Attack vector
Service-account or non-human identity abuse
Service-account or non-human identity abuse is the use of machine credentials as a way in. API keys, service accounts, OAuth apps, bots and workload tokens often hold broad permissions, usually cannot use interactive MFA and rarely rotate. They also live in code, scripts and configuration files, where an attacker who finds one can sign in as a trusted system.
Machine credentials used as a way in.
How attackers use it
Attackers search code repositories, build logs, cloud storage and compromised servers for keys and tokens left in plain text. A service account with a password that has not changed in years, or an OAuth app granted wide access, lets them act as a trusted system. Machine activity is noisy and expected, so misuse can go unnoticed.
What breach letters say
None of the 2,161 California breach filings in the ledger (January 1, 2023 – August 14, 2026) names this vector. That says what notification letters disclose, not how often it happens.
How to stop it
Govern non-human identities with an inventory of every service account, key and app grant, each with a named owner, least-privilege scope and scheduled rotation. Keep secrets in a vault rather than in code or configuration files.
Terms under this vector
- Non-human identity
A non-human identity is any account or credential used by software rather than a person, such as a service account, API key, access token, certificate or workload identity.
- OAuth consent phishing
OAuth consent phishing is an attack that tricks a user or administrator into authorizing a malicious application to access their account or organization.
- Secrets sprawl
Secrets sprawl is the spread of passwords, API keys, tokens and private keys into places they should not live, such as source code, public repositories, chat messages, tickets and config files.
Threat actors tied to it
- APT29
Profile with government sources
Last reviewed Oct 2, 2026