COMMENTARY A look back at 2024's top non-human identity (NHI) attacks and their year-end explosion sends a worrying signal that 2025 is going to be a tough year for machine-to-machine identity theft. One year ago, NHI burst onto the scene with a big warning flare, when Cloudflare disclosed that NHI mismanagement caused a massive breach, stemming from the failure to rotate an access token and account credentials exposed in the 2023 Okta compromise. While the attack was contained, the impact on Cloudflare was nonetheless significant. The company disclosed it had to rotate every production credential (more than 5,000 individual credentials), physically segment test and staging systems, perform forensic triages on 4,893 systems, and then reimage and reboot every machine in its global network. As the year progressed, NHI breaches gained momentum. In June, the New York Times made its own news when 270GB of its internal data and applications in 5,000 repositories were stolen from GitHub and published on the Web. How? The breach was executed using NHI when an exposed GitHub Personal Access Token, a machine-to-machine secret, allowed unauthorized access to the company's code repositories. The "All the News That's Fit to Print" outlet downplayed the story. Cybersecurity experts did not agree, however, arguing that source-code leaks can have wide-ranging implications. The year ended with a spate of high-profile breach disclosures attributed to NHI during the fourth quarter. Thousands of...
Will 2025 See a Rise of NHI Attacks?
Dark Reading
·Itzik Alvas
·Published Jan 22, 2025
·Updated
Affected Software
10 affected components
Adobe Commerce
AWS machine-to-machine authentication keys
Microsoft Azure machine-to-machine authentication keys
Schneider Electric development platform
Atlassian Jira
Palo Alto Networks Expedition
Cloudflare Cloudflare
Okta Okta
GitHub GitHub
New York Times New York Times