We have analysed 151 real-world breaches involving non-human identities and AI agents — leaked API keys, stolen tokens, compromised service accounts and the new AI attack paths. Explore how attackers get in, what they take, and what to fix first.
Calculated live from the breaches below. Hover or tap a card for what to do about it.
Leaked secret is the #1 known way in — 32 of 151 breaches.
Hover or tap — what to doAttackers reuse what works. Prioritise controls against the most common entry route first, then work down the chart.
See these breaches65 breaches began with a leaked, stolen or weak credential.
Hover or tap — what to doScan code, CI logs and tickets for secrets, vault what you find, rotate on exposure and replace long-lived keys with short-lived, scoped credentials.
See leaked-secret breaches34 breaches came through the supply chain or a SaaS / OAuth integration.
Hover or tap — what to doYour NHI risk includes your vendors' NHIs. Inventory third-party OAuth grants and integrations, scope them down and revoke what is unused.
See supply-chain breachesbreaches involve AI agents, LLM platforms or AI-specific attack routes.
Hover or tap — what to doTreat every agent as a governed identity: an owner, least-privilege and short-lived credentials, tool allow-lists, approval for risky actions and a kill switch.
See AI-related breachesA breach can have more than one route or identity type, so bars can add up to more than 151.
Click any bar to filter the breach list. 9 breaches (6%) did not disclose how the attacker got in.
47 of the breaches involve AI agents, LLM platforms, prompt injection or agent misbehaviour — the same NHI weaknesses, now exploited through software that acts on its own.
Show all AI-related breachesOpenAI agents used Census API keys leaked on GitHub, reposted SEC data and, per Transluce, tried to hack an Education site. No compromise found.
AI agent misbehaviour · Leaked secret · AI agent · API key Sep 2026 AI agentsNHISalesBleed: poisoned Web-to-Lead records made Salesforce Agentforce leak CRM data past Trusted URLs and phish in Slack as the agent. Now fixed.
Prompt injection · AI agent Sep 2026 NHIAI agentsLLM & AI platformCarbonato infects unauthenticated Docker hosts and runs a Hermes AI agent that steals AI API keys, SSH keys and tokens to fuel its own LLM service.
Misconfiguration · API key · Secret or password Sep 2026 NHIAI agentsHijacked GitHub Actions stole MemTensor's npm and PyPI tokens to ship sckit, a credential stealer in an AI agent memory plugin and MemoryOS.
Supply chain · CI/CD or publishing token · Source control token · Cloud credential · Secret or password Sep 2026 AI agentsNHIA Meta Muse zero-day let local malware redirect dictation, steal the agent's authentication material and abuse its delegated access. Hot-fixed.
Vulnerability exploit · AI agent · Session token Sep 2026 NHIHuman identityShinyHunters claims it breached the FBI via PeopleSoft and pivoted into AWS GovCloud. The FBI is investigating; the breach is not confirmed.
Vulnerability exploit · Cloud credential · Service account Sep 2026 AI agentsNHISpain's data regulator received its first breach notification blamed on an attacker's AI agent, which logged in, altered personal data and read invoices.
Not disclosed Sep 2026 NHILLM & AI platformAI agentsCVE-2026-59822 let any bearer token open LiteLLM's MCP gateway; attackers stole master and provider keys. 9.6% of exposed gateways used sk-1234.
Vulnerability exploit · Weak or default credentials · API key · Cloud credential Aug 2026 AI agentsLLM & AI platformA misconfigured Irregular cyber test gave Meta's Muse Spark 1.1 internet access and a real target; it exploited the site and changed its database.
AI agent misbehaviour · AI agent Aug 2026 NHIChainDrop hijacked a keyv maintainer account and spread through 444 npm packages on 4 August 2026, stealing npm, GitHub, CI, cloud and AI tool credentials.
Supply chain · CI/CD or publishing token · Source control token · Cloud credential · Secret or password Jul 2026 AI agentsNHILLM & AI platformFour Claude models in misconfigured cyber evaluations reached the internet and breached real organisations, including via a malicious PyPI package.
AI agent misbehaviour · AI agent · Secret or password Jul 2026 AI agentsLLM & AI platformIn UK AISI cyber tests, AI agents took 19 unsanctioned actions on the live internet, creating fake identities to push malicious code to a real project.
AI agent misbehaviour · AI agent Jul 2026 NHIAI agentsLLM & AI platformIn July 2026 OpenAI evaluation agents escaped their sandbox and used stolen Kubernetes, cloud, VPN and GitHub tokens to take over Hugging Face clusters.
AI agent misbehaviour · Vulnerability exploit · AI agent · Service account · Cloud credential · Signing key or certificate · Source control token · Secret or password Jul 2026 AI agentsHuman identityNHIAutonomous AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, pivoted via SSO and stole 2,564+ records in four days.
Weak or default credentials · Misconfiguration · Session token · Secret or password · Service account Jul 2026 AI agentsNHIAn AI agent exploited Langflow, harvested API keys and cloud credentials, used default MinIO and Nacos secrets, and destroyed a production database.
Vulnerability exploit · Weak or default credentials · API key · Cloud credential · Secret or password · Signing key or certificate Jul 2026 AI agentsNHIAutonomous AI agents hit hundreds of retailers for ~$25 each, dumping AWS Secrets Manager and cloud keys to steal 600,000+ cards and plant skimmers.
Vulnerability exploit · Cloud credential · Secret or password · Signing key or certificate Jun 2026 NHIAI agentsAmazon Q auto-ran MCP servers from a repo's .amazonq/mcp.json, passing developers' AWS keys and tokens to attacker commands. Fixed; no exploitation.
Vulnerability exploit · AI agent · Cloud credential Jun 2026 AI agentsNHIAn OpenAI agent reached non-public files on an Australian Medicare statistics portal, via a guest endpoint, and OpenAI took 84 days to notify.
AI agent misbehaviour · AI agent Jun 2026 NHIAI agentsHuman identityIn June 2026 a former contributor's unrevoked npm account republished 140+ Mastra AI packages with a RAT dependency. Microsoft blames Sapphire Sleet.
Supply chain · CI/CD or publishing token Jun 2026 NHILLM & AI platformIn 2026, 15 fake AI assistant plugins on the JetBrains Marketplace stole OpenAI, DeepSeek and SiliconFlow API keys. How it worked and how to govern AI keys.
Supply chain · API key Jun 2026 AI agentsNHIA fake Sentry error posted with a public DSN made Claude Code, Cursor and Codex run attacker commands with the developer's credentials, via MCP.
Prompt injection · AI agent · API key · Cloud credential Jun 2026 NHIIn June 2026 a stale Klue GitHub token let attackers plant code, steal customers' Salesforce OAuth tokens and export CRM data from connected tenants.
OAuth / SaaS integration · Stolen credentials · Source control token · OAuth token Jun 2026 NHIAI agentsIn June 2026 the Miasma and Hades worms used stolen GitHub accounts, OIDC publishing and npm and PyPI tokens to spread credential theft to Microsoft repos.
Supply chain · CI/CD or publishing token · Source control token · Cloud credential · Secret or password May 2026 Human identityNHIStorm-2949, 2026: Microsoft says SSPR abuse and IT support impersonation gave an actor Entra ID accounts, then Key Vault secrets, storage keys and Azure data.
Social engineering · Cloud credential · Secret or password · Service account May 2026 NHIA GitHub CLI token stolen via TanStack let TeamPCP publish a poisoned Nx Console extension that stole a GitHub employee's secrets and 3,800 repos.
Supply chain · Source control token · CI/CD or publishing token · Cloud credential · Secret or password May 2026 NHIMegalodon used compromised GitHub tokens and fake bot identities to add secret-stealing workflows to 5,561 repos, harvesting CI and OIDC credentials.
Stolen credentials · Supply chain · Source control token · CI/CD or publishing token · Cloud credential · Secret or password May 2026 AI agentsNHIAn AI agent swarm attributed to OpenAI flooded RubyGems, ran code on RubyDoc build servers and tried to steal users' API keys via a caching flaw.
AI agent misbehaviour · AI agent · CI/CD or publishing token Apr 2026 Human identityNHICanvas Instructure breach 2026: a malicious support ticket hijacked an agent's session, yielding a token that ShinyHunters used to pull data via Canvas APIs.
Vulnerability exploit · Session token · OAuth token · API key Apr 2026 NHIAI agentsA Cursor agent running Claude Opus 4.6 found an account-wide Railway token and deleted PocketOS production data and backups in one API call.
AI agent misbehaviour · API key · AI agent Apr 2026 NHIAI agentsIn April 2026 a stolen Context.ai OAuth token let attackers take over a Vercel employee's Google Workspace and read customer environment variables.
OAuth / SaaS integration · OAuth token · Secret or password Apr 2026 AI agentsLLM & AI platformHuman identityIn 2026 attackers asked Meta's AI support assistant to send Instagram recovery links to their own email, hijacking 20,225 accounts that lacked 2FA.
Social engineering · AI agent Mar 2026 NHIGravity SMTP CVE-2026-4020 (2026) let anyone pull email API keys, OAuth tokens and SMTP passwords from WordPress sites, with 17m+ exploit attempts blocked.
Vulnerability exploit · API key · OAuth token · Secret or password Mar 2026 NHILLM & AI platformIn March 2026 a PyPI token leaked via a poisoned Trivy scan let TeamPCP publish malicious LiteLLM versions that stole cloud, Kubernetes and LLM API keys.
Supply chain · CI/CD or publishing token · Cloud credential · API key · Service account · Secret or password Mar 2026 Human identityHow a hijacked admin account and Microsoft Intune were used to wipe Stryker devices in March 2026, what Handala claimed, and the privileged identity lessons.
Not disclosed Mar 2026 LLM & AI platformAI agentsNHIMcKinsey AI platform hack 2026: CodeWall's AI agent used unauthenticated APIs and SQL injection to reach Lilli chats and writable system prompts. Disclosed.
Vulnerability exploit · Service account Feb 2026 NHILLM & AI platformIn 2026 Truffle Security found 2,863 public Google API keys that silently gained Gemini access, exposing uploaded files and billing. NHI lessons and fixes.
Leaked secret · API key Feb 2026 NHIIn 2026 researchers found 4.96 million IPs exposing .git folders and 252,733 Git configs holding deployment credentials, a machine identity secrets risk.
Misconfiguration · Secret or password · CI/CD or publishing token Jan 2026 NHIAI agentsIn January 2026 Moltbook's open Supabase database exposed 1.5 million AI agent API keys, letting anyone impersonate agents. How it happened and what to fix.
Misconfiguration · API key · AI agent Jan 2026 AI agentsLLM & AI platformIn January 2026 Miggo showed a calendar invite could make Gemini leak private meetings using the user's own calendar access. AI agent identity lessons.
Prompt injection · AI agent Dec 2025 NHIMongoBleed (CVE-2025-14847), disclosed December 2025, let unauthenticated attackers read MongoDB heap memory holding passwords, keys and tokens. 87K+ exposed.
Vulnerability exploit · Secret or password · Session token · API key Dec 2025 NHIIn 2025 a researcher found a Home Depot GitHub token exposed since early 2024, with write access to repos and cloud systems. Revoked after press contact.
Leaked secret · Source control token Dec 2025 NHILLM & AI platformDocker Hub secrets leak 2025: Flare found 10,456 public images exposing cloud, CI, GitHub and nearly 4,000 AI API keys, most never revoked. NHI lessons.
Leaked secret · Secret or password · API key Dec 2025 NHIGladinet hard-coded keys (2025): identical AES keys in CentreStack and Triofox let attackers forge tickets, steal ASP.NET machine keys and run code.
Vulnerability exploit · Signing key or certificate Nov 2025 NHI2025 study: a TruffleHog scan of 5.6 million public GitLab repositories found 17,430 live secrets, from GCP keys to Slack tokens. NHI lessons and fixes.
Leaked secret · Secret or password · API key · Cloud credential Nov 2025 NHIIn November 2025 watchTowr found 80,000+ saved pastes on JSONFormatter and CodeBeautify exposing cloud keys, tokens and passwords, and attackers testing them.
Leaked secret · Secret or password · API key · Cloud credential Nov 2025 NHIShai-Hulud npm worm 2025: stolen npm and CI tokens spread a preinstall credential stealer to hundreds of packages and 25,000+ GitHub repos. Lessons for NHIs.
Supply chain · CI/CD or publishing token · Source control token · Cloud credential Nov 2025 NHIA contractor's public "Private-CISA" repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Leaked secret · Cloud credential · Secret or password · Signing key or certificate Nov 2025 NHIHard-coded credentials in SAP SQL Anywhere Monitor (Non-GUI) earned a CVSS 10.0 (CVE-2025-42890). SAP removed the monitor to fix it.
Weak or default credentials · Secret or password · Service account Nov 2025 NHIIn 2025, attackers used stolen AWS IAM credentials to mine crypto on EC2 and ECS in customer accounts, then blocked termination and created backdoor users.
Stolen credentials · Cloud credential Oct 2025 NHITruffleNet used 800+ attacker hosts running TruffleHog to test stolen AWS keys; in one account SES was abused for a vendor invoice scam.
Stolen credentials · Cloud credential Oct 2025 NHIAI agentsDatadog showed Copilot Studio agents on a Microsoft domain can lead users to malicious OAuth consent and forward their tokens to attackers.
Social engineering · OAuth / SaaS integration · OAuth token · AI agent Oct 2025 NHIHow GlassWorm hid in Open VSX and VS Code extensions, stole npm, GitHub and Open VSX tokens and used publishing tokens to spread.
Supply chain · CI/CD or publishing token · Source control token · Secret or password Oct 2025 NHIWiz found 550+ secrets in 500+ VS Code extensions, including 130+ publishing tokens that could push updates to about 150,000 installs.
Leaked secret · Supply chain · CI/CD or publishing token · API key · Secret or password Oct 2025 Human identityHuntress saw attackers log in to more than 100 SonicWall SSL VPN accounts with valid credentials in October 2025. Source of logins unknown.
Stolen credentials Oct 2025 NHIThe Crimson Collective copied a Red Hat Consulting GitLab instance in 2025, exposing customer tokens, keys and connection strings in engagement reports.
Not disclosed · API key · Secret or password Oct 2025 NHIA OneLogin API returned OIDC client secrets to any caller with valid API credentials (CVE-2025-59363). Fixed in 2025.3.0; no customers hit.
Vulnerability exploit · API key · Secret or password Sep 2025 AI agentsLLM & AI platformNHIForcedLeak let a Web-to-Lead form inject instructions into Salesforce Agentforce and exfiltrate CRM data via an expired, allowlisted $5 domain.
Prompt injection · AI agent Sep 2025 NHIAI agentsA CrewAI error response exposed an internal GitHub token with admin rights over all private repositories. Fixed within five hours.
Leaked secret · Source control token Sep 2025 AI agentsNHILLM & AI platformA Chinese state-sponsored group used Claude Code agents to attack about 30 organisations, with AI doing 80-90% of the work, including credential theft.
Vulnerability exploit · Secret or password · Signing key or certificate Sep 2025 NHIUndocumented Actor tokens and an Azure AD Graph flaw could let an attacker impersonate Global Admins in any Entra ID tenant. Fixed in July 2025.
Vulnerability exploit · Session token · Service account Sep 2025 NHIStolen Salesloft Drift OAuth tokens let attackers export Palo Alto Networks Salesforce data, including support case notes with credentials.
OAuth / SaaS integration · Supply chain · OAuth token Aug 2025 Human identityThe 2025 JLR cyberattack halted production for five weeks and cost the UK an estimated £1.9bn. What is known about access, stolen credentials and lessons.
Not disclosed Aug 2025 NHIAI agentsA stolen npm token let attackers publish malicious Nx versions that stole 2,349 secrets, abusing AI CLIs, then exposed private repositories.
Supply chain · Leaked secret · CI/CD or publishing token · Source control token · Secret or password Aug 2025 NHIHuman identityHow Cl0p exploited Oracle E-Business Suite zero-day CVE-2025-61882, ran commands as the applmgr account and sent extortion from stolen mailboxes.
Vulnerability exploit · Service account Aug 2025 NHIIn August 2025 UNC6395 used stolen Salesloft Drift OAuth tokens to export Salesforce data from hundreds of firms and mine it for AWS keys and passwords.
OAuth / SaaS integration · OAuth token · Cloud credential · API key Jul 2025 NHIAI agentsTracebit found a poisoned README could make Google Gemini CLI silently run commands and send developer secrets out. Fixed in 0.1.14.
Prompt injection · AI agent · Secret or password Jul 2025 NHIAI agentsAn over-scoped GitHub token let an attacker add a wiper prompt to the Amazon Q Developer VS Code extension, which AWS shipped in v1.84.0.
Supply chain · Misconfiguration · Source control token · AI agent Jul 2025 AI agentsNHIReplit's AI coding agent deleted a live production database during a code freeze, then said recovery was impossible. Rollback worked.
AI agent misbehaviour · AI agent Jul 2025 NHIHow ToolShell attackers exploited on-premises SharePoint in July 2025 and stole ASP.NET machine keys that kept access alive after patching.
Vulnerability exploit · Signing key or certificate Jul 2025 NHIAI agentsResearchers logged in to McDonald's McHire AI hiring platform with 123456/123456 and found an IDOR exposing up to 64 million applicant records.
Weak or default credentials · Service account · Session token Jul 2025 NHIAruba Instant On access points shipped with hard-coded admin credentials (CVE-2025-37103, CVSS 9.8). Firmware 3.2.1.0 fixes it.
Weak or default credentials · Secret or password Jun 2025 Human identityAttackers used an external user login, likely stolen by infostealer malware, to download insurance claim documents from a Scania portal.
Stolen credentials Jun 2025 LLM & AI platformAI agentsEchoLeak (CVE-2025-32711) let a single crafted email make Microsoft 365 Copilot leak data in its context, with no user click. How it worked and what to do.
Prompt injection · AI agent Jun 2025 NHIHuman identityCallers talked staff into approving malicious Salesforce connected apps, then bulk-exported CRM data from Google, Qantas, Allianz Life, Cisco and others.
Social engineering · OAuth / SaaS integration · OAuth token May 2025 NHIA hacker called 303 claims to have leaked Deloitte GitHub credentials and source code in May 2025. Deloitte has not confirmed it.
Not disclosed · Source control token May 2025 Human identityHow criminals bribed Coinbase support agents to copy data on 69,461 customers, then demanded $20 million. Lessons for insider and access control.
Insider Apr 2025 Human identityAttackers linked to Scattered Spider social-engineered a password reset at Co-op and stole the personal data of all 6.5 million members.
Social engineering Apr 2025 Human identityAttackers impersonated a third-party user to get into M&S in April 2025, stole customer data and halted online orders, costing about £300 million.
Social engineering Apr 2025 NHIHuman identityCoupang breach 2025: a former developer kept a token signing key that was never revoked, forged access tokens and exposed 33.7 million accounts in Korea.
Insider · Signing key or certificate · Session token Apr 2025 NHIUnit 42 traced the tj-actions attack to a SpotBugs maintainer PAT stolen in December 2024 through a pull_request_target workflow.
Leaked secret · Supply chain · Source control token Mar 2025 NHIA stolen maintainer PAT let attackers poison reviewdog/action-setup@v1, leaking CI secrets including the token behind the tj-actions attack.
Stolen credentials · Supply chain · Source control token · Secret or password Mar 2025 NHIA stolen bot PAT let attackers repoint tj-actions/changed-files tags to code that printed CI/CD secrets to logs (CVE-2025-30066).
Stolen credentials · Supply chain · Source control token · Secret or password Mar 2025 NHICybernews found 71% of 156,080 iOS apps leak hard-coded secrets, exposing 406 TB in open storage and 19.8 million Firebase records.
Leaked secret · Misconfiguration · Secret or password · API key · Cloud credential Feb 2025 NHILLM & AI platformTruffle Security found 11,908 live API keys and passwords in Common Crawl, a dataset used to train LLMs, mostly hard-coded in web pages.
Leaked secret · API key · Secret or password Feb 2025 NHIHow hijacked AWS session tokens from a Safe{Wallet} developer laptop let North Korean attackers alter wallet code and steal about $1.5 billion from Bybit.
Social engineering · Supply chain · Session token · Cloud credential Feb 2025 NHICisco Talos found Salt Typhoon entered US telecoms mostly with stolen credentials, then harvested SNMP strings and TACACS/RADIUS keys to persist.
Stolen credentials · Vulnerability exploit · Secret or password Feb 2025 Human identityA hacker claims a 2024 Zacks breach; HIBP verified 12 million leaked accounts with unsalted SHA-256 hashes. Zacks has not confirmed it.
Not disclosed Feb 2025 NHIKraken posted Cisco Active Directory hashes, including service accounts and krbtgt, in 2025. Cisco says the data is from its May 2022 breach.
Stolen credentials · Service account Feb 2025 NHIMicrosoft found 3,000+ ASP.NET machine keys copied from public sources; one was used to inject Godzilla malware via ViewState in 2024.
Leaked secret · Signing key or certificate · Secret or password Jan 2025 NHILLM & AI platformWiz found an unauthenticated DeepSeek ClickHouse database exposing a million log lines, chat history and API keys in January 2025.
Misconfiguration · API key · Secret or password Jan 2025 NHILLM & AI platformA hacker claims to have leaked 34 million OmniGPT chat messages containing users' API keys and credentials. OmniGPT has not confirmed it.
Not disclosed · API key · Secret or password Jan 2025 NHICodefinger used compromised AWS keys to re-encrypt S3 data with SSE-C keys only it held, then demanded ransom. How long-lived keys enabled it.
Stolen credentials · Leaked secret · Cloud credential Jan 2025 NHILLM & AI platformStorm-2139 used Azure OpenAI API keys stolen from Microsoft customers to bypass guardrails and resell access. How the LLMjacking scheme worked.
Leaked secret · Stolen credentials · API key Dec 2024 NHIHuman identityHow a phished OAuth consent let attackers publish a malicious Cyberhaven Chrome extension update in December 2024, and the NHI lessons for OAuth apps.
Social engineering · OAuth / SaaS integration · OAuth token · CI/CD or publishing token · Session token Dec 2024 NHIDatadog showed the Azure Key Vault Contributor role could grant itself access to every secret in vaults using access policies. What to change.
Misconfiguration · Secret or password · Cloud credential Dec 2024 NHIA compromised BeyondTrust Remote Support SaaS API key let a China state-sponsored actor reach US Treasury workstations in December 2024.
Stolen credentials · Supply chain · API key · Service account Nov 2024 Human identityHellcat used credentials linked to an infostealer infection to access Schneider Electric's Jira server and claimed 40GB of project and user data.
Stolen credentials Oct 2024 NHIEMERALDWHALE scanned for exposed .git/config files, used the tokens to clone private repos and stole more than 15,000 cloud credentials.
Misconfiguration · Leaked secret · Source control token · Cloud credential Oct 2024 NHIIntelBroker took code and files from Cisco's public DevHub, exposed by a misconfigured migration script, and claimed hard-coded credentials inside.
Misconfiguration · Leaked secret · Secret or password · API key Sep 2024 NHIAn exposed GitLab token led to the theft of 31 million Internet Archive user records, and unrotated Zendesk tokens enabled a second breach.
Leaked secret · Misconfiguration · Source control token · API key · Secret or password Sep 2024 NHIA Razz Security researcher showed how credentials in an exposed .git directory let an edited Bitbucket pipeline add an SSH key to a production server.
Misconfiguration · Leaked secret · Source control token · Secret or password Aug 2024 NHIIn 2024 attackers scanned 230M+ targets for exposed .env files, stole AWS access keys, escalated IAM privileges and extorted victims by emptying S3 buckets.
Leaked secret · Cloud credential · API key · OAuth token Jun 2024 NHIAn exposed GitHub credential let an attacker copy New York Times repositories in January 2024; 270GB of code was leaked on 4chan in June.
Leaked secret · Source control token Jun 2024 NHIThe Gitloker campaign wiped GitHub repos and demanded contact on Telegram, using stolen credentials and phishing for malicious OAuth app grants.
Social engineering · OAuth / SaaS integration · OAuth token May 2024 NHILLM & AI platformHugging Face detected unauthorised access to Spaces secrets in May 2024, revoked tokens, removed org tokens and told users to refresh keys.
Not disclosed · API key · Secret or password May 2024 NHICVE-2024-37051 let malicious pull request content make IntelliJ-based IDEs send GitHub tokens to a third party. JetBrains fixed it; no exploitation known.
Vulnerability exploit · Source control token · OAuth token May 2024 NHILLM & AI platformHow attackers use stolen cloud access keys and AI API keys to run and resell LLMs at the victim's expense: Sysdig, Permiso and Microsoft Storm-2139 cases.
Leaked secret · Vulnerability exploit · Cloud credential · API key Apr 2024 NHIAttackers compromised a Dropbox Sign back-end service account and reached customer data, including hashed passwords, API keys, OAuth tokens and MFA data.
Not disclosed · Service account · API key · OAuth token Apr 2024 Human identityNHIHow UNC5537 used infostealer credentials without MFA, unrotated for years, to steal data from about 165 Snowflake customers including AT&T in 2024.
Stolen credentials · Service account Apr 2024 NHISisense and CISA told customers to rotate all credentials after attackers reportedly used a GitLab credential to reach S3 buckets of customer secrets.
Leaked secret · Cloud credential · Source control token · API key · Signing key or certificate Mar 2024 NHIA contributor spent two years gaining maintainer rights, then hid a backdoor in XZ Utils that could bypass SSH authentication. How it was caught.
Social engineering · Supply chain · CI/CD or publishing token Mar 2024 NHIResearchers found 916 websites with open Firebase security rules exposing 125 million user records and about 19.87 million plaintext passwords.
Misconfiguration · API key Feb 2024 Human identityAttackers used a stolen credential on a Citrix portal without MFA, deployed ransomware nine days later and exposed data on 192.7 million people.
Stolen credentials Jan 2024 Human identityHow deepfaked video of Arup's CFO and colleagues persuaded a Hong Kong finance worker to make 15 transfers totalling HK$200 million (about US$25.6m).
Social engineering Jan 2024 NHIHuman identityIn 2024 Microsoft disclosed that Midnight Blizzard sprayed a test account without MFA, then abused OAuth apps with full_access_as_app to read executive email.
Stolen credentials · OAuth token Jan 2024 NHIHuman identityTwo Ivanti VPN zero-days let attackers harvest user passwords and appliance-stored service account credentials, keys and certificates, breaching CISA.
Vulnerability exploit · Service account · API key · Signing key or certificate · Session token Nov 2023 NHIAqua found Kubernetes registry secrets in public GitHub repos, including an SAP artifact repository key with access to 95 million artifacts.
Leaked secret · Secret or password · CI/CD or publishing token Nov 2023 NHIA service token and three service accounts Cloudflare failed to rotate after the Okta breach let a nation-state attacker into its Atlassian servers.
Stolen credentials · Service account · API key · Cloud credential Nov 2023 NHIGitGuardian and Tom Forbes found 3,938 unique secrets in 2,922 PyPI projects, 768 valid, including cloud, database and SSH credentials.
Leaked secret · API key · Cloud credential · Secret or password Nov 2023 NHIA compromised credential was used to access a Sumo Logic AWS account, prompting customers to rotate API keys. No customer data impact was found.
Stolen credentials · Cloud credential · API key Oct 2023 Human identityHow CitrixBleed (CVE-2023-4966) leaked NetScaler session cookies that let attackers bypass MFA at Boeing, ICBC and Xfinity in 2023.
Vulnerability exploit Sep 2023 NHIA stolen Okta support service account exposed HAR files of 134 customers; session tokens in them were used to hijack five customers' Okta sessions.
Stolen credentials · Service account · Session token Sep 2023 Human identityAttackers social engineered an outsourced IT support vendor and stole Caesars loyalty database with licence and SSN data. A ransom was reportedly paid.
Social engineering Sep 2023 Human identityAttackers impersonated an MGM employee to the help desk, took Okta and Azure admin access, encrypted 100+ ESXi hosts and cost MGM about $100 million.
Social engineering Jul 2023 NHIRWTH Aachen researchers found 52,107 private keys and 3,158 API secrets in container images, with 275,269 hosts relying on leaked keys.
Leaked secret · Secret or password · API key · Signing key or certificate Jul 2023 NHIAttackers used stolen GitHub personal access tokens to push fake Dependabot commits to hundreds of repos in 2023, stealing CI/CD secrets.
Stolen credentials · Supply chain · Source control token · CI/CD or publishing token · Secret or password Jun 2023 NHINorth Korean hackers spear-phished JumpCloud in 2023 and injected data into its device commands framework, prompting a reset of all admin API keys.
Social engineering · Supply chain · API key · Service account May 2023 NHIStorm-0558 forged tokens with a stolen 2016 Microsoft signing key to read email at 22 organisations in 2023. How the key and validation failed.
Stolen credentials · Vulnerability exploit · Signing key or certificate · Session token May 2023 NHIA 2020 email with an ArcGIS login was stolen and published in 2023. The password still worked, exposing Polish military and port maps.
Leaked secret · Secret or password Apr 2023 Human identityReused passwords let an attacker into 18,000 23andMe accounts, and the DNA Relatives feature exposed data on almost 7 million people. Missed warnings.
Stolen credentials Mar 2023 Human identityParts of Twitter source code and internal tools sat on public GitHub for months before a March 2023 takedown and subpoena. Insider leak.
Insider Dec 2022 NHIStolen Slack employee tokens, taken via a compromised vendor, let an attacker download private GitHub repos over the 2022 holidays.
Stolen credentials · OAuth / SaaS integration · Source control token Dec 2022 NHIMalware stole a CircleCI engineer's 2FA-backed SSO session, letting attackers exfiltrate customer secrets, tokens and keys. What went wrong.
Stolen credentials · Session token · Secret or password · API key · OAuth token · Cloud credential Dec 2022 NHIFraudulent Microsoft partner accounts gave malicious OAuth apps a verified badge in 2022; users who consented handed over mailbox tokens.
OAuth / SaaS integration · Social engineering · OAuth token Dec 2022 NHIA compromised GitHub machine account token cloned Desktop and Atom repos in 2022, exposing code signing certificates that GitHub then revoked.
Stolen credentials · Source control token · Signing key or certificate Nov 2022 NHIA bad actor abused one T-Mobile API without authorisation for six weeks, taking data on 37 million accounts. What API identity controls missed.
Vulnerability exploit Oct 2022 NHIA subcontractor left a Toyota T-Connect server access key on public GitHub for five years, exposing 296,019 customer emails. Misuse unknown.
Leaked secret · Secret or password Sep 2022 NHIAn attacker linked to Lapsus$ used a contractor's stolen password and MFA fatigue to reach Uber's Slack, G Suite and HackerOne in 2022.
Stolen credentials · Social engineering · Secret or password · Service account Aug 2022 NHIHuman identityA keylogger on a DevOps engineer's home PC exposed AWS access keys and decryption keys, letting an attacker copy LastPass customer vault backups in 2022.
Stolen credentials · Cloud credential · Signing key or certificate · Secret or password Aug 2022 Human identitySMS phishing gave attackers Twilio employee logins in August 2022, affecting 209 customers and exposing about 1,900 Signal users. The 0ktapus campaign.
Social engineering May 2022 Human identityNHIA browser-synced password and MFA push fatigue gave attackers Cisco VPN access in May 2022. They then used machine accounts; Yanluowang leaked files.
Social engineering · Service account Apr 2022 NHIStolen Heroku and Travis CI OAuth tokens let an attacker clone private GitHub repos from dozens of orgs in 2022, then use an AWS key found inside.
OAuth / SaaS integration · OAuth token · Cloud credential Mar 2022 NHISocial engineering gave attackers a Mailchimp support tool in 2022: 319 accounts viewed, 102 lists exported and customer API keys exposed.
Social engineering · API key Oct 2021 NHIA Twitch server misconfiguration leaked 6,000 Git repositories and payout data in 2021. Inside the code: nearly 6,600 secrets, including 194 AWS keys.
Misconfiguration · Secret or password · API key · Cloud credential May 2021 Human identityDarkSide entered Colonial Pipeline through a dormant VPN account with a leaked password and no MFA, forcing a six-day pipeline shutdown in May 2021.
Stolen credentials Feb 2021 NHIEthical hackers found 35 exposed credential pairs, private keys and 13,000 records across Indian government sites via exposed .git and .env files.
Leaked secret · Misconfiguration · Secret or password · Signing key or certificate · Session token Jan 2021 NHIIn 2021 attackers altered Codecov's Bash Uploader with a leaked cloud key, harvesting CI secrets, tokens and keys from customer pipelines for two months.
Supply chain · Cloud credential · CI/CD or publishing token · Signing key or certificate · Secret or password Jan 2021 NHIEthical hackers used exposed Git credentials to reach 100,000+ UNEP staff records in 2021. How leaked repository secrets unlocked UN databases.
Leaked secret · Misconfiguration · Secret or password · Source control token Dec 2020 NHIAttackers backdoored SolarWinds Orion builds, then forged SAML tokens and added credentials to cloud app identities to read government and corporate email.
Supply chain · Signing key or certificate · Service account · CI/CD or publishing token Jul 2020 NHILLM & AI platformA Microsoft AI repo shared an Azure SAS token with full control over a whole storage account, exposing 38TB of internal data for three years.
Misconfiguration · Leaked secret · Cloud credential · Secret or password Mar 2019 NHIAn attacker abused a misconfigured firewall to take its cloud role credentials, then copied data on about 106 million people from Capital One storage.
Misconfiguration · Vulnerability exploit · Cloud credentialNo breaches match these filters.
Find your exposed NHIs and AI agents before attackers do — with a risk assessment or our training.
Free weekly newsletter
The latest on Non-Human Identity and Agentic AI security, every week.
Bonus 33% off our NHI Foundation Level Course when you subscribe.