Threat reportThreat IntelligenceTL-2026-3305

Non-Human Identity (NHI) Attacks: Over-Privileged, Long-Lived Credentials on Service Accounts, Scripts, IoT and Third-Party Integrations

mediumMONITORING

Non-Human Identity (NHI) Attacks (TL-2026-3305), also tracked as NHI compromise, is a medium-severity tracked intrusion set, first published 2026-10-11. It has no confirmed attribution, affects Multi-vendor Cloud service accounts, API keys and OAuth/access tokens, maps to 8 MITRE ATT&CK techniques (T1078, T1078.004, T1098.001), and is covered by 9 detection rules and 6 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
6Indicators of compromise

Key facts for TL-2026-3305

Threat ID
TL-2026-3305
Also known as
NHI compromise, Machine identity abuse
Severity
MEDIUM
Status
MONITORING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, cloud, finance, government administration, health
Target regions
Global
Detection rules
9
Indicators of compromise
6

How Non-Human Identity (NHI) Attacks works

Non-human identities (service accounts, scripts, IoT devices, third-party integrations) frequently hold excessive privileges and authenticate with long-lived tokens or keys that cannot use 2FA, so a single stolen credential grants durable, hard-to-detect access. Sweet Security's guidance and the OWASP NHI Top 10 frame this as a conceptual, widespread identity risk rather than a single campaign.

Sweet Security (Sarah Elkaim, 2024-07-16) describes attacks that target non-human identities (NHIs): automated scripts, service accounts, IoT devices and third-party integrations. The article identifies three core weaknesses. First, NHIs commonly possess very high access privileges that grant near-unrestricted access to sensitive data. Second, NHIs cannot be protected with two-factor authentication and typically rely on long-lived tokens or keys, so they are exposed once the secret is compromised. Third, multi-cloud environments use differing authentication mechanisms and lifecycle practices, which makes NHIs hard to inventory and track.

The only scenario given is hypothetical: a developer integrates a third-party SaaS tool with access to critical data repositories such as GitHub or Google Drive; if that third party is breached, the tokens used by its NHIs can be stolen and the attacker can impersonate those identities. The article names no actors, malware, CVEs or IOCs and cites no specific breach.

The OWASP Non-Human Identities Top 10 (released 2025-01-14) corroborates and broadens the picture: NHI1 Improper Offboarding, NHI2 Secret Leakage, NHI3 Vulnerable Third-Party NHIs, NHI4 Insecure Authentication, NHI5 Overprivileged NHIs, NHI6 Insecure Cloud Deployment Configurations, NHI7 Long-Lived Secrets, NHI8 Environment Isolation, NHI9 NHI Reuse, NHI10 Human Use of NHIs. Secondary reporting on the OWASP list cites Microsoft's Midnight Blizzard compromise (2024), the Internet Archive Zendesk compromise (2024) and the Okta support system compromise (2023) as incidents illustrating NHI-related credential failures; this record does not independently verify those incidents' root causes. Secondary sources also state that organizations commonly have 10 to 50 times more NHIs than human identities.

This is a conceptual, low-confidence identity-threat record. No active exploitation, PoC, KEV listing or attribution is stated in the sources; severity MEDIUM is analyst-assigned. Mitigations stated by the source: robust NHI inventory, runtime monitoring for anomalous access, short-lived tokens, least privilege, automated token revocation, and deprecation of unused NHIs.

MITRE ATT&CK techniques used in TL-2026-3305

Initial Access

T1078 Valid Accounts; T1078.004 Valid Accounts: Cloud Accounts; T1199 Trusted Relationship

Persistence

T1098.001 Account Manipulation: Additional Cloud Credentials

Credential Access

T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files

Collection

T1530 Data from Cloud Storage

lateral-movement

T1550.001 Use Alternate Authentication Material: Application Access Token

Affected products and versions in Non-Human Identity (NHI) Attacks

  • Multi-vendor — Cloud service accounts, API keys and OAuth/access tokens, CI/CD and SaaS integrations, IoT device identities
    Vulnerable versions: Environments with over-privileged, long-lived NHI credentials

Remediation for Non-Human Identity (NHI) Attacks

Immediate actions

  • Inventory all NHIs (service accounts, API keys, tokens, scripts, IoT identities, third-party integrations) and their permissions across every cloud
  • Revoke and rotate tokens and keys belonging to unused, orphaned or unowned NHIs
  • Review third-party SaaS integrations holding access to GitHub, Google Drive and other critical repositories

Workarounds

  • Compensate for the lack of 2FA with network/source restrictions and anomaly alerting on NHI authentication

Longer-term hardening

  • Replace long-lived tokens and keys with short-lived, automatically rotated credentials
  • Enforce least privilege for every NHI and scope tokens narrowly
  • Deploy runtime monitoring for anomalous NHI access behavior
  • Automate token revocation and deprecate NHIs that are no longer used

Weaknesses (CWE) in Non-Human Identity (NHI) Attacks

CWE-250, CWE-798, CWE-522

Timeline of Non-Human Identity (NHI) Attacks

  • Okta discloses compromise of its customer support system, cited by OWASP-related reporting as an example of credential-related identity failure
  • Microsoft discloses the Midnight Blizzard compromise of corporate systems, cited as an NHI/credential failure example in OWASP-related reporting
  • Sweet Security publishes 'Practical Ways to Thwart Non-Human Identity Attacks' describing over-privileged, long-lived NHI credentials without 2FA
  • Internet Archive Zendesk support platform compromise becomes public, cited as an NHI-related incident in OWASP-related reporting
  • OWASP releases the first Non-Human Identities Top 10 (NHI1-NHI10) covering offboarding, secret leakage, overprivilege and long-lived secrets
  • Threat tracked by Threadlinqs as a low-confidence conceptual identity-threat record; no active exploitation stated in sources

Sources cited for Non-Human Identity (NHI) Attacks

Detection coverage for TL-2026-3305

As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3305 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
6 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats