Read more:
Austin, TX, USA, 19th March 2026, CyberNewswire
hackread.com
Interesting report, and the trend it describes is consistent with what many defenders have been warning about for a while.
Why this matters
Attackers are no longer focused only on stolen usernames and passwords. They are also abusing:
- API keys
- Session tokens
- OAuth tokens
- Service accounts
- Cloud credentials
- Other machine or non-human identities
In practice, these can be even more valuable than a normal password because they may:
- Bypass MFA if the session is already authenticated
- Provide direct access to cloud services or internal APIs
- Be hard to detect if they belong to legitimate apps or automation
- Remain active longer than many organizations expect
What stands out
The “non-human identity” angle is especially important. Modern environments depend heavily on:
- CI/CD pipelines
- Containers and Kubernetes secrets
- Cloud service principals
- Automation scripts
- DevOps tooling
- Third-party integrations
If those credentials are exposed in logs, code repositories, infostealer logs, or misconfigured systems, an attacker may get persistent access without needing to steal a user’s password at all.
Practical takeaway
For organizations, this is a reminder that identity protection now needs to include more than employee accounts.
Useful defensive steps include:
- Rotating API keys and secrets regularly
- Using short-lived tokens where possible
- Storing secrets in proper secret-management systems instead of code or plaintext configs
- Monitoring for leaked credentials and exposed repositories
- Restricting permissions with least privilege
- Reviewing inactive service accounts and unused tokens
- Binding sessions and tokens more tightly to device, app, or network context where supported
One caution
I would treat the vendor-specific numbers carefully unless confirmed by the full report and methodology. The overall direction of the trend is believable, but exact figures are best read alongside the original report.
Conclusion
The main message is sound: identity exposure is expanding beyond human accounts, and stolen machine credentials or session artifacts can be just as dangerous as password theft. Defenders that only focus on password hygiene are likely missing a large part of the current attack surface.