Executive Summary
In July 2026, security researcher Aleksandr Krasnov uncovered a significant security vulnerability involving dormant non-human identities (NHIs) within cloud environments. An AI-enabled workflow agent, inactive for 30 days, unexpectedly initiated API calls at irregular times, prompting an investigation. This led to the discovery of 'ghost credentials'—tokens, agents, and service accounts existing outside traditional trust boundaries yet capable of lateral movement and privilege escalation within systems. Krasnov developed an open-source tool, NHI Hound, to identify and mitigate these hidden trust paths, aiming to enhance organizational security posture.
The incident underscores the escalating risks associated with unmanaged NHIs in increasingly automated and AI-driven infrastructures. As NHIs now outnumber human identities by significant margins, organizations face heightened threats from potential exploitation of these entities. This case highlights the urgent need for robust identity governance frameworks to manage and secure NHIs effectively.
Why This Matters Now
The proliferation of non-human identities in cloud environments presents a growing security challenge, as these entities often operate with excessive privileges and lack proper oversight. This incident highlights the critical need for organizations to implement comprehensive identity governance strategies to mitigate potential exploitation risks associated with NHIs.
Attack Path Analysis
An AI-enabled workflow agent, dormant for 30 days, was reactivated and began making unusual API calls, leading to the discovery of compromised non-human identities (NHIs). These NHIs escalated privileges, moved laterally across cloud environments, established command and control channels, exfiltrated sensitive data, and caused significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
An AI-enabled workflow agent, dormant for 30 days, was reactivated and began making unusual API calls, indicating potential compromise of non-human identities (NHIs).
MITRE ATT&CK® Techniques
Valid Accounts
Use Alternate Authentication Material
Cloud Accounts
Account Manipulation
Create Account
Default Accounts
Unsecured Credentials
Modify Authentication Process
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure proper user identification and authentication management
Control ID: 7.2.1
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement robust identity and access management controls
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Ghost credentials and nonhuman identities create critical lateral movement risks in AI-enabled workflows, requiring enhanced zero trust segmentation and identity governance controls.
Information Technology/IT
Dormant service accounts and API tokens expose infrastructure to privilege escalation attacks, demanding comprehensive visibility into east-west traffic and multicloud environments.
Financial Services
AI workflow agents with excessive permissions threaten regulatory compliance under PCI and create data exfiltration paths requiring immediate egress security enforcement.
Health Care / Life Sciences
Automated healthcare systems with ghost credentials violate HIPAA trust boundaries, exposing patient data through unmonitored nonhuman identity privilege escalation vectors.
Sources
- Ghost Credentials Expose Cloud Systems to Hidden Identity Riskshttps://www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-pathVerified
- Non-Human Identities Are Your Biggest Cloud Network Security Risk in 2026 — Here's Whyhttps://cloud-tech-alert.com/blog/non-human-identities-are-your-biggest-cloud-network-security-risk-in-2026-heres-why/Verified
- Non-human identity governance: The silent threat in modern cloud environmentshttps://www.cpx.net/insights/blogs/non-human-identity-governance-the-silent-threat-in-modern-cloud-environments/Verified
- What Are Non-Human Identities (NHIs)?https://www.wiz.io/academy/cloud-security/non-human-identities-nhiVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to escalate privileges, move laterally, establish command and control channels, and exfiltrate sensitive data, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely constrain unauthorized API calls by enforcing strict identity-based policies, thereby limiting the initial reach of the compromised NHIs.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the ability of compromised NHIs to escalate privileges by enforcing least-privilege access controls.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely restrict lateral movement by monitoring and controlling internal traffic flows, thereby limiting unauthorized access to additional resources.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely detect and limit unauthorized command and control channels by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely restrict data exfiltration by controlling and monitoring outbound traffic to unauthorized destinations.
While the attack caused operational disruption and data loss, the implemented controls would likely have reduced the overall impact by limiting the attacker's reach and the extent of data exfiltration.
Impact at a Glance
Affected Business Functions
- Cloud Infrastructure Management
- Automated Workflow Operations
- Identity and Access Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive cloud service configurations and access credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
- • Enhance Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and mitigate unusual behaviors in real-time.
- • Regularly audit and manage non-human identities to ensure they have appropriate permissions and are not dormant or over-privileged.



