By NHI Mgmt Group Editorial TeamBased on Aembit: “OWASP’s Top Security Risks for Non-Human Identities and How to Address Them” (April 29, 2026)

TL;DR: Non-human identity risk is concentrated in familiar failures such as improper offboarding, secret leakage, overprivilege, weak authentication and environment reuse, with breach examples spanning public repositories, cloud workloads and third-party access, according to Aembit's analysis of OWASP's first NHI Top 10. The core issue is that NHI governance still treats machine credentials like managed user access, even though many persist, spread and operate outside human review windows.


At a glance

What this is: This is Aembit's breakdown of OWASP's first NHI Top 10, which maps the main non-human identity failure modes to breach patterns, compliance gaps and governance blind spots.

Why it matters: It matters because IAM teams now have a clearer way to prioritise NHI controls across service accounts, API keys, workloads and agentic systems before those identities expand blast radius or outlive ownership.

By the numbers:

  • Non-human identities now outnumber human identities by 144 to 1 in the average enterprise, according to Entro Security research cited by Aembit.
  • Nearly 29 million new hardcoded secrets were exposed on public GitHub in 2025 alone, a 34% year-over-year increase, according to GitGuardian research cited by Aembit.
  • 64% of secrets exposed as far back as 2022 remained valid in early 2026, according to GitGuardian research cited by Aembit.

Context

Non-human identity governance fails when organisations assume machine credentials behave like employee accounts. Service accounts, API keys, tokens and workload secrets often persist after the workload changes, can be reused across environments, and may never be reviewed in the same way as human access.

That gap is the point of OWASP's first NHI Top 10. Aembit's breakdown uses breach examples and control themes to show that the real problem is not only credential exposure, but the absence of lifecycle control, ownership and scope management across NHI estates.

The article is broadly representative of current enterprise practice, where NHI risk is still being managed as a side effect of human IAM rather than as a separate governance domain.


Key questions

Q: What breaks when NHI credentials are never offboarded?

A: When offboarding is missing, API keys, tokens and service accounts can remain valid after the workload or integration is gone. That creates orphaned access that no one owns, no one reviews and attackers can eventually find in repositories, logs or old configurations. The failure is lifecycle, not just hygiene: the credential outlives the business need.

Q: Why do leaked secrets remain such a persistent NHI risk?

A: Leaked secrets persist because they are often embedded in code, pipelines, or collaboration tools, then left valid long enough for reuse. The real problem is not only exposure but weak identity lifecycle management, especially when ownership, rotation, and revocation are not tightly governed.

Q: When should teams prioritise least privilege over convenience for NHIs?

A: Always, but especially when an NHI can reach production data, cloud control planes or third-party systems. Convenience often leads to broad roles, shared identities and reused credentials, all of which magnify the impact of compromise. Least privilege is the control that contains blast radius before an incident becomes systemic.

Q: How do organisations govern third-party NHI access safely?

A: They should treat vendor-linked tokens, service accounts and integrations as governed dependencies with an owner, a scope and a removal date. The access should be monitored continuously and revoked when the business relationship, environment or integration purpose changes. Without that discipline, vendor access becomes persistent trust rather than controlled access.


Technical breakdown

Why NHI offboarding fails when credentials outlive workloads

Improper offboarding is the point where a workload or service is retired but its credentials remain valid. In NHI environments, that usually means API keys, service accounts or tokens were never tied to a lifecycle event that forces revocation. Because these identities do not log off like users, stale access can sit dormant until an attacker finds it. The control failure is not only a missed cleanup task. It is a broken lifecycle assumption that treats machine access as static instead of disposable.

Practical implication: connect every NHI to an owner, an expiration condition and an automated revocation path.

How secret leakage turns into immediate credential abuse

Secret leakage matters because most non-human credentials do not have a second factor or an interactive challenge at use time. If a token, key or certificate appears in a repository, log or ticket, it can often be used immediately. That is why scanning is only part of the answer. The architecture problem is that many integrations still trust possession of the secret alone. Once the secret is exposed, the identity boundary is effectively gone until the credential is revoked or expires.

Practical implication: move exposed NHI secrets to revocation-first handling, not just detection and alerting.

Why overprivileged NHIs expand blast radius faster than human accounts

Overprivileged NHIs fail because privilege is often assigned for convenience, not for function. A service account with broad cloud permissions or a workload identity shared across systems can turn one compromised credential into access across data, infrastructure and downstream services. The article also shows that least privilege becomes harder when NHIs are reused or left active across environments. In practice, this is a blast-radius problem: the credential may be narrow in name but wide in effect.

Practical implication: right-size NHI permissions by function, environment and application boundary.


Threat narrative

Attacker objective: The attacker aims to turn one exposed or poorly governed machine credential into durable access across systems, data and cloud workloads.

  1. Entry occurs when an attacker finds an exposed NHI secret in a repository, log or other shared location and uses it without needing an interactive login.
  2. Escalation follows when the stolen credential belongs to an overprivileged service account or workload identity that can reach multiple systems beyond its intended scope.
  3. Impact arrives as the attacker uses that standing access to exfiltrate data, move laterally or pivot through third-party and production systems.
  • Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
  • Cisco Active Directory credentials leak 2025: Kraken leaked Cisco Active Directory hashes, including service and krbtgt accounts; Cisco says they came from its 2022 breach, not a new one.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

OWASP's NHI Top 10 is really a lifecycle document, not just a threat list: the central problem is that many organisations still do not govern machine identities as identities. Offboarding, ownership, rotation and scoping are treated as implementation details instead of the core control plane. That is why the same failure patterns keep reappearing across cloud workloads, SaaS integrations and service accounts.

Secret leakage is the symptom, but standing trust is the disease: once a non-human credential is copied into a repo, log or ticket, the access model has already failed. The deeper issue is that possession of the secret is often treated as sufficient proof of authority, which is a brittle trust model for distributed systems. Practitioners should read this as a governance failure, not a tooling failure.

Overprivileged NHI: the blast-radius problem is now the dominant machine-identity risk: when NHIs are granted broad permissions to make automation easier, the resulting access window is much larger than the task requires. That widens the impact of compromise and makes cleanup slower. The practical conclusion is that identity scope must be narrowed to the service boundary, not the convenience boundary.

Vulnerable third-party NHI access is becoming a supply-chain control issue: the article shows that vendor access is only safe when it is continuously inventoried, constrained and revoked with the same discipline as internal access. If a third party can retain valid tokens after a relationship or environment change, accountability has already slipped. Practitioners should treat third-party NHIs as governed dependencies, not static integrations.

OWASP NHI Top 10 gives IAM teams a shared vocabulary for compliance and engineering: it aligns operational failure modes with controls that auditors, architects and platform teams can all recognise. That matters because NHI governance stalls when security speaks in abstract risk terms while engineering sees only working automation. The useful outcome is a control model that links identity ownership, privilege scope and secret lifecycle to one practical programme.

From our research library:

What this signals

Identity blast radius is the right lens for NHI governance: once machine credentials are overprivileged or reused, the question is not only whether a secret was exposed. The real issue is how far that one credential can move through cloud and SaaS environments before detection or revocation closes the window.

Access reviews and recertification workflows were designed around stable identities that persist long enough to be observed. NHIs break that assumption when secrets are embedded in code, shared across systems or left behind after offboarding, so governance has to move earlier in the lifecycle.

Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs, which means most teams are managing an access surface they cannot fully enumerate. That is why ownership, scope and expiry are not optional details but the core of machine identity control.


For practitioners

  • Map every NHI to an owner and an offboarding trigger Tie service accounts, API keys and workload identities to a named owner, a system of record and a revocation event when the workload or integration is retired.
  • Replace static secrets with expiring credentials Use short-lived tokens or federated workload identity so a leaked secret has a smaller replay window and a clear expiry path.
  • Right-size permissions by service boundary Review cloud roles, OAuth app scopes and service account grants against the actual function they support, then remove access outside that boundary.
  • Continuously scan for exposed machine secrets Search repositories, logs, documentation and CI/CD artifacts for tokens and keys, then revoke anything found before it can be reused.
  • Separate third-party access from internal privilege Inventory vendor-linked NHIs separately, constrain them to the minimum required systems and remove them when the integration no longer needs access.

Key takeaways

  • OWASP's first NHI Top 10 shows that the hardest machine-identity problems are still lifecycle, scope and trust issues rather than purely technical misconfigurations.
  • The strongest evidence in the article ties exposed secrets, missed offboarding and excessive privilege to real breach paths across cloud, SaaS and third-party access.
  • The practical response is to govern NHIs as identities with owners, expiry conditions and scoped permissions instead of treating them as static credentials.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centres on retired NHIs whose access remains active after use ends.
NHI-02 — Secret LeakageExposed tokens, keys and logs are a primary failure mode in the article.
NHI-05 — Overprivileged NHIExcessive permissions are repeatedly shown to widen blast radius across cloud and SaaS systems.
Recommendation — Tie every NHI to an offboarding trigger and revoke access when the workload or integration retires. Scan for exposed NHI secrets and revoke any leaked credential before it can be reused. Right-size each NHI to the minimum permissions its function requires and remove broad roles.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing and reviewing access permissions for machine identities.
Recommendation — Apply entitlement review and least-privilege controls to all NHI accounts, tokens and service roles.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe breach patterns involve stolen secrets leading to wider access and movement.
Recommendation — Map exposed NHI credentials to credential access and lateral movement techniques in detection workflows.

Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Offboarding: Offboarding is the controlled retirement of a workload, service account, token, certificate, or other non-human identity when it is no longer needed. It includes revoking credentials, removing permissions, and verifying that no residual trust path remains available to attackers.
  • Overprivileged Nhi: An overprivileged NHI is a service account, token, key, or other machine identity that has been granted more access than it needs to do its job. The risk is not theoretical. Excess scope increases blast radius, makes compromise more valuable to attackers, and slows containment when the identity is abused.
  • Secrets Leakage: Secrets leakage is the exposure of credentials such as API keys, tokens, or certificates in places where they can be discovered and reused. The risk is not just disclosure, but unauthorized authentication that turns a coding or pipeline mistake into active access.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org