TL;DR: Storm-0501 has used weak credentials and over-privileged accounts to move from on-premises systems into cloud platforms, showing how unmanaged non-human identities can enable persistent lateral movement across hybrid environments, according to Oasis Security. The real failure is not just exposure, but governance that assumes machine access stays visible, owned, and reviewable long enough to be controlled.
At a glance
What this is: This analysis shows how Storm-0501 used weak credentials and over-privileged accounts to move from on-premises systems into cloud platforms, exposing gaps in hybrid-cloud NHI governance.
Why it matters: It matters because IAM teams need governance that tracks service accounts, tokens, and delegated privileges across environments before attackers turn invisible machine access into lateral movement.
Context
Storm-0501 is a hybrid-cloud intrusion pattern, not just a cloud breach story. The core problem is that machine access often spans on-premises systems and cloud services without a single owner, inventory, or review path, so privilege can persist after the original business need has changed.
In this case, weak credentials and over-privileged service accounts gave the attackers a route from compromised servers into cloud resources. That makes the incident a governance failure as much as a security one, because traditional IAM processes were not built to continuously track non-human identities across fragmented environments.
Key questions
Q: How should security teams protect identities across Microsoft on-premises and cloud environments?
A: Security teams should treat Microsoft estates as one identity control plane, then apply strong authentication, lifecycle governance, and continuous monitoring across on-premises and cloud resources. The priority is to reduce inconsistent trust decisions between Session Windows, ADFS, Exchange on-premises, Office 365, Entra ID, and related integrations. Centralised identity policy and logging help teams spot gaps before they become access abuse.
Q: Why do non-human identities increase privileged access risk in cloud environments?
A: Non-human identities increase risk because they often outnumber humans, operate continuously, and depend on credentials that are easier to reuse than to govern. When those identities retain broad or persistent access, attackers gain a faster path to cloud services, data stores, and automation layers. The risk is structural, not just operational.
Q: What are the signs that NHI lifecycle governance is failing in hybrid cloud?
A: The clearest signs are stale accounts that remain active after migrations, sync identities that still bridge multiple environments, and service accounts whose permissions no longer match their workload. Those conditions show that offboarding and recertification are not keeping pace with machine change.
Q: How should teams govern service accounts in multi-cloud environments?
A: Treat service accounts as governed identities with owners, purpose, expiry expectations and revocation paths. They need the same lifecycle discipline as human-admin access because they often carry high privilege and persist unnoticed. Governance should include inventory, review, offboarding and periodic validation that the account still supports an active business function.
Technical breakdown
How weak credentials become a hybrid-cloud entry point
Hybrid-cloud attackers often begin where authentication is easiest to abuse: reused passwords, stale service accounts, or credentials embedded in infrastructure. In Storm-0501's case, on-premises compromise was the starting position, but the real advantage came from identities that were already trusted inside the environment. Once a machine identity is accepted by both sides of the hybrid boundary, the attacker inherits that trust relationship. The technical problem is not only exposure of a secret, but the fact that the secret authenticates a workload or sync process with enough reach to bridge environments.
Practical implication: inventory hybrid trust paths and remove machine credentials that still authenticate across both on-premises and cloud boundaries.
Why over-privileged service accounts enable lateral movement
A service account is a non-human identity used by software, sync tools, or workloads to perform routine actions. When it carries broad permissions, compromise of the account turns a local foothold into a platform-wide opportunity. Storm-0501 illustrates how over-privileged NHIs can be used to impersonate higher-value users, reach additional systems, and create backdoors that survive initial containment. This is a classic NHI pattern: the identity is not the asset, but it becomes the access bridge into the asset estate.
Practical implication: reduce service-account scope to the minimum required and separate sync, admin, and application functions into distinct identities.
Why stale accounts create persistence in hybrid environments
Stale accounts are identities that remain active after the workload, server, or dependency that created them has changed or no longer needs access. In hybrid environments, this creates an offboarding gap because access can survive infrastructure changes, migrations, or abandoned integrations. Storm-0501 shows that persistence is often not gained by sophisticated malware alone, but by identities that were never retired. Once the account is stale, defenders lose the clearest signal that the access path should no longer exist.
Practical implication: tie NHI offboarding to workload retirement, sync changes, and infrastructure decommissioning rather than relying on manual cleanup.
Threat narrative
Attacker objective: The attackers aimed to maintain durable access across hybrid environments and expand their reach from compromised servers into cloud resources.
- Entry occurred through exploitation of on-premises systems and weak credentials that exposed trusted machine access.
- Credential access and abuse followed when the attackers leveraged over-privileged service accounts tied to hybrid identity processes.
- Escalation and lateral movement extended the compromise from on-premises environments into cloud resources.
- Impact came from persistent access points that enabled prolonged, undetected exploitation across hybrid infrastructure.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Hybrid-cloud NHI governance fails when teams treat machine access as environment-specific. Storm-0501 shows that the same service account can become the bridge between on-premises systems and cloud platforms, which means governance has to follow the identity rather than the hosting layer. The discipline problem is not simply visibility, but continuity of ownership across a fragmented trust boundary. Practitioners should model the identity path, not the infrastructure silo.
Stale accounts are an offboarding failure, not just an inventory problem. When a workload, sync process, or server changes, the attached non-human identity can remain live long after the business need disappears. Storm-0501 illustrates that persistence often comes from access that was never explicitly retired, so the control gap is lifecycle governance that does not keep pace with machine change. Practitioners need to treat decommissioning as an identity event.
Over-privileged service accounts turn hybrid trust into blast radius. Once a machine identity has more reach than its workload requires, compromise of one system becomes access to several. The campaign underscores that privilege design for NHIs still too often mirrors operational convenience instead of security boundaries. Practitioners should assume any broadly scoped service account will be used as a lateral movement path if it is exposed.
Identity review cycles do not fail because they are absent, but because they are too slow for machine-to-machine access. The article's central warning is that NHIs can move between environments before a manual review ever reaches them. That makes continuous governance, not periodic certification, the relevant control model for hybrid estates. Practitioners should align control timing with machine execution speed.
Hybrid-cloud attack paths create a distinct concept: identity bridge risk. When a credential or service account is trusted in more than one environment, compromise of one side can automatically extend to the other. That risk is structural, not accidental, because the identity itself becomes the bridge. Practitioners should govern cross-environment identities as shared attack surfaces, not isolated configuration items.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Identity bridge risk: hybrid estates fail when a single non-human identity can bridge on-premises and cloud trust zones. That identity becomes the attacker’s fastest route across boundaries, so governance has to follow the credential path rather than the deployment model.
Service-account sprawl is not just an inventory issue. Once machine identities are over-privileged, stale, or unowned, they turn routine administration into persistent lateral movement opportunities, which is why lifecycle control has to be continuous instead of periodic.
For practitioners
- Map cross-environment machine trust paths Identify which service accounts, sync identities, and tokens can move from on-premises systems into cloud platforms, then classify each by the environments it can bridge.
- Reduce privilege on sync and workload identities Separate directory sync, application runtime, and administrative functions so one compromised identity cannot impersonate a higher-value role across the hybrid boundary.
- Retire stale non-human identities with system changes Bind NHI offboarding to server decommissioning, workload migration, and integration removal so abandoned identities do not outlive the systems that created them.
- Review hybrid identities for persistent lateral movement risk Prioritise any account that authenticates both on-premises and cloud resources, especially if it can reach Microsoft Entra Connect Sync or other federation paths.
- Instrument alerts for over-privileged NHI behaviour Watch for machine identities that begin impersonating privileged users, touching unusual cloud resources, or creating backdoors after initial access.
Key takeaways
- Storm-0501 demonstrates that hybrid-cloud compromise often starts with machine identities that were trusted too broadly, not with a novel exploit chain.
- The article highlights a familiar enterprise imbalance: non-human identities now outnumber human identities by 25x to 50x in modern environments, which widens the control problem.
- The most relevant control shift is to treat cross-environment service accounts as lifecycle-managed attack surfaces, with ownership, scope, and retirement tied to system change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article centers on stale accounts and delayed retirement of machine access across hybrid environments. |
| NHI-05 — Overprivileged NHI | Service accounts in the article carry more reach than the workloads require, enabling lateral movement. | |
| NHI-09 — NHI Reuse | Reused identities across on-premises and cloud systems enabled the cross-boundary path Storm-0501 exploited. | |
| Recommendation — Tie NHI retirement to workload decommissioning and integration removal so stale access cannot persist. Reduce machine identity scope so a compromised account cannot become a lateral movement bridge. Eliminate identity reuse across environments and give each workload a single, bounded purpose. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The campaign relies on credential abuse followed by movement from on-premises systems into cloud platforms. |
| Recommendation — Map hybrid credential abuse to TA0006 and TA0008 to prioritise detection and containment across trust zones. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about entitlement scope and authorization across hybrid environments. |
| Recommendation — Review machine entitlements under PR.AA-05 and remove permissions that exceed workload function. | ||
Key terms
- Hybrid-cloud NHI governance: The set of ownership, lifecycle, and privilege controls used to manage non-human identities across on-premises and cloud environments. It matters because machine access can span multiple trust zones, so governance has to track the identity across the full path of use, not just the host where it runs.
- Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
- Stale Account: A stale account is an identity that still exists and may still authenticate, but no longer has a valid business purpose. In NHI programmes, stale accounts often outlive the workload or team that created them, leaving residual access that should be removed or tightly constrained.
- Identity bridge risk: The risk that one non-human identity can authenticate across more than one environment and therefore extend compromise from one trust zone into another. It is a structural problem in hybrid estates because the identity itself becomes the connection between domains, not just the credential used to log in.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org