TL;DR: Credential enrichment, password spraying, and exposed source code are used to target non-human identities and create operational disruption, even when attacks fail, according to Oasis Security. Frequent targeting means NHI governance now has to account for continuous external pressure, not just internal lifecycle hygiene.
At a glance
What this is: This is Oasis Security’s introduction to a live NHI Threat Center, which argues that external threat activity against non-human identities is frequent and operationally disruptive even when attacks do not succeed.
Why it matters: It matters because IAM and NHI programmes have to account for repeated outside pressure on credentials, accounts, and authentication flows, not just internal lifecycle hygiene and periodic review.
Context
NHI threat intelligence is the external pressure layer that many identity programmes treat as separate from governance, even though the two are tightly linked. When attackers continuously probe service accounts, tokens, and exposed credentials, the control problem is no longer only what exists in inventory but what can be discovered, abused, or brute-forced from outside.
Oasis Security frames the issue around a live Threat Center and 20 threat actors it has observed in action. That is a useful signal for IAM and NHI teams because frequent attack attempts create operational consequences even when they fail, including lockouts, noisy authentication events, and a wider gap between perceived and actual exposure.
Key questions
Q: What breaks when attackers can enrich NHI target lists from leaked credentials and public code?
A: Governance breaks at the point where identities are no longer only internally managed. If service accounts, tokens, or API keys are discoverable in code, logs, or shared credential pools, attackers can assemble a target set before they ever touch the tenant. That means inventory, secrecy, and exposure management have to be treated as one control surface, not separate tasks.
Q: Why do repeated password-spraying attempts matter even when they fail?
A: Because failure still reveals pressure on the identity boundary. Distributed login attempts can trigger lockouts, generate noisy authentication events, and show which accounts are worth testing at scale. For practitioners, that means repeated failures are not just signal noise. They are evidence that attackers are mapping the environment and probing for weak authentication paths.
Q: What signs show that NHI threat activity is becoming operational risk?
A: Frequent lockouts, bursts of failed logins, and sudden increases in authentication noise are the clearest signs. Those patterns indicate that attackers are testing credentials across multiple identities rather than attacking one account in isolation. The practical test is whether the identity team can distinguish normal user friction from distributed abuse against NHI-related authentication paths.
Q: How should IAM teams respond when threat intelligence shows continuous targeting of NHIs?
A: They should move from periodic review to pressure-aware governance. That means using threat intelligence to re-rank high-value service accounts, tightening exposure controls on secrets and source code, and feeding authentication anomalies into NHI risk review. The point is to govern the attack surface continuously, not after a compromise is confirmed.
How it works in practice
Credential enrichment turns NHI exposure into a standing target set
Threat actors do not need to start from scratch when they go after NHIs. They build target lists by aggregating leaked credentials, public source code, exposed configuration files, and email addresses harvested at scale. In practice, that means an organisation’s attack surface is not limited to its own directories and vaults. It also includes the wider internet, dark web marketplaces, and shared credential pools where a service account or token can be matched to a live tenant. For NHI governance, this shifts the problem from local stewardship to external discoverability.
Practical implication: treat credential exposure as an externalised governance failure, not just an internal hygiene issue.
Password spraying and credential stuffing exploit authentication assumptions
Once attackers have a pool of credentials, they test them against accounts using credential stuffing and password spraying. These techniques work because identity providers often rate-limit individual attempts without fully accounting for distributed low-and-slow abuse across many accounts. The attacker does not need deep access at the start, only enough valid pairs to trigger a successful login path. In NHI terms, the authentication layer becomes the chokepoint where reused or weakly protected credentials convert into account compromise, especially when the same secret is reused across services or tenants.
Practical implication: enforce strong credential uniqueness and monitor distributed login patterns, not just single-account brute force.
Operational disruption is a governance signal, not just an incident symptom
The article notes that even failed attacks can create account lockouts and other operational problems. That matters because lockouts, repeated authentication failures, and bursts of login noise are not mere nuisance events. They are evidence that external actors are mapping your NHI boundary and testing which identities have standing value. A governance programme that only counts successful compromise will miss this pressure entirely. The better lens is exposure plus pressure, where the operational signal becomes part of the control assessment rather than an after-the-fact alert.
Practical implication: fold repeated lockouts and failed login bursts into NHI risk review and control tuning.
NHI Mgmt Group analysis
NHI threat intelligence is now a governance control, not a background feed: once attackers continuously target service accounts, tokens, and exposed credentials, the question is not whether a compromise has already happened. The question is whether the governance model can absorb constant external pressure on identity assets that were previously managed as static internal objects. That makes threat visibility part of NHI control design, not just SOC awareness.
Credential enrichment is the real upstream control failure: the article shows that attackers build identity target sets from leaked credentials, source code, exposed files, and harvested email addresses. That means the NHI problem starts before authentication, because the identity estate is already visible to attackers in fragments. Practitioners should read this as proof that discovery and exposure management are inseparable from access governance.
Frequent failed attacks expose an identity blast radius problem: repeated lockouts, password spraying, and distributed login attempts are evidence that attackers can stress an environment without ever landing a full breach. The named concept here is identity blast radius, the degree to which one exposed credential can ripple across accounts, services, and operational workflows. NHI governance has to measure that ripple, not just count credentials.
Standing-access assumptions break when identities are probed continuously: NHI governance often assumes that access can be reviewed after issuance because the identity will remain stable long enough to inspect. That assumption fails when attackers are actively testing credentials at scale, because exposure is continuous and the useful control window shrinks to detection and revocation. The implication is that lifecycle governance must account for external discoverability as a first-class risk.
Threat feeds become actionable only when they map to controls: a list of actors is useful if it changes how teams prioritise credential hygiene, authentication monitoring, and lockout analytics. Without that translation, threat intelligence stays descriptive. For NHI programmes, the operational question is whether observed attacker behaviour changes the control thresholds used to govern secrets, service accounts, and identity providers.
From our research library:
- Valid account abuse was responsible for 35% of cloud-related incidents, according to CrowdStrike's 2025 Global Threat Report.
What this signals
Identity blast radius: the important shift here is that attackers are not only hunting for credentials, they are testing how far one exposed secret can reach across an organisation. That should change how teams score NHI exposure, because a credential that is reused, shared, or embedded in code creates more governance debt than a credential that is isolated and short-lived.
Frequent failed login activity should be treated as an early governance signal for NHI programmes, not only as a detection problem. If attackers can trigger lockouts or repeated authentication noise without success, they have already learned something about the identity boundary, and that learning matters for prioritisation.
Threat intelligence becomes useful when it changes review cadence, exposure triage, and authentication monitoring for service accounts and other machine identities. Without that operational translation, the programme has visibility but no decision advantage.
For practitioners
- Prioritise externally discoverable NHI assets Inventory service accounts, API keys, tokens, and certificates that are likely to appear in public code, logs, exposed files, or shared credential pools, then rank them by blast radius and reusability.
- Tighten credential reuse controls Eliminate repeated use of the same secret across services and tenants, and treat any credential that appears in leaks or public repositories as immediately suspect.
- Instrument authentication for distributed abuse Watch for many low-volume failures spread across accounts, locations, and time windows, because password spraying and stuffing are designed to avoid single-account lockout thresholds.
- Use lockout noise as a governance signal Classify repeated account lockouts and unexplained authentication bursts as evidence of active targeting, then route them into NHI risk review instead of treating them as routine help desk events.
Key takeaways
- NHI threat activity is not limited to successful compromise, because repeated probing can still expose weak identity boundaries and create operational disruption.
- Credential enrichment, password spraying, and public-source leakage show that attackers often assemble their target set before they ever reach your tenant.
- The most useful response is pressure-aware governance that treats exposure, authentication noise, and lockouts as part of NHI control ownership.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The article centres on leaked credentials, public source code, and exposed files feeding NHI targeting. |
| NHI-07 — Long-Lived Secrets | Credential reuse and credential-stuffing risk are amplified when secrets persist across services. | |
| NHI-04 — Insecure Authentication | Password spraying and credential stuffing exploit weak authentication paths and rate-limit assumptions. | |
| Recommendation — Scan repositories, logs, and exposed files for leaked NHI secrets and revoke anything that is externally discoverable. Reduce secret lifespan and eliminate reusable credentials that attackers can test across multiple services. Harden authentication paths against distributed login abuse and monitor low-and-slow attempts across accounts. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article shows why identity permissions must be governed under continuous external pressure. |
| Recommendation — Reassess access permissions for exposed NHIs and tighten authorization scope before attackers reach them. | ||
| MITRE ATT&CK | TA0006 — Credential Access | The core threat pattern is harvesting and testing credentials to gain initial access. |
| Recommendation — Map observed credential-enrichment and stuffing activity to TA0006 and prioritise detection around credential access paths. | ||
Key terms
- Authentication Enrichment: Authentication enrichment is the process of adding context to login events so analysts can judge whether a sign-in looks normal or suspicious. Typical enrichment includes IP reputation, geolocation, proxy or VPN detection, ASN ownership, breach exposure, and browser or device details. The extra context turns raw logs into higher-value detection inputs.
- Password Spraying: A guessing technique that uses a small set of common passwords against many accounts to avoid lockouts and detection. It is effective when organisations do not reject common passwords, do not monitor patterns across identities, or allow too much standing access.
- Credential Stuffing: Credential stuffing is an attack that uses stolen username and password pairs from previous breaches to try logging into other services. It works because many people reuse credentials, and because the login attempt uses valid information, it can look ordinary until the surrounding behavior gives it away.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org