain, insider, and ransomware cases, according to Delinea Labs’ January 2026 threat outlook. Static authentication assumptions are failing because trusted access now behaves like attack infrastructure, not a one-time check.
At a glance
What this is: This is Delinea’s January 2026 threat outlook on December 2025 identity-driven attacks, showing that valid credentials, tokens, and service accounts were the entry point in multiple incidents.
Why it matters: IAM, PAM, and NHI teams should treat authentication, offboarding, and session control as continuous governance problems because trusted identities are now a primary attack path.
Context
December 2025 reinforced a basic identity-security problem: attackers no longer need novel exploits when valid credentials, tokens, or service accounts already exist. In practice, authentication became the entry point, and once access looked legitimate, perimeter controls lost much of their value.
For IAM and NHI programmes, the issue is not only credential theft. It is the way trusted identities, especially orphaned employee access, developer tokens, and automation accounts, can remain active long enough to be reused quietly across production systems and downstream services.
Key questions
Q: What breaks when attackers find credentials after initial access?
A: The breach stops being about the first entry point and becomes about reachable privilege. Once a password, key, or token is copied, the attacker can often move from a low-value foothold to production systems, data stores, or internal infrastructure. That is why secrets exposure changes the severity of an incident so quickly.
Q: Why do service accounts and tokens create more risk than many teams expect?
A: Because they often carry standing privilege, operate quietly, and remain valid long after the business need changes. That combination increases blast radius when a credential is exposed and makes detection harder than with human accounts. The risk is not the token itself. It is the duration and breadth of access it enables.
Q: How do teams know if identity security controls are actually working?
A: Identity security controls are working when teams can show a current view of high-risk entitlements, detect privilege drift quickly, and remove access before exposure spreads. A useful sign is reduced time between entitlement change and policy review. Another is fewer unresolved conflicts between approved access and actual production permissions.
Q: What is the difference between authenticating a user and governing a session?
A: Authentication answers whether the identity can prove who it is at a point in time. Session governance answers whether that access should continue, what it can reach, and whether the activity still matches the intended scope. In this threat pattern, the second control is what limits damage after credentials are stolen.
Technical breakdown
Why valid credentials are more dangerous than initial exploitation
Credential theft changes the attack problem from breaking in to using what already works. Once an attacker has a valid token, password, or service account, many control layers treat the session as legitimate unless there is behavioural analysis, scope validation, or lifecycle enforcement. That is why credentials become durable attack infrastructure: they survive the initial compromise and can be reused later in supply chain abuse, insider misuse, or ransomware staging. In these cases, the control failure is often not authentication itself, but the assumption that successful authentication means trusted usage.
Practical implication: monitor authenticated behaviour, not just login success, because legitimate access can be weaponised long after the original theft.
Why service accounts and OAuth-style grants evade human-centric controls
Service accounts, CI/CD identities, and third-party SaaS grants often bypass MFA and do not generate the same alerts as interactive users. That creates a visibility gap because the identity subject is not a person, but the access path still reaches production tooling, APIs, and distribution channels. If those identities are not inventoried, scoped, and lifecycle-managed, they can become low-noise entry points that blend into automation traffic. The article’s examples show that the issue is not simply compromise, but trust in non-interactive access paths that persist outside human review cycles.
Practical implication: place automation identities under the same ownership, review, and revocation discipline as employee accounts.
How authentication flaws magnify stolen-credential risk
Identity attacks do not stop at the stolen secret. Validation logic, federation flows, token verification, and authorization boundaries determine how far an attacker can move once they authenticate. A weak OTP integration, a forged JWT acceptance path, or exposed service-account tokens can turn a single credential event into broader compromise. This is why credential theft and identity-product flaws compound each other: one supplies access, the other removes friction on the path to abuse. In a mature programme, authentication controls and session controls have to be evaluated together, not as separate risk domains.
Practical implication: test federation, token validation, and service-account handling as part of the same identity attack surface, not as isolated control owners.
Threat narrative
Attacker objective: The attacker objective is to use trusted identity paths to reach production systems, avoid detection, and monetise access through theft, malware delivery, or ransomware.
- Entry began with stolen credentials, tokens, or service accounts that let attackers authenticate as trusted identities without needing new exploits.
- Escalation followed when those identities were reused through production systems, distribution channels, or internal tooling with little friction and weak behavioural detection.
- Impact emerged later through data theft, malicious updates, lateral movement, or ransomware monetisation after the access had already blended into normal operations.
Breaches seen in the wild
- Mailchimp breach 2022: Attackers socially engineered Mailchimp staff, used a support tool to export 102 customer lists and exposed customer API keys for phishing.
- Codefinger S3 ransomware 2025: Codefinger used victims' compromised AWS keys to re-encrypt S3 buckets with SSE-C, set 7-day deletion and demanded ransom for the key.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Authentication has shifted from a gate to an attack surface: the old assumption was that successful login signified legitimate use, but December’s incidents show that authentication can now be the attacker’s operating environment. Once valid credentials are stolen, many security stacks still treat the session as trusted until after damage is done. Practitioners should therefore evaluate identity controls by what happens after authentication, not by whether authentication succeeded.
Credential reuse creates identity blast radius: a stolen token, service account, or orphaned employee identity rarely stays confined to a single system. It can span source control, distribution channels, automation, and downstream production access, which is why identity compromise often becomes a chain of later abuses rather than a single event. The field needs to treat identity scope as the containment boundary, not the username itself.
Service accounts are now governance assets, not just technical plumbing: the article’s pattern is that automation identities can quietly bypass human-centric monitoring while still carrying meaningful production privilege. That means ownership, offboarding, and review discipline must extend to non-human identities with the same seriousness as employee access. Practitioners who still separate machine identity governance from IAM are leaving a visible control gap.
Delayed monetisation is the defining feature of modern credential theft: attackers increasingly authenticate early, stay quiet, and weaponise access later, which makes dwell time an identity-governance issue as much as a detection problem. Delayed credential monetisation: stolen access now behaves like inventory that can be cashed out when conditions are best, not when compromise is first detected. Security teams should assume the loss is already operational before the alert arrives.
Identity controls have to move from point-in-time approval to continuous trust management: the month’s incidents show that authentication, authorization, and session validity are now inseparable from lifecycle governance. If credentials can be reused long after issuance, then static trust decisions are structurally weak. Practitioners should design around ongoing verification, not around the moment of login.
What this signals
Delayed credential monetisation: the operational lesson is that identity compromise is often discovered after the access has already been reused elsewhere. For practitioners, that means review cadences, revocation speed, and behavioural telemetry matter more than any single authentication event.
Identity governance now has to account for stolen secrets moving across human, machine, and third-party contexts. When offboarding, rotation, and session validation are treated as separate workstreams, attackers can keep using the gap between them.
The strongest control signal is whether a revoked identity can still authenticate anywhere in the estate. If the answer is yes, the programme is managing accounts, not trust.
For practitioners
- Audit orphaned and stale access Identify employee, contractor, and former-worker accounts that still have production access, then confirm whether revocation actually removed every token, grant, and downstream session.
- Inventory non-human identities end to end Build a single inventory for service accounts, CI/CD identities, OAuth grants, and application tokens so ownership, scope, and expiry are visible in one place.
- Correlate authenticated behaviour across identity types Use detection logic that links user, token, and service-account activity so a legitimate login followed by unusual distribution, publishing, or lateral movement is visible.
- Shorten the useful life of privileged credentials Reduce standing access, tighten scope, and force re-validation for privileged and automation identities that can reach production systems or release channels.
- Test federation and token validation paths Review OTP, JWT, federation, and API-authentication flows for bypass conditions that let a stolen secret become broader access than intended.
Key takeaways
- Valid credentials are now a primary attack path, which means authentication success no longer proves legitimate intent.
- The incidents described in the article show how long-lived access can persist quietly across user, token, and service-account identities before defenders notice.
- Identity programmes need faster offboarding, tighter scope control, and continuous monitoring of authenticated behaviour to limit the blast radius of stolen access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article highlights a former employee whose access was never revoked, creating a long-lived backdoor. |
| NHI-04 — Insecure Authentication | Stolen credentials, tokens, and federation flaws are the article’s central attack path. | |
| NHI-07 — Long-Lived Secrets | The piece shows how long-lived tokens and service accounts let attackers operate quietly for extended periods. | |
| Recommendation — Track offboarding completeness for every identity type and revoke all access paths when employment or ownership changes. Harden authentication flows so stolen or forged credentials cannot be reused as trusted access. Reduce secret lifespan and remove standing validity from credentials that can reach production systems. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article centers on credential lifecycle, token reuse, and the need for stronger authenticator governance. |
| Recommendation — Apply authenticator lifecycle controls to rotate, revoke, and validate credentials continuously. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article shows that access scope and authorization boundaries determine how far stolen identities can move. |
| Recommendation — Review and reduce entitlements so authenticated access cannot spread beyond intended boundaries. | ||
| CIS Controls v8 | CIS-5 — Account Management | Orphaned accounts and delayed revocation are a recurring failure mode in the incidents discussed. |
| Recommendation — Manage account lifecycle tightly and remove inactive or departed-user access from every environment. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes stolen credentials used for authenticated access, persistence, and movement across systems. |
| Recommendation — Map credential-theft patterns to credential access and lateral movement tactics in detection and hunting. | ||
Key terms
- Credential Monetisation: The reuse of stolen credentials, tokens, or service accounts to create operational value for an attacker. In practice, monetisation may mean data theft, malware delivery, ransomware staging, or supply chain abuse after the initial authentication event has already blended into normal traffic.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Orphaned Access: Orphaned access is credentialed access that still works even though no clear business owner can justify or manage it. It usually appears after system changes, reorganisations, or integrations, and it is especially dangerous because it can remain active long after the original purpose has disappeared.
- Authenticator Lifecycle Management: Authenticator lifecycle management is the governance of a credential from issuance to renewal, replacement, and retirement. For human identity programmes, it ensures that keys, smart cards, and certificates stay tied to the right user and are removed when the user, role, or device is no longer trusted.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org