#1 Authority in NHI Education, Research and Advisory, empowering organizations to tackle the critical risks posed by Non-Human Identities (NHIs), including AI Agents.
Real-world breaches involving API keys, service accounts, secrets, tokens and AI agents — what happened, how attackers got in, and what to fix. Researched and analysed by NHI Mgmt Group.
OpenAI agents used Census API keys leaked on GitHub, reposted SEC data and, per Transluce, tried to hack an Education site. No compromise found.
Read breach analysis → AI agentsNHI Prompt injectionSalesBleed: poisoned Web-to-Lead records made Salesforce Agentforce leak CRM data past Trusted URLs and phish in Slack as the agent. Now fixed.
Read breach analysis → NHIAI agentsLLM & AI platform MisconfigurationCarbonato infects unauthenticated Docker hosts and runs a Hermes AI agent that steals AI API keys, SSH keys and tokens to fuel its own LLM service.
Read breach analysis → NHIAI agents Supply chainHijacked GitHub Actions stole MemTensor's npm and PyPI tokens to ship sckit, a credential stealer in an AI agent memory plugin and MemoryOS.
Read breach analysis → AI agentsNHI Vulnerability exploitA Meta Muse zero-day let local malware redirect dictation, steal the agent's authentication material and abuse its delegated access. Hot-fixed.
Read breach analysis → Claimed NHIHuman identity Vulnerability exploitShinyHunters claims it breached the FBI via PeopleSoft and pivoted into AWS GovCloud. The FBI is investigating; the breach is not confirmed.
Read breach analysis → AI agentsNHI Not disclosedSpain's data regulator received its first breach notification blamed on an attacker's AI agent, which logged in, altered personal data and read invoices.
Read breach analysis → NHILLM & AI platformAI agents Vulnerability exploitCVE-2026-59822 let any bearer token open LiteLLM's MCP gateway; attackers stole master and provider keys. 9.6% of exposed gateways used sk-1234.
Read breach analysis →A misconfigured Irregular cyber test gave Meta's Muse Spark 1.1 internet access and a real target; it exploited the site and changed its database.
Read breach analysis → NHI Supply chainChainDrop hijacked a keyv maintainer account and spread through 444 npm packages on 4 August 2026, stealing npm, GitHub, CI, cloud and AI tool credentials.
Read breach analysis →Four Claude models in misconfigured cyber evaluations reached the internet and breached real organisations, including via a malicious PyPI package.
Read breach analysis → AI agentsLLM & AI platform AI agent misbehaviourIn UK AISI cyber tests, AI agents took 19 unsanctioned actions on the live internet, creating fake identities to push malicious code to a real project.
Read breach analysis → NHIAI agentsLLM & AI platform AI agent misbehaviourIn July 2026 OpenAI evaluation agents escaped their sandbox and used stolen Kubernetes, cloud, VPN and GitHub tokens to take over Hugging Face clusters.
Read breach analysis → AI agentsHuman identityNHI Weak or default credentialsAutonomous AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, pivoted via SSO and stole 2,564+ records in four days.
Read breach analysis → AI agentsNHI Vulnerability exploitAn AI agent exploited Langflow, harvested API keys and cloud credentials, used default MinIO and Nacos secrets, and destroyed a production database.
Read breach analysis → AI agentsNHI Vulnerability exploitAutonomous AI agents hit hundreds of retailers for ~$25 each, dumping AWS Secrets Manager and cloud keys to steal 600,000+ cards and plant skimmers.
Read breach analysis →Amazon Q auto-ran MCP servers from a repo's .amazonq/mcp.json, passing developers' AWS keys and tokens to attacker commands. Fixed; no exploitation.
Read breach analysis → AI agentsNHI AI agent misbehaviourAn OpenAI agent reached non-public files on an Australian Medicare statistics portal, via a guest endpoint, and OpenAI took 84 days to notify.
Read breach analysis → NHIAI agentsHuman identity Supply chainIn June 2026 a former contributor's unrevoked npm account republished 140+ Mastra AI packages with a RAT dependency. Microsoft blames Sapphire Sleet.
Read breach analysis → NHILLM & AI platform Supply chainIn 2026, 15 fake AI assistant plugins on the JetBrains Marketplace stole OpenAI, DeepSeek and SiliconFlow API keys. How it worked and how to govern AI keys.
Read breach analysis → AI agentsNHI Prompt injectionA fake Sentry error posted with a public DSN made Claude Code, Cursor and Codex run attacker commands with the developer's credentials, via MCP.
Read breach analysis → NHI OAuth / SaaS integrationIn June 2026 a stale Klue GitHub token let attackers plant code, steal customers' Salesforce OAuth tokens and export CRM data from connected tenants.
Read breach analysis → NHIAI agents Supply chainIn June 2026 the Miasma and Hades worms used stolen GitHub accounts, OIDC publishing and npm and PyPI tokens to spread credential theft to Microsoft repos.
Read breach analysis →Storm-2949, 2026: Microsoft says SSPR abuse and IT support impersonation gave an actor Entra ID accounts, then Key Vault secrets, storage keys and Azure data.
Read breach analysis → NHI Supply chainA GitHub CLI token stolen via TanStack let TeamPCP publish a poisoned Nx Console extension that stole a GitHub employee's secrets and 3,800 repos.
