By NHI Mgmt Group Editorial TeamBased on Delinea: “Identity attacks are evolving faster than defenders can adapt” (December 18, 2025)

TL;DR: Attackers are increasingly using legitimate credentials, tokens, service accounts and SaaS integrations to move through environments instead of breaking in, according to Delinea Labs December 2025 Threat Outlook. The security problem is no longer authentication alone, but the trust assumptions embedded in identity, automation and federation controls.


At a glance

What this is: Delinea's December 2025 threat outlook argues that identity attacks are shifting from intrusion to abuse of legitimate authentication, automation and federation paths.

Why it matters: IAM, PAM and NHI teams need to treat trusted identity pathways as attack surfaces, because credentials, service accounts and provisioning flows are now being used to move laterally and accelerate compromise.


Context

Identity attack patterns now matter because defenders often still treat authentication as a gate rather than an attack surface. When attackers can reuse valid credentials, tokens, service accounts, SCIM provisioning flows and SaaS integrations, traditional perimeter assumptions no longer hold.

The article frames this as a governance problem across human and machine identity. The issue is not simply stolen passwords, but the trust relationships embedded in identity systems, automation workflows and federation chains.

That makes this a control-design issue for IAM, PAM and NHI programmes rather than a narrow detection problem. The article's examples show a pattern that is already visible in production environments, not a future-state concern.


Key questions

Q: What fails when attackers can use legitimate identity pathways instead of breaking in?

A: What fails is the assumption that successful authentication means trusted access. When attackers reuse tokens, service accounts or federation flows, the organisation loses the ability to separate normal identity activity from hostile use. The control failure is not login itself, but the lack of context about intent, purpose and downstream reach.

Q: Why do service accounts and tokens create more risk than many teams expect?

A: Because they often carry standing privilege, operate quietly, and remain valid long after the business need changes. That combination increases blast radius when a credential is exposed and makes detection harder than with human accounts. The risk is not the token itself. It is the duration and breadth of access it enables.

Q: What are the signs that identity-driven attacks are already underway?

A: Common signs include impossible travel, privilege misuse, dormant accounts suddenly becoming active, and suspicious credential use by identities that normally do little. Security teams should also watch for lateral movement patterns and activity that fits a valid account but not its usual baseline. The key signal is not just abnormal login behavior, but identity activity that is technically allowed yet operationally unexpected.

Q: How should teams respond when automation credentials are treated as trusted access?

A: They should treat automation credentials as high-value privilege, not as background infrastructure. That means limiting scope, removing standing access where possible, verifying federation and provisioning chains, and ensuring the same identity cannot move across environments without oversight. The goal is to shrink the blast radius before compromise becomes lateral movement.


Technical breakdown

Why legitimate authentication paths become attack paths

Attackers do not need to bypass authentication if they can reuse the organisation's own identity pathways. Tokens, service accounts, SCIM provisioning and SaaS integrations create trusted execution paths that look normal to identity systems but still permit movement, privilege gain and data access. The security failure is that authentication success is treated as safety, even when authorisation context, session purpose and downstream trust have not been verified. In practice, identity becomes the medium of intrusion, not the barrier.

Practical implication: review every trusted identity path as a potential ingress route, not just a login mechanism.

How automation secrets and SCIM flows widen exposure

Automation credentials are attractive because they are often unattended, long-lived and reused across tools and pipelines. When CI tokens, cloud keys or automation secrets are exposed, an attacker can sign into developer tools, abuse provisioning flows, or inherit access that was never meant for interactive use. SCIM increases the blast radius when provisioning logic grants access faster than governance can validate it. The result is that machine-driven access can become more dependable for attackers than human accounts.

Practical implication: constrain provisioning and automation credentials to the narrowest possible scope and lifecycle.

Why machine-speed intrusion breaks human-paced defence

The article's AI-assisted espionage example shows how recon, credential harvesting, privilege escalation and lateral movement can compress into hours when an adversary uses AI to orchestrate the sequence. That matters because many detection and review models still assume time for investigation, certification and manual escalation. Once an attacker can chain identity actions at machine speed, the control plane has to notice behaviour, not just events. Identity telemetry and session analysis become more important than static account checks.

Practical implication: shift monitoring from periodic account review to continuous identity behaviour detection.


Threat narrative

Attacker objective: The attacker seeks to reuse trusted identity pathways to reach privileged access, move laterally and complete compromise without triggering traditional intrusion signals.

  1. Entry occurs through legitimate authentication paths, including tokens, service accounts, SCIM flows and SaaS integrations rather than exploit-based intrusion.
  2. Credential access is achieved through theft of CI tokens, cloud keys and automation secrets, which then provide trusted reuse across tools and environments.
  3. Escalation and lateral movement follow when those identities are accepted by downstream systems, enabling privilege gain and pivoting at machine speed.
  4. Impact is delivered through deep environment access, supply chain propagation and accelerated espionage operations that outpace human response cycles.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Authentication without authorization is now the dominant identity failure mode. The article shows attackers succeeding by using systems exactly as intended, which means successful login can no longer be treated as evidence of legitimate intent. That breaks the long-standing assumption that identity proof and access legitimacy move together. Practitioners should re-evaluate trust boundaries inside authentication flows, not just the strength of the login step.

Standing trust in automation is becoming a liability. SCIM connectors, SaaS integrations and unattended service accounts are only safe when their authority is tightly bounded and continuously reviewed. Once they are allowed to persist, they become reusable attacker infrastructure with a lower noise profile than interactive accounts. The practitioner conclusion is simple: automation trust has to be governed as aggressively as privileged human access.

Machine-speed intrusion collapses human review assumptions. Access review processes and manual escalation paths were designed for dwell time, not for attacks that harvest credentials, escalate privileges and pivot in hours. That means the issue is not merely faster attackers, but a broken operating assumption about how long identity risk remains observable. Security teams need identity controls that act at issuance and session time, because post-event review is arriving too late.

Identity blast radius now spans human and machine estates together. The article links developer credentials, service accounts, VPN logins, admin accounts and federated systems into one attack surface. That makes compartmentalisation the central governance question for both NHI and workforce identity programmes. The practical conclusion is that boundary design, not isolated account hygiene, now determines whether an identity incident becomes an enterprise event.

Identity attack telemetry is becoming a control plane requirement. If the same credentials can unlock multiple tools, then session behaviour, provisioning anomalies and reuse patterns are the most valuable signals. This aligns with OWASP-NHI, NIST CSF and Zero Trust thinking, but the deeper point is governance: organisations need evidence about who or what is acting, not just that authentication succeeded. Practitioners should treat identity telemetry as operational security infrastructure, not a forensic afterthought.

What this signals

Authentication is no longer the end of the control story. When attackers can operate through valid credentials and trusted provisioning paths, the decisive question becomes whether the identity can do more than it should after it is authenticated. That shifts programme design toward session-level observation, entitlement containment and fast revocation.

Ephemeral-looking access can still produce persistent risk. Service accounts, automation credentials and SaaS integrations may appear operationally narrow, yet each can become a durable foothold if the surrounding governance is weak. For practitioners, the lesson is to treat identity trust as a living control surface, not a static configuration.


For practitioners

  • Harden trusted identity pathways Inventory tokens, service accounts, SCIM connectors and SaaS integrations as ingress paths, then scope them by the exact downstream systems they can reach.
  • Reduce standing automation privilege Remove long-lived automation secrets where possible, rotate what remains, and constrain service accounts so a single compromised credential cannot reach multiple environments.
  • Enforce adaptive authentication everywhere Require MFA and risk-based step-up for identity providers, privileged roles, admin workflows and federated access paths that currently rely on legacy exceptions.
  • Monitor identity behaviour continuously Track token reuse, suspicious provisioning, lateral movement and automation abuse across sessions so machine-speed abuse is visible before the incident matures.
  • Validate provisioning chains and federation controls Review SCIM and SAML configurations for overreach, then test whether a provisioning or federation failure would silently extend access beyond intended scope.

Key takeaways

  • Identity attacks are increasingly succeeding by abusing legitimate authentication, automation and federation paths rather than defeating them outright.
  • The article ties this shift to real-world patterns involving tokens, service accounts, SCIM flows, SaaS integrations and AI-assisted intrusion chains.
  • Teams need to govern trusted identity pathways continuously, because the practical security boundary now sits inside identity behaviour, not just at the login screen.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on attackers reusing valid identity paths rather than breaking authentication outright.
NHI-05 — Overprivileged NHIService accounts and automation credentials are described as the easiest paths in because they carry excessive reach.
NHI-07 — Long-Lived SecretsThe article explicitly calls out stale secrets, tokens and automation credentials as attacker leverage points.
Recommendation — Review authentication paths that attackers can reuse and remove assumptions that a successful login is inherently trustworthy. Reduce non-human access scope so a compromised credential cannot move freely across tools and environments. Rotate long-lived secrets aggressively and eliminate credentials that remain valid beyond their operational need.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe described attack patterns rely on credential theft followed by pivoting across environments.
Recommendation — Map identity abuse to credential access and lateral movement to prioritise detections around reuse and pivoting.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about mis-scoped permissions and trusted access paths.
Recommendation — Continuously validate entitlements so trusted identity paths do not exceed their intended authorization.
NIST Zero Trust (SP 800-207)Continuous monitoring and verification — Continuous monitoring and verificationThe article shows why trust in identity actions must be verified continuously rather than assumed after authentication.
Recommendation — Apply continuous verification to identity actions and session behaviour instead of relying on one-time authentication checks.

Key terms

  • Identity Attacks: Identity attacks are attempts to steal or abuse credentials, session tokens, cookies, or other identity artifacts through the browser. They often rely on phishing, session hijacking, malicious extensions, or local storage exposure. The browser is a key target because it sits directly in the path of authentication and user sessions.
  • Automation trust: Automation trust is the set of permissions and assumptions that allow scripts, connectors, provisioning flows and service accounts to act without human intervention. It becomes a security risk when those trusted paths are broad, persistent or insufficiently monitored, because attackers can reuse them as quiet infrastructure.
  • Provisioning chain: A provisioning chain is the sequence of systems and rules that creates, updates and removes access across identity platforms, applications and services. When that chain is weakly governed, access can appear faster than oversight can validate it, creating unreviewed privilege paths for both humans and machine identities.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org