TL;DR: DHS found that avoidable NHI management failures, including a forgotten signing key left unrotated for more than six years and reused across business and consumer systems, helped enable the Storm-0558 compromise of Microsoft Exchange Online accounts, according to Oasis Security's summary of the report. Manual key management is no longer a tolerable control model when one stale credential can collapse cloud-wide trust.
At a glance
What this is: This is an analysis of the DHS review of the Microsoft Exchange incident, showing how manual NHI rotation failures and reused signing keys contributed to the compromise.
Why it matters: It matters because IAM, PAM, and NHI teams need to treat credential lifecycle automation and environment isolation as operational controls, not optional hygiene.
Context
Non-human identity governance fails when a highly privileged credential can live for years, cross trust boundaries, and remain outside routine review. In this case, the problem was not just exposure of a key. It was a lifecycle model that allowed a signing credential to persist beyond its safe operating window and to be reused across different environments.
The Microsoft Exchange incident illustrates a familiar NHI governance gap. When rotation is manual, ownership is fragmented, and dependency visibility is weak, stale credentials become durable trust anchors. That makes the issue larger than one compromised key, because the same control failure can affect service accounts, signing keys, API credentials, and acquired environments.
Key questions
Q: What breaks when manual NHI rotation is used for privileged signing keys?
A: Manual rotation breaks when the credential itself becomes part of the trust infrastructure. If a signing key is left active for years, people stop treating it as a change-controlled object and start treating it as invisible plumbing. That is when a single stale credential can outlive ownership, evade review, and remain usable by an attacker.
Q: Why do compromised signing keys create such high risk for cloud identity systems?
A: Compromised signing keys are dangerous because they can produce authentication artefacts that downstream systems trust as valid. That means an attacker may bypass normal login controls and operate inside ordinary access flows, which makes the activity hard to spot without additional monitoring. The result is a stealthy attack path that can persist until token misuse or anomalous behaviour is detected.
Q: What signs indicate an NHI lifecycle programme is failing?
A: A weak programme usually shows the same signals: credentials older than their intended rotation window, unclear ownership, reuse across environments, and no documented decommission path. When those signs appear together, the issue is not just bad housekeeping. It means trust has become durable without being governable.
Q: How should teams govern acquired systems with hidden machine identities?
A: Teams should treat acquired systems as untrusted until every inherited credential has an owner, a rotation status, and an offboarding decision. If those facts are missing, the credential is not governed. The safest approach is to discover, classify, and re-authorise the NHI estate before keeping any legacy trust active.
Technical breakdown
Why manual key rotation breaks at cloud scale
Manual rotation fails because human-paced workflows cannot keep up with the number, coupling, and dependency depth of non-human credentials. A signing key used for token validation is not just a secret to store. It is a trust root whose age, scope, and downstream dependencies all matter. If that key is left in place for years, the organisation has effectively turned a recoverable secret into a standing authentication primitive. The Microsoft case shows how operational continuity can mask security decay when rotation only happens during outages or special projects.
Practical implication: Treat key rotation as a lifecycle control with enforced cadence, not an ad hoc maintenance task.
How cross-environment key reuse widens the blast radius
A credential used across business and consumer systems creates shared fate. If one trust anchor is exposed or mismanaged, the compromise is not contained to a single application boundary. Token signing keys are especially sensitive because they can mint or validate access across services, which means reuse turns one identity failure into many. This is where environment isolation matters: credentials, signing material, and validation paths should not be interchangeable across domains with different risk profiles. The incident shows that reuse is not just inefficient governance; it is a multiplier on compromise impact.
Practical implication: Segment signing and authentication material by environment so one key cannot authenticate everywhere.
Why acquired firms and legacy systems need explicit NHI review
Inherited infrastructure often carries hidden identities, old keys, and undocumented trust relationships. In mergers, acquisitions, and platform integrations, the governance failure is not only missing inventory. It is assuming that credentials discovered later can be safely left in place because they are “just legacy.” For NHI lifecycle control, acquired systems require the same scrutiny as production assets: ownership, rotation status, privilege scope, and decommission plan. Without that review, legacy keys survive organisational change and become long-lived trust debt.
Practical implication: Include acquired systems in NHI discovery and offboarding reviews before allowing their credentials to remain trusted.
Threat narrative
Attacker objective: The objective was persistent unauthorized access to high-value email accounts for espionage and intelligence collection.
- Entry occurred through a forgotten Microsoft signing key that had remained active for more than six years and was used to validate authentication tokens.
- Escalation followed when the stolen signing material allowed the threat actor to mint or abuse trusted access into Exchange Online mailboxes.
- Impact included compromise of accounts across 22 organisations and more than 500 individuals, including senior government officials.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Manual NHI rotation is a governance failure, not a process preference. A signing key that remains active for years ceases to be a managed control and becomes a latent trust anchor. The Microsoft case shows that human approval loops and calendar-driven maintenance cannot reliably secure machine-issued credentials at cloud scale. The practitioner conclusion is straightforward: if rotation depends on memory, the control has already failed.
