A new SpyCloud study claims that compromised non-human identities (NHIs), including AI agents, service accounts, API keys and authentication tokens, are now the number one entry point for hackers into enterprises. Based on a survey of 750 cybersecurity leaders and practitioners at organisations with 500+ employees across North America, the UK, and several European countries, NHIs accounted for 31% of intrusions, well ahead of phishing at 17%.
The findings come with a stark caveat: while 95% of organisations say they have visibility into NHIs, only 36% actually monitor them, rendering machine identities the least-watched identity risk category. The report notes that 68% of respondents experienced an identity-based event in the period, with NHI-related misuse affecting 42%.
The study highlights governance gaps and supply-chain exposure as key drivers. Although most respondents use AI tools with access to internal systems, only 56% have formal processes to govern privileges, with 41% relying on informal or partial ownership. Those organisations with insight into stolen session cookies experienced identity-based events at a significantly lower rate (37%) than those that lacked visibility (50%).
Supply-chain identity events were linked to malware-infected third-party devices (23%) and exposed vendor/API keys (22%), while nearly two-fifths admitted no consistent process to confirm third-party identity exposure. About a third (32%) said they plan to prioritise supply-chain risk management in the next 12–18 months. Hilligoss emphasised that every control shifts attackers toward uncovered surfaces, leaving gaps that attackers will exploit.