Avatier

Service-account or non-human identity abuse

Non-human identity

Also called: machine identity, service account abuse

A non-human identity is any account or credential used by software rather than a person, such as a service account, API key, access token, certificate or workload identity. These identities often hold broad, long-lived access, skip MFA and have no clear owner, which makes them attractive to attackers and easy to overlook in reviews.

How it works

Applications, scripts and integrations are given credentials to talk to each other, and those credentials are rarely rotated. An attacker who finds one in code, a config file or a compromised system can use it to call APIs directly. Because the traffic looks like normal automation, misuse can continue unnoticed for a long time.

A real example

Cloudflare said in February 2024 that attackers reached some of its internal systems using one access token and three service account credentials that had been taken, and that Cloudflare failed to rotate, after a supplier's October 2023 breach.

Source: Thanksgiving 2023 security incident — Cloudflare, 2024-02-01

How to stop it

Inventory every non-human identity with a named owner, give each the narrowest scope, prefer short-lived credentials, and rotate all of them after any related breach.

Related terms

Threat actors that use it

  • APT29

    Profile with government sources

Sources

  1. Thanksgiving 2023 security incident — Cloudflare, 2024-02-01

Last reviewed Oct 2, 2026