Silhouette of person in front of digital code background.

How Non-Human Identities Are Reshaping Risk in Software and Technology

Table of Contents

Check your exposure

AI access is sprawling

TL;DR

Source note: Unless otherwise noted, findings in this article are based on SpyCloud’s 2026 Identity Threat benchmark research – a survey conducted in June 2026, that was the basis for the 2026 SpyCloud Identity Threat Report.

Software and technology companies depend on identities at nearly every stage of building and operating a product, perhaps more than any other industry. Developers connect to repositories and cloud infrastructure, applications call APIs, service accounts run automated processes, and AI agents gain access to internal systems and data.

This year alone, two separate reports show how directly attackers exploit those identities. Microsoft documented an AI-enabled device-code phishing campaign that used generative AI to personalize lures and abuse OAuth device-code authentication, resulting in valid access and refresh tokens without password theft. Anthropic reported a separate operation in which an actor used AI for reconnaissance, phishing infrastructure, credential theft, and Microsoft 365 token theft. 

SpyCloud’s 2026 Identity Threat Report shows this exposure isn’t limited to headline incidents. Non-human identities, including API keys, service accounts, tokens, and AI agents, now play a central role in identity risk, alongside employee credentials, unmanaged devices, and third-party access.

Software and technology teams are dealing with recurring identity exposure

While software and technology organizations were affected slightly less often than the overall benchmark – 64% had at least one identity-based incident – affected teams saw events repeat far more frequently. Among affected organizations:

69%

reported six to 10 identity-based events during the year, compared with 49% overall

47%

saw leadership changes or organizational restructuring vs. 36% overall

23%

reported three to five events, while 5% reported 11 to 25.

44%

experienced unauthorized transactions or fraud vs. 40%

The level of frequency highlights the need for a repeatable response process. Security teams in tech and software need a consistent way to identify the exposed identity, understand what access it carries, choose the appropriate response, and confirm that remediation is complete. A process centered mainly on employee passwords can miss sessions, API keys, service accounts, and other identity assets – each of which requires a different remediation action than a password reset.

Non-human identity risk now runs through development, cloud, and automation

Technology companies rely on non-human identities throughout development and production, connecting CI/CD pipelines, cloud services, and customer-facing applications through API keys, OAuth tokens, certificates, SSH keys, secrets, and service accounts.

NHI authentication is most common in development tools and environments

44%

Development tools or environments

43%

B2B sales or customer-facing applications

41%

Cloud or infrastructure systems

Machine access reaches systems that influence code, infrastructure, internal operations, and customer interactions. Credentials may also outlive the project or person that created them. A key issued for a temporary integration can remain active, while a service account may support several applications without a clearly maintained owner. 

NHIs were the single most common initial access vector among affected software and technology organizations at 28%. Phishing or social engineering followed at 21%, while third-party or supply chain access and stolen sessions or tokens each accounted for 13%.

Beyond how attackers get in, NHI exposure also shows up in the type of incident technology organizations report after the fact. Misuse or compromise involving AI agents, service accounts, applications, or bots was the most frequently reported identity event type at 36%, and API key compromise or misuse affected 21%.

Machine identities can be difficult to distinguish from legitimate activity because the key, token, or service account already has permission to interact with the target system. Response also differs from a human credential reset. Teams may need to rotate a key, revoke a token, contain a service account, reduce privileges, and update applications that depend on the affected credential.

Unmanaged devices can expose human and machine credentials

Developer endpoints outside company management — personal laptops, contractor machines, unapproved tools — can hold far more than employee passwords. API keys, session material, secrets, and service-account credentials often sit there too, without the visibility a managed device would have.

Contract developers, implementation consultants, outsourced engineering teams, and other technical partners may access code, SaaS applications, development environments, or cloud services from devices outside company control. 

Infostealer malware pulls human credentials and machine-access assets off an infected device in one pass. Cleaning or reimaging the device doesn’t invalidate stolen keys, tokens, or sessions that remain usable, so post-infection remediation has to extend beyond the endpoint.

44%

of affected software and technology organizations cited unmanaged or unauthorized devices as an access path, compared with 34% overall

10%

named unmanaged devices as their single most common initial access vector, compared with 4% overall.

AI agents are expanding machine access faster than governance can keep up

Adoption is outpacing governance throughout the tech industry – 84% of software and technology organizations use AI tools or agents with access to internal systems or data.

AI agents add to an NHI environment technology teams already need to govern. They often authenticate through API keys, tokens, service accounts, and other machine credentials, then use that access to reach internal tools, code, data, and applications before security teams have assigned ownership or reviewed privileges. That pace is part of the identity security challenges organizations face as AI and other non-human identities expand.

59%

rely on informal processes or partial ownership for AI identity privileges

34%

have formal policies and clear ownership, compared with 56% overall

18%

have explicit visibility into AI-related NHI exposures, compared with 36% overall

See which identity exposures may be tied to your organization

Check your exposure to see what identity threats may already be tied to your organization’s domain.

Software supply chains make remediation harder to verify

Cloud vendors, development partners, managed service providers, contractors, integrations, and software suppliers can all introduce identities that connect to internal or shared systems. 

33% of affected software and technology organizations named third-party or supply chain exposure as their initial access vector, while a related but distinct 21% experienced a third-party, vendor, or supply-chain identity exposure as the type of incident itself. 

Continuous vendor identity exposure monitoring

SpyCloud Supply Chain Threat Protection monitors vendor employee domains against recaptured breach records, infostealer logs, phishing captures, and combolists, surfacing active identity exposure across third-party ecosystems rather than relying on static vendor risk scores. The Supply Chain Threat Protection overview explains how that approach helps teams identify active identity risk across vendor ecosystems.

Vendor visibility often stops before remediation is confirmed

For a technology company, verification may mean confirming that a credential has been reset, a session revoked, an API key rotated, an infected device addressed, or unnecessary application access removed. SpyCloud’s Supply Chain Exposure Response Guide outlines how teams can move from identifying exposure to coordinating remediation, while Vendor Risk Detection can help extend visibility into third-party identity exposure. 

Automated credential and session remediation

SpyCloud Identity Guardians integrates with Active Directory, Entra ID, and Okta Workforce to detect and remediate compromised credentials and stolen sessions, moving teams from manual case- handling to automated identity response.

Technology leaders are prioritizing faster identity remediation

Software and technology organizations are already placing more emphasis on the response side of identity security. 31% identified improving remediation speed for exposed credentials, sessions, tokens, and API keys as a priority. Another 28% plan to prioritize governance for AI agents and NHIs, while 21% are focused on automating identity-related incident-response workflows. 

Meeting that top priority means matching the response to the exposed identity asset by:

Automation can shorten parts of that response where the identity, risk conditions, required action, dependencies, and approval process are already clear.

Technology teams should aim to build response processes around the identities and access paths that create the greatest exposure. SpyCloud’s guide to identity threat protection platforms outlines capabilities that support exposure visibility, prioritization, and remediation.


Before prioritizing an exposed identity, confirm:

  • Whether the identity is human or non-human, such as a credential, session token, API key, service account, or AI agent
  • Whether it has access to production systems, customer-facing applications, source code, or sensitive data
  • Whether the exposure would survive a routine password reset, such as an active session, a long-lived key, or an infected device
  • Whether ownership is unclear or the identity is shared across multiple applications or teams

 

Extend visibility across human and non-human identities.

Monitor employee and contractor credentials alongside sessions, API keys, secrets, service accounts, automation credentials, AI-related identities, and the devices where those assets may be stored or used.

Establish clear ownership for machine and AI access.

Assign responsibility for each service account, application identity, automated process, and AI agent. Record its purpose, privileges, dependencies, credential-rotation requirements, and the systems or data it can reach.

Match remediation to the exposed identity asset.

Turn those asset-to-action decisions into a standing workflow, not a one-off decision each time an exposure surfaces. Defined workflows make it easier to automate approved actions without overlooking the dependencies attached to machine access.

Confirm third-party exposure has been addressed.

Give vendors or partners specific exposure information and required actions, then confirm that the exposed identity or access can no longer be used. Notification alone does not establish whether trusted access remains available.

Software identity resilience depends on remediating every exposed access path

Software and technology companies rely on identities across development environments, cloud infrastructure, applications, automation, AI, and third-party services. NHIs create access throughout that environment, while unmanaged devices, vendor connections, and AI adoption can make ownership and remediation harder to track.

A repeatable response starts by identifying the exposed identity, tracing what it can reach and what depends on it, applying the right remediation, and verifying that the access is gone. That gives security and engineering teams a practical way to handle recurring identity exposure without treating every asset as the same problem.

Go deeper on the identity threats facing tech teams

Read the full 2026 SpyCloud Identity Threat Report to explore benchmark data on identity events, AI and NHI governance, third-party exposure, visibility gaps, and remediation maturity.

FAQs

64% of software and technology organizations experienced at least one identity-based event in the past year. Among affected organizations, 69% reported six to 10 events, showing that identity exposure can recur frequently and requires repeatable remediation processes.

Government organizations reported the highest identity-based event rate of any industry in SpyCloud’s 2026 study. 92% of government organizations experienced an identity-based event in the past year, compared with 68% of organizations overall.

NHIs authenticate throughout development, cloud infrastructure, customer-facing applications, automation, and AI workflows. They can carry significant privileges, depend on other applications or services, and require remediation steps such as key rotation or token revocation that differ from employee password resets.

Unmanaged or unauthorized devices can hold employee credentials, session material, API keys, secrets, and service-account credentials. If those assets are stolen, cleaning or reimaging the device may not remove the access. Teams still need to revoke sessions, rotate keys and tokens, and confirm remediation.

SpyCloud’s 2026 Identity Threat benchmark research found that 84% of software and technology organizations use AI tools or agents with access to internal systems or data. However, 59% rely on informal processes or partial ownership for AI identity privileges, and only 18% have explicit visibility into AI-related NHI exposures. Security teams need to govern the credentials behind AI access as well as the tools themselves.

Many technology organizations can see vendor identity exposure without consistently confirming that the affected access has been removed. Verification should establish whether credentials, sessions, API keys, devices, or privileges have actually been addressed.

Keep reading

U.S. Capitol with illuminated columns and dome at sunset.
What SpyCloud’s 2026 Data Reveals About Government Identity Threats
See what SpyCloud’s 2026 research reveals about government identity threats, including visibility gaps, NHIs, third-party exposure, and remediation maturity.
Mapping SpyCloud to NIS2 Directive Requirements
Mapping SpyCloud to NIS2 Directive Requirements
Scattered LAPSUS$ Hunters weaponizes stolen credentials and session tokens from Salesforce breaches to fuel downstream account takeover attacks – here's how this federated cybercrime group operates and what security teams must do to stop them.
SpyCloud logo with text about session hijacking detection tools.
Best Session Hijacking Detection and Prevention Tools for 2026
Session hijacking attacks bypass MFA, passkeys, and passwordless authentication entirely – attackers don't crack passwords or intercept authentication codes. Whether the session token was pulled off an infected device by malware or intercepted mid-login by a phishing kit, the result is the same.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.