CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

Non-human identities are 91% of everything active in production

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3960

As cited

Copy frozen at (site build).

identity access

Non-human identities are 91% of everything active in production

Non-human identities (service accounts, API keys, and machine credentials) represent 91% of all active identity activity in production environments. Most non-human activity operates outside standard business hours, making unauthorized use of stolen credentials difficult to detect through normal monitoring patterns.

Why it matters: Security teams managing identity and access controls must account for the vast majority of production activity being machine-driven; defenders unable to monitor non-human credential usage risk missing lateral movement and privilege escalation by attackers who steal service accounts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Non-human identities are 91% of everything active in production

Non-human identities account for 91% of active credentials in production environments, with 80% of their activity occurring outside standard business hours. This distributed, continuous usage pattern creates an expanded window for attackers to exploit compromised machine credentials without triggering typical detection mechanisms that focus on business hour anomalies.

Why it matters: Security teams managing AWS and other cloud platforms need to implement continuous monitoring and anomaly detection for non-human identities rather than relying on business-hour-focused alerts, as attackers can easily blend malicious activity into the heavy baseline of off-hours machine operations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Non-human identities are 91% of everything active in production

Non-human identities account for 91% of active credentials in production environments, with 80% of their activity occurring outside standard business hours. This distributed, continuous usage pattern creates an expanded window for attackers to exploit compromised machine credentials without triggering typical detection mechanisms that focus on business hour anomalies.

Why it matters: Security teams managing AWS and other cloud platforms need to implement continuous monitoring and anomaly detection for non-human identities rather than relying on business-hour-focused alerts, as attackers can easily blend malicious activity into the heavy baseline of off-hours machine operations.

VendorsAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary