Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

The Silent Threat: How Phishing Attacks Now Target Non-Human Identities


(@entro)
Reputable Member
Joined: 1 year ago
Posts: 125
Topic starter  

Read full article here: https://entro.security/blog/how-phishing-targets-nhis/?utm_source=nhimg

Phishing is evolving — and non-human identities (NHIs) are the new prize.

While traditional phishing once focused on stealing user passwords or payment data, today’s attackers are going after something more powerful: machine credentials that live behind the scenes. These include service accounts, personal access tokens (PATs), API keys, and credentials — all critical to modern infrastructure, and all increasingly at risk.

 

Why It Matters

Once inside the network, attackers no longer stop at human credentials. They pivot toward non-human identities, which often:

  • Carry elevated, long-standing privileges

  • Operate autonomously and undetected

  • Lack proper monitoring, rotation, and ownership

This makes NHIs ideal for lateral movement, privilege escalation, and persistent access — all while blending in with normal system traffic.

 

Real-World Impact

Let’s look at some real-world examples to drive this home:

  • Internet Archive in 2024: Attackers leveraged stale access tokens in their Zendesk platform, compromising over 800,000 support tickets with data stretching back to 2018.
  • Schneider Electric in 2024: Hackers exploited exposed non-human identity credentials in the development environment, making off with 40GB of data, including 400,000 records with names, emails, and critical project details.
  • The New York Times in 2024: An over-privileged GitHub token was exploited, giving attackers access to all of the Times’ source code repositories.

The cost? Millions in financial damage, compliance fines, and operational downtime — all from identities that often go unmonitored.

 

Defense strategies

Security teams must move beyond reactive identity controls. The future of defense is machine identity-first:

  • Contextual Secrets Rotation - Triggered by behavioral anomalies, not static schedules

  • Zero Trust for Machines - Temporary, task-specific access for every non-human identity

  • Real-Time Monitoring - AI-driven baselines for normal NHI behavior

  • Comprehensive Visibility - Full inventory, ownership mapping, and risk scoring of all machine identities


This topic was modified 12 months ago by Abdelrahman
This topic was modified 11 months ago by Abdelrahman

   
Quote
Share: