Threat reportThreat IntelligenceTL-2026-3305
Non-Human Identity (NHI) Attacks: Over-Privileged, Long-Lived Credentials on Service Accounts, Scripts, IoT and Third-Party Integrations
Non-Human Identity (NHI) Attacks (TL-2026-3305), also tracked as NHI compromise, is a medium-severity tracked intrusion set, first published 2026-10-11. It has no confirmed attribution, affects Multi-vendor Cloud service accounts, API keys and OAuth/access tokens, maps to 8 MITRE ATT&CK techniques (T1078, T1078.004, T1098.001), and is covered by 9 detection rules and 6 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 6Indicators of compromise
Key facts for TL-2026-3305
- Threat ID
- TL-2026-3305
- Also known as
- NHI compromise, Machine identity abuse
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud, finance, government administration, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 6
How Non-Human Identity (NHI) Attacks works
Non-human identities (service accounts, scripts, IoT devices, third-party integrations) frequently hold excessive privileges and authenticate with long-lived tokens or keys that cannot use 2FA, so a single stolen credential grants durable, hard-to-detect access. Sweet Security's guidance and the OWASP NHI Top 10 frame this as a conceptual, widespread identity risk rather than a single campaign.
Sweet Security (Sarah Elkaim, 2024-07-16) describes attacks that target non-human identities (NHIs): automated scripts, service accounts, IoT devices and third-party integrations. The article identifies three core weaknesses. First, NHIs commonly possess very high access privileges that grant near-unrestricted access to sensitive data. Second, NHIs cannot be protected with two-factor authentication and typically rely on long-lived tokens or keys, so they are exposed once the secret is compromised. Third, multi-cloud environments use differing authentication mechanisms and lifecycle practices, which makes NHIs hard to inventory and track.
The only scenario given is hypothetical: a developer integrates a third-party SaaS tool with access to critical data repositories such as GitHub or Google Drive; if that third party is breached, the tokens used by its NHIs can be stolen and the attacker can impersonate those identities. The article names no actors, malware, CVEs or IOCs and cites no specific breach.
The OWASP Non-Human Identities Top 10 (released 2025-01-14) corroborates and broadens the picture: NHI1 Improper Offboarding, NHI2 Secret Leakage, NHI3 Vulnerable Third-Party NHIs, NHI4 Insecure Authentication, NHI5 Overprivileged NHIs, NHI6 Insecure Cloud Deployment Configurations, NHI7 Long-Lived Secrets, NHI8 Environment Isolation, NHI9 NHI Reuse, NHI10 Human Use of NHIs. Secondary reporting on the OWASP list cites Microsoft's Midnight Blizzard compromise (2024), the Internet Archive Zendesk compromise (2024) and the Okta support system compromise (2023) as incidents illustrating NHI-related credential failures; this record does not independently verify those incidents' root causes. Secondary sources also state that organizations commonly have 10 to 50 times more NHIs than human identities.
This is a conceptual, low-confidence identity-threat record. No active exploitation, PoC, KEV listing or attribution is stated in the sources; severity MEDIUM is analyst-assigned. Mitigations stated by the source: robust NHI inventory, runtime monitoring for anomalous access, short-lived tokens, least privilege, automated token revocation, and deprecation of unused NHIs.
MITRE ATT&CK techniques used in TL-2026-3305
Initial Access
T1078 Valid Accounts; T1078.004 Valid Accounts: Cloud Accounts; T1199 Trusted Relationship
Persistence
T1098.001 Account Manipulation: Additional Cloud Credentials
Credential Access
T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files
Collection
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Affected products and versions in Non-Human Identity (NHI) Attacks
- Multi-vendor — Cloud service accounts, API keys and OAuth/access tokens, CI/CD and SaaS integrations, IoT device identities
Vulnerable versions: Environments with over-privileged, long-lived NHI credentials
Remediation for Non-Human Identity (NHI) Attacks
Immediate actions
- Inventory all NHIs (service accounts, API keys, tokens, scripts, IoT identities, third-party integrations) and their permissions across every cloud
- Revoke and rotate tokens and keys belonging to unused, orphaned or unowned NHIs
- Review third-party SaaS integrations holding access to GitHub, Google Drive and other critical repositories
Workarounds
- Compensate for the lack of 2FA with network/source restrictions and anomaly alerting on NHI authentication
Longer-term hardening
- Replace long-lived tokens and keys with short-lived, automatically rotated credentials
- Enforce least privilege for every NHI and scope tokens narrowly
- Deploy runtime monitoring for anomalous NHI access behavior
- Automate token revocation and deprecate NHIs that are no longer used
Weaknesses (CWE) in Non-Human Identity (NHI) Attacks
Timeline of Non-Human Identity (NHI) Attacks
- Okta discloses compromise of its customer support system, cited by OWASP-related reporting as an example of credential-related identity failure
- Microsoft discloses the Midnight Blizzard compromise of corporate systems, cited as an NHI/credential failure example in OWASP-related reporting
- Sweet Security publishes 'Practical Ways to Thwart Non-Human Identity Attacks' describing over-privileged, long-lived NHI credentials without 2FA
- Internet Archive Zendesk support platform compromise becomes public, cited as an NHI-related incident in OWASP-related reporting
- OWASP releases the first Non-Human Identities Top 10 (NHI1-NHI10) covering offboarding, secret leakage, overprivilege and long-lived secrets
- Threat tracked by Threadlinqs as a low-confidence conceptual identity-threat record; no active exploitation stated in sources
Sources cited for Non-Human Identity (NHI) Attacks
- Practical Ways to Thwart Non-Human Identity Attacks (Sarah Elkaim, Sweet Security)
- OWASP NHI Top 10 (Cyber Security News)
- OWASP's Top Security Risks for Non-Human Identities and How to Address Them (Aembit)
- OWASP reveals top 10 non-human identity threats (SecureBlink)
- Service Account Persistence (Non-Human & AI Identity Journal)
- What breaks when service accounts keep long-lived standing access (NHI Management Group)
Detection coverage for TL-2026-3305
As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3305 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.