Avatier

Attack vector

Service-account or non-human identity abuse

Service-account or non-human identity abuse is the use of machine credentials as a way in. API keys, service accounts, OAuth apps, bots and workload tokens often hold broad permissions, usually cannot use interactive MFA and rarely rotate. They also live in code, scripts and configuration files, where an attacker who finds one can sign in as a trusted system.

Machine credentials used as a way in.

How attackers use it

Attackers search code repositories, build logs, cloud storage and compromised servers for keys and tokens left in plain text. A service account with a password that has not changed in years, or an OAuth app granted wide access, lets them act as a trusted system. Machine activity is noisy and expected, so misuse can go unnoticed.

What breach letters say

None of the 2,161 California breach filings in the ledger (January 1, 2023 – August 14, 2026) names this vector. That says what notification letters disclose, not how often it happens.

See the Identity Attack Ledger

How to stop it

Govern non-human identities with an inventory of every service account, key and app grant, each with a named owner, least-privilege scope and scheduled rotation. Keep secrets in a vault rather than in code or configuration files.

Terms under this vector

  • Non-human identity

    A non-human identity is any account or credential used by software rather than a person, such as a service account, API key, access token, certificate or workload identity.

  • OAuth consent phishing

    OAuth consent phishing is an attack that tricks a user or administrator into authorizing a malicious application to access their account or organization.

  • Secrets sprawl

    Secrets sprawl is the spread of passwords, API keys, tokens and private keys into places they should not live, such as source code, public repositories, chat messages, tickets and config files.

Threat actors tied to it

  • APT29

    Profile with government sources

Last reviewed Oct 2, 2026