# Non-Human Identity (NHI) Attacks: Over-Privileged, Long-Lived Credentials on Service Accounts, Scripts, IoT and Third-Party Integrations

> Non-human identities (service accounts, scripts, IoT devices, third-party integrations) frequently hold excessive privileges and authenticate with long-lived tokens or keys that cannot use 2FA, so a single stolen credential grants durable, hard-to-detect access. Sweet Security's guidance and the OWASP NHI Top 10 frame this as a conceptual, widespread identity risk rather than a single campaign.

- **Published:** 2026-10-11T13:36:25Z
- **Last reviewed:** 2026-10-11T13:36:25Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3305
- **ID:** TL-2026-3305
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Sweet Security (Sarah Elkaim, 2024-07-16) describes attacks that target non-human identities (NHIs): automated scripts, service accounts, IoT devices and third-party integrations. The article identifies three core weaknesses. First, NHIs commonly possess very high access privileges that grant near-unrestricted access to sensitive data. Second, NHIs cannot be protected with two-factor authentication and typically rely on long-lived tokens or keys, so they are exposed once the secret is compromised. Third, multi-cloud environments use differing authentication mechanisms and lifecycle practices, which makes NHIs hard to inventory and track.

The only scenario given is hypothetical: a developer integrates a third-party SaaS tool with access to critical data repositories such as GitHub or Google Drive; if that third party is breached, the tokens used by its NHIs can be stolen and the attacker can impersonate those identities. The article names no actors, malware, CVEs or IOCs and cites no specific breach.

The OWASP Non-Human Identities Top 10 (released 2025-01-14) corroborates and broadens the picture: NHI1 Improper Offboarding, NHI2 Secret Leakage, NHI3 Vulnerable Third-Party NHIs, NHI4 Insecure Authentication, NHI5 Overprivileged NHIs, NHI6 Insecure Cloud Deployment Configurations, NHI7 Long-Lived Secrets, NHI8 Environment Isolation, NHI9 NHI Reuse, NHI10 Human Use of NHIs. Secondary reporting on the OWASP list cites Microsoft's Midnight Blizzard compromise (2024), the Internet Archive Zendesk compromise (2024) and the Okta support system compromise (2023) as incidents illustrating NHI-related credential failures; this record does not independently verify those incidents' root causes. Secondary sources also state that organizations commonly have 10 to 50 times more NHIs than human identities.

This is a conceptual, low-confidence identity-threat record. No active exploitation, PoC, KEV listing or attribution is stated in the sources; severity MEDIUM is analyst-assigned. Mitigations stated by the source: robust NHI inventory, runtime monitoring for anomalous access, short-lived tokens, least privilege, automated token revocation, and deprecation of unused NHIs.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1078.004 Valid Accounts: Cloud Accounts
- T1199 Trusted Relationship
- T1528 Steal Application Access Token
- T1552.001 Unsecured Credentials: Credentials In Files
- T1550.001 Use Alternate Authentication Material: Application Access Token
- T1098.001 Account Manipulation: Additional Cloud Credentials
- T1530 Data from Cloud Storage

## Sources

- [Practical Ways to Thwart Non-Human Identity Attacks (Sarah Elkaim, Sweet Security)](https://www.sweet.security/blog/practical-ways-to-thwart-non-human-identity-attacks)
- [OWASP NHI Top 10 (Cyber Security News)](https://cybersecuritynews.com/owasp-nhi-top-10/)
- [OWASP's Top Security Risks for Non-Human Identities and How to Address Them (Aembit)](https://aembit.io/blog/owasps-top-security-risks-for-non-human-identities-and-how-to-address-them/)
- [OWASP reveals top 10 non-human identity threats (SecureBlink)](https://www.secureblink.com/threat-feeds/owasp-reveals-top-10-non-human-identity-threats)
- [Service Account Persistence (Non-Human & AI Identity Journal)](https://nhimg.org/glossary/service-account-persistence/)
- [What breaks when service accounts keep long-lived standing access (NHI Management Group)](https://nhimg.org/faq/what-breaks-when-service-accounts-keep-long-lived-standing-access/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3305