Cross-environment credential reuse creates identity blast radius. When the same signing material or trust relationship spans business and consumer systems, compromise in one context collapses trust in the other. That is not a narrow implementation flaw, it is a structural governance error in how NHI boundaries are defined. The practitioner conclusion is to treat reuse as an exposure multiplier, not merely a convenience problem.
Identity lifecycle governance must extend into acquired and inherited systems. The report's broader lesson is that organisations inherit hidden NHI debt when they absorb legacy platforms, old keys, or undocumented dependencies. If offboarding, rotation, and ownership review stop at the acquisition boundary, stale trust survives the transaction. The practitioner conclusion is that lifecycle controls must follow the identity, not the org chart.
Automation is now the baseline for NHI trust hygiene. Manual key management assumes there are few enough credentials, dependencies, and exceptions for people to track them accurately. That assumption no longer holds in distributed cloud estates. The practitioner conclusion is that NHI programmes should move from episodic review to continuous discovery, rotation, and decommission governance.
Long-lived signing keys are a form of trust debt. The article describes a credential that had been forgotten, reused, and left unrotated until it became operationally invisible. That pattern accumulates risk quietly and then fails catastrophically when an attacker finds it. The practitioner conclusion is to measure the age, reuse, and ownership quality of privileged machine credentials as first-class risk signals.
What this signals
Trust roots need lifecycle controls, not periodic heroics. The Microsoft case is a reminder that the most dangerous machine credentials are often the ones nobody remembers to revisit. Once a signing key becomes part of the authentication fabric, discovery and rotation have to be continuous or the control degrades into folklore.
Environment isolation is now a trust design requirement. If business and consumer systems share signing material or validation paths, one compromise can bridge domains that should have been isolated. IAM teams should assume that shared credentials will eventually be found and design so that reuse cannot spread impact.
Automation should be judged by how much hidden identity debt it removes. The practical test is not whether rotation exists on paper. It is whether the programme can surface old keys, identify reused trust relationships, and retire credentials before they become invisible assets.
For practitioners
- Automate signing key rotation Replace manual rotation runs with enforced lifecycle scheduling for all privileged machine credentials, especially token-signing keys and federation material.
- Map credential reuse across trust domains Inventory where a single NHI or signing key is trusted by multiple workloads, tenants, or user populations, then separate those trust boundaries.
- Review inherited identities after acquisitions Require explicit ownership, rotation status, and decommission decisions for credentials discovered in acquired platforms before they remain trusted in production.
- Prioritise privileged keys with multi-year age Escalate any long-lived signing or access credentials that have remained active beyond normal review cycles, because age often indicates hidden governance debt.
Key takeaways
- The incident shows how a forgotten signing key and manual lifecycle control can turn an NHI into a durable trust anchor.
- The compromise affected 22 organisations and more than 500 individuals, showing that one stale credential can scale into broad cloud exposure.
- Automated rotation, strict environment separation, and explicit offboarding of inherited credentials are the controls that would have reduced the blast radius.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-07 — Long-Lived Secrets | The article centres on a signing key left active for over six years. |
| NHI-09 — NHI Reuse | The same key was reused across business and consumer systems. | |
| NHI-01 — Improper Offboarding | The incident highlights failure to decommission an old signing key. | |
| Recommendation — Enforce rotation and expiry for privileged keys before they become standing trust anchors. Eliminate cross-environment reuse of signing material and other privileged NHI credentials. Retire orphaned keys as part of formal offboarding and lifecycle governance. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | IA-5 directly governs credential lifecycle, including rotation and revocation. |
| Recommendation — Apply authenticator management controls to rotate and revoke machine credentials on schedule. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The breach reflects weak control over which identities could authenticate across services. |
| Recommendation — Review and limit entitlements so machine credentials cannot authenticate beyond intended scope. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The compromise used stolen signing material to move from credential abuse into broad mailbox access. |
| Recommendation — Map stale key exposure to credential-access and lateral-movement detections in your monitoring stack. | ||
Key terms
- Signing Key: A signing key is a secret used to create or verify trusted authentication material. When that key is tied to identity infrastructure, it can become a high-value trust anchor that affects many systems at once. If it is reused or left unrotated, compromise can spread far beyond the original service.
- Credential Rotation: The practice of regularly replacing secrets and credentials with new values to limit the window of exposure if a credential is compromised. Automated rotation, enforced by policy, is the security-optimal approach.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Trust anchor: A trust anchor is the root authority that signs federation metadata and establishes the policies other participants inherit. In practice, it controls who can join, what cryptographic rules apply, and how trust is delegated across an ecosystem. The security posture of the whole federation depends heavily on this layer.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org