Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Third-party NHI activity that looks like a breach: what teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: A GitHub App token generated a JWT, cloned public documentation to an unknown laptop, and overlapped with normal cloud activity from the same identity, creating an impossible-travel pattern that Exaforce treated as breach-like until proven otherwise. Identity-centric correlation matters because isolated anomalies rarely show the full risk picture.

NHIMG editorial — based on content published by Exaforce: Learning from the Exaforce frontline on trusted third parties behaving like threat actors

By the numbers:

Questions worth separating out

Q: What breaks when a trusted third-party NHI behaves like a threat actor?

A: The main failure is that teams can no longer trust the identity boundary.

Q: Why do third-party NHI incidents often look legitimate at first?

A: Because the access can be technically valid while the behaviour is operationally wrong.

Q: How should security teams handle risky behaviour from non-human identities without breaking production?

A: Treat response as a business-impact decision, not just an alert workflow.

Practitioner guidance

  • Correlate identity, device, and network context for every third-party token. Require detection logic to join token use, source network, user agent, geography, and concurrent session state before escalating or suppressing an NHI alert.
  • Treat concurrent activity as a high-severity anomaly for bot identities. Define impossible travel and dual-environment execution as breach-class indicators for non-human identities, even when each individual alert looks explainable.
  • Suspend third-party integrations before the intent debate is resolved. Build a playbook that allows rapid suspension of a third-party NHI, revocation of administrative authentications, and preservation of forensic evidence once behaviour crosses the trust boundary.

What's in the full article

Exaforce's full blog covers the operational detail this post intentionally leaves for the source:

  • The specific alert aggregation logic used to collapse multiple noisy signals into one incident.
  • The exact sequence of response actions, including suspension of the third-party integration and revocation of administrative authentications.
  • The platform telemetry pattern behind the impossible travel assessment for the bot identity.
  • How the team distinguished unsafe support activity from an external breach after investigation.

👉 Read Exaforce's analysis of trusted third-party NHI activity that mimicked a breach →

Third-party NHI activity that looks like a breach: what teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Trusted third-party NHI behaviour is now a breach-class signal, not a support exception. This incident shows that organisations cannot rely on the intent of the actor to determine severity once a non-human identity departs from its baseline. When a third-party integration behaves like a person using a workstation from a residential network while also appearing active in its normal cloud context, the governance question becomes whether the identity relationship itself is still trustworthy. Practitioners should treat that as an identity-control issue, not a helpdesk ambiguity.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to the same report.

A question worth separating out:

Q: Who is accountable when a third-party integration is abused?

A: Accountability belongs to the business owner, the platform owner, and the identity team together, because connected apps sit across operational boundaries. If no one can state who approved the grant, who renews it, and who revokes it, the organisation has a governance gap. Ownership must be explicit before incidents happen.

👉 Read our full editorial: Trusted third-party NHI activity can mimic a breach



   
ReplyQuote
Share: