Kasey Cromer, Netlok | August 4, 2026
Executive Summary
For years, enterprise security programs have been built around protecting human logins. The assumption was straightforward: secure the accounts your employees use, and you secure the organization. That assumption is now dangerously out of date. Non-human identities — the API keys, service accounts, AI agents, bots, and automation credentials that connect every system, integration, and workflow in a modern enterprise — now outnumber human identities by ratios as high as 144 to 1 in cloud-native environments, according to Entro Labs’ NHI & Secrets Risk Report H1 2025. They grew 44% in total number year over year, while the ratio of machine identities to human identities increased by 56% — reflecting that human identity growth did not keep pace. And unlike human identities, non-human identities are largely under-governed.
The gap between how many machine identities exist and how well they are managed has become one of the most consequential blind spots in enterprise security. Attackers have noticed. When a stolen API key can grant persistent, silent access to cloud infrastructure, data stores, and downstream systems — without triggering the alerts that a compromised human account would — machine identity compromise offers something passwords never could: long-term, invisible access that looks exactly like normal operations.
Photolok by Netlok does not manage machine identities directly. But it addresses the most common door attackers use to reach them: the human login. By eliminating passwords at the identity layer, Photolok removes the starting point most sophisticated attackers use to move into the machine identity environment.
The Scale of the Problem
Most CISOs know that non-human identities exist in their environment. Few know how many there actually are. Entro Labs’ NHI & Secrets Risk Report H1 2025 found that in cloud-native environments — organizations built primarily around cloud infrastructure — non-human identities outnumber human identities at a ratio of 144 to 1, up from 92 to 1 just one year earlier. Across the broader enterprise, specialized identity research from the NHI Management Group — an independent industry body unaffiliated with Entro Labs — estimates the ratio at 25 to 1 to 50 to 1, with variation driven by cloud adoption, the number of cloud software subscriptions, and how aggressively organizations have deployed automation.
A significant portion of those identities are invisible to security teams. Orchid Security’s Identity Gap 2026 Snapshot, based on data from enterprise environments across North America and Europe, found that 67% of non-human identities are created directly within applications by developers, vendors, or automated systems — outside of any central identity provider, and without formal onboarding or assigned ownership.
Every new cloud software subscription, cloud service, automation workflow, and AI agent adds more machine credentials. According to GitGuardian’s State of Secrets Sprawl 2026 report, 28.65 million new passwords, API keys, and tokens written directly into code were added to public GitHub repositories — online storage systems where developers keep code — in 2025 alone, a 34% year-over-year increase and the largest single-year jump ever recorded. Internal repositories, the same report found, are roughly six times more likely to contain these embedded credentials than public ones, meaning the total exposure across any organization is considerably larger than what appears in public data.
Why Machine Identities Stay Vulnerable
Human identity programs have mature playbooks: onboard through HR, assign a manager, conduct access reviews, offboard when an employee leaves. Non-human identities were never designed to fit that model. They are created by developers to make an integration work, by operations teams to run an automated task, by vendors during implementation. They rarely have an accountable owner, are almost never included in termination workflows, and do not expire with employee turnover.
The practical consequence is a growing backlog of forgotten, ownerless, and over-privileged accounts. Some are temporary connections that outlived their original purpose. Others are permanent integrations that were never properly scoped or maintained. In either case, the access they carry has never been reviewed, reduced, or reassigned — leaving organizations with a population of active accounts that no one is watching.
The governance gap is compounded by the fact that non-human identities frequently bypass the controls that protect human accounts. They do not have multi-factor authentication (MFA) — the step that requires a second form of verification beyond a password. They are not bound to a specific device. They operate continuously, often with permissions that would immediately raise flags if a human account held the same level of access. Specialized identity research from the NHI Management Group’s 2026 Infrastructure Identity Survey found that 70% of organizations grant AI systems more access than they would give a human employee performing the exact same job.
How Embedded Credentials Fuel Machine Identity Compromise
The primary way attackers gain access to non-human identities is through the uncontrolled spread of passwords, API keys, and tokens written directly into code and shared across collaboration tools — what the industry calls secrets sprawl. When a developer writes an API key directly into a script or shares a service account token in a Slack channel, that credential can persist indefinitely, valid and exploitable long after the original need has passed.
GitGuardian’s State of Secrets Sprawl 2026 report makes the scale concrete. Of secrets confirmed as valid in 2022, 64% were still valid and exploitable as of January 2026 — meaning credentials have been sitting in public code for four years without being rotated or revoked. That persistence is what makes secrets sprawl strategically valuable to attackers. A credential does not need to be fresh to be useful. It needs to be valid.
The problem extends beyond source code. The same report found that about 28% of credential leak incidents originate entirely outside repositories, in collaboration and productivity tools such as Slack, Jira, and Confluence. The reason this happens is rarely deliberate. Developers work in tools built for speed and collaboration, not security review. There is no automatic warning when a password is pasted into a Slack message or a key is written into a script. By the time the exposure is discovered — if it is discovered at all — the credential has often been sitting in plain sight for months or years.
From Human Login to Machine Identity: How Attackers Move
While machine identities are a compelling target on their own, most sophisticated attackers begin with a human account and then move into machine identity space. Compromising a human account gives an attacker the ability to discover machine credentials — finding API keys in code repositories the employee has access to, extracting tokens from settings files, or creating new service accounts using administrative privileges. Once they control a machine identity, they can operate silently, because their activity looks like authorized automation rather than a human intruder.
Verizon’s 2025 Data Breach Investigations Report found that credential abuse was the leading initial access method, present in 22% of analyzed breaches. CrowdStrike’s 2024 Threat Hunting Report documented how adversaries exploit legitimate human credentials to reach cloud environments, then abuse connections between different systems to access additional infrastructure. The pattern is consistent: a human login is compromised, and machine identities are what attackers reach for next.
The reason is straightforward. A compromised machine identity often offers more value than a compromised human account. Machine identities run continuously. They hold system-level permissions across services, data stores, and infrastructure layers. They rarely trigger alerts because their activity does not look anomalous. And when their credentials persist for years without being updated, a single exposed API key can provide access long after the original breach has been forgotten.
AI Agents Are Accelerating the Problem
The rise of agentic AI in 2025 and 2026 has multiplied the non-human identity surface significantly. Every AI agent deployed in an enterprise is another machine identity — one that authenticates using credentials, accesses data and systems, and often operates with more access than necessary. Microsoft Copilot Studio users have collectively created more than one million AI agents, yet only 44% of organizations have implemented any oversight rules for them, according to the 2026 Infrastructure Identity Survey. GitGuardian’s 2026 data shows AI-service credentials as one of the fastest-growing leak categories, up 81% year over year. When AI agents share keys across multiple applications, a single exposed credential can grant access across an entire agent fleet.
How Photolok by Netlok Addresses the Gap
Photolok by Netlok operates at the identity layer and focuses on the human side of this problem. It does not manage API keys, service accounts, or machine tokens directly. Instead, it hardens the human login so attackers cannot use compromised credentials as a bridge to machine identities.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker captures or steals the photos, they cannot use them — the encryption and device binding lock them out. There is no static secret to phish, no password database to raid, and no captured image that can be reused to break in.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired — there is nothing to capture that can be reused to break in again. This directly addresses the persistence problem that makes stolen credentials so valuable: a credential that cannot be reused has no value in the markets where stolen secrets are traded.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. If an employee with access to critical systems is pressured into authenticating under coercion, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The security operations center receives a real-time distress signal while the person doing the coercing sees a normal login — a capability that passwords, passkeys, and biometrics do not provide.
For CISOs working to reduce non-human identity risk, the most immediate leverage point is the human login. When attackers cannot easily compromise human credentials, their ability to discover and weaponize machine identities is substantially reduced. Photolok offers a way to harden that layer at the identity level, without requiring any change to the cloud platforms, AI systems, or machine identity infrastructure running behind it.
The Bottom Line
The gap between how many non-human identities exist and how well they are governed is one of the fastest-growing attack surfaces in 2026. Machine identities outnumber human identities at 144 to 1 in cloud-based environments, up from 92 to 1 just one year earlier, and at 25 to 1 to 50 to 1 across the broader enterprise. 64% of credentials confirmed valid in 2022 are still exploitable today. AI agents are multiplying this surface faster than oversight programs can absorb. And 67% of non-human identities were never visible to security teams in the first place.
Attackers do not need to invent a new technique to exploit this. They need a valid human login, and the path to machine identities is often wide open. Photolok closes that first door — eliminating the password most attackers use as their starting point — and gives security teams a real-time signal when someone is authenticating under duress.
The identities you cannot see are the ones attackers are counting on you to ignore.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Entro Labs. ‘NHI & Secrets Risk Report H1 2025.’ July 2025. entro.security
[2] NHI Management Group. ‘How Many NHIs Does a Typical Enterprise Have?’ May 2026. nhimg.org
[3] NHI Management Group / Teleport. ‘2026 Infrastructure Identity Survey.’ 2026. nhimg.org
[4] Orchid Security. ‘Identity Gap: 2026 Snapshot.’ May 2026. globenewswire.com
[5] GitGuardian. ‘State of Secrets Sprawl 2026.’ March 2026. gitguardian.com
[6] GitGuardian. ‘State of Secrets Sprawl 2025.’ March 2025. gitguardian.com
[7] Verizon. ‘2025 Data Breach Investigations Report.’ May 2025. verizon.com/business/resources/reports/dbir
[8] CrowdStrike. ‘2024 Threat Hunting Report.’ 2024. crowdstrike.com
[9] Netlok. ‘How Photolok Works.’ netlok.com
Does a non-human own your ID?
Kasey Cromer, Netlok | August 4, 2026 Executive Summary For years, enterprise security p[...more]
Critical Infrastructure Isn’t Breached. It’s Logged Into.
Kasey Cromer, Netlok | July 15, 2026 Executive Summary In 2026, the most consequential cyberattac[...more]
AI-Powered Phishing and the Speed of Attack
Kasey Cromer, Netlok | June 16, 2026 Executive Summary In 2026, phishing is no longer a numbers game[...more]
Helpdesk is the Easiest Breach in Your Organization
Kasey Cromer, Netlok | June 9, 2026 Executive Summary In 2026, the most dangerous entry point in you[...more]
Leaner Teams, Smarter Logins: Why Eliminating Passwords Is the Right Move for 2026
Kasey Cromer, Netlok | May 27, 2026 Executive Summary In 2026, security leaders are being asked to d[...more]
When anyone can be faked: Photolok as the identity layer for the AI era
Kasey Cromer, Netlok | May 13, 2026 Executive summary As we move through 2026, the corporate world i[...more]
App Overload: Why SaaS apps and AI Sprawl Are Breaking Enterprise Security
Kasey Cromer, Netlok | April 29, 2026 Executive summary In 2026, most enterprises are running more a[...more]
Identity Crisis: When Attackers Log In Instead of Break In
Kasey Cromer, Netlok | April 10, 2026 Executive Summary Geopolitical escalation reliably coincides w[...more]
Protecting the Person, Not Just the Account
Kasey Cromer, Netlok | March 31, 2026 Executive Summary Traditional authentication was designed to a[...more]