Read breach analysis → NHI Stolen credentialsMegalodon used compromised GitHub tokens and fake bot identities to add secret-stealing workflows to 5,561 repos, harvesting CI and OIDC credentials.
Read breach analysis → AI agentsNHI AI agent misbehaviourAn AI agent swarm attributed to OpenAI flooded RubyGems, ran code on RubyDoc build servers and tried to steal users' API keys via a caching flaw.
Read breach analysis →Canvas Instructure breach 2026: a malicious support ticket hijacked an agent's session, yielding a token that ShinyHunters used to pull data via Canvas APIs.
Read breach analysis → NHIAI agents AI agent misbehaviourA Cursor agent running Claude Opus 4.6 found an account-wide Railway token and deleted PocketOS production data and backups in one API call.
Read breach analysis → NHIAI agents OAuth / SaaS integrationIn April 2026 a stolen Context.ai OAuth token let attackers take over a Vercel employee's Google Workspace and read customer environment variables.
Read breach analysis → AI agentsLLM & AI platformHuman identity Social engineeringIn 2026 attackers asked Meta's AI support assistant to send Instagram recovery links to their own email, hijacking 20,225 accounts that lacked 2FA.
Read breach analysis →Gravity SMTP CVE-2026-4020 (2026) let anyone pull email API keys, OAuth tokens and SMTP passwords from WordPress sites, with 17m+ exploit attempts blocked.
Read breach analysis → NHILLM & AI platform Supply chainIn March 2026 a PyPI token leaked via a poisoned Trivy scan let TeamPCP publish malicious LiteLLM versions that stole cloud, Kubernetes and LLM API keys.
Read breach analysis → Human identity Not disclosedHow a hijacked admin account and Microsoft Intune were used to wipe Stryker devices in March 2026, what Handala claimed, and the privileged identity lessons.
Read breach analysis → LLM & AI platformAI agentsNHI Vulnerability exploitMcKinsey AI platform hack 2026: CodeWall's AI agent used unauthenticated APIs and SQL injection to reach Lilli chats and writable system prompts. Disclosed.
Read breach analysis →In 2026 Truffle Security found 2,863 public Google API keys that silently gained Gemini access, exposing uploaded files and billing. NHI lessons and fixes.
Read breach analysis → NHI MisconfigurationIn 2026 researchers found 4.96 million IPs exposing .git folders and 252,733 Git configs holding deployment credentials, a machine identity secrets risk.
Read breach analysis →In January 2026 Moltbook's open Supabase database exposed 1.5 million AI agent API keys, letting anyone impersonate agents. How it happened and what to fix.
Read breach analysis → AI agentsLLM & AI platform Prompt injectionIn January 2026 Miggo showed a calendar invite could make Gemini leak private meetings using the user's own calendar access. AI agent identity lessons.
Read breach analysis →MongoBleed (CVE-2025-14847), disclosed December 2025, let unauthenticated attackers read MongoDB heap memory holding passwords, keys and tokens. 87K+ exposed.
Read breach analysis → NHI Leaked secretIn 2025 a researcher found a Home Depot GitHub token exposed since early 2024, with write access to repos and cloud systems. Revoked after press contact.
Read breach analysis → NHILLM & AI platform Leaked secretDocker Hub secrets leak 2025: Flare found 10,456 public images exposing cloud, CI, GitHub and nearly 4,000 AI API keys, most never revoked. NHI lessons.
Read breach analysis → NHI Vulnerability exploitGladinet hard-coded keys (2025): identical AES keys in CentreStack and Triofox let attackers forge tickets, steal ASP.NET machine keys and run code.
Read breach analysis →2025 study: a TruffleHog scan of 5.6 million public GitLab repositories found 17,430 live secrets, from GCP keys to Slack tokens. NHI lessons and fixes.
Read breach analysis → NHI Leaked secretIn November 2025 watchTowr found 80,000+ saved pastes on JSONFormatter and CodeBeautify exposing cloud keys, tokens and passwords, and attackers testing them.
Read breach analysis → NHI Supply chainShai-Hulud npm worm 2025: stolen npm and CI tokens spread a preinstall credential stealer to hundreds of packages and 25,000+ GitHub repos. Lessons for NHIs.
Read breach analysis → NHI Leaked secretA contractor's public "Private-CISA" repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read breach analysis → NHI Weak or default credentialsHard-coded credentials in SAP SQL Anywhere Monitor (Non-GUI) earned a CVSS 10.0 (CVE-2025-42890). SAP removed the monitor to fix it.
Read breach analysis → NHI Stolen credentialsIn 2025, attackers used stolen AWS IAM credentials to mine crypto on EC2 and ECS in customer accounts, then blocked termination and created backdoor users.
Read breach analysis →TruffleNet used 800+ attacker hosts running TruffleHog to test stolen AWS keys; in one account SES was abused for a vendor invoice scam.
Read breach analysis → NHIAI agents Social engineeringDatadog showed Copilot Studio agents on a Microsoft domain can lead users to malicious OAuth consent and forward their tokens to attackers.
Read breach analysis → NHI Supply chainHow GlassWorm hid in Open VSX and VS Code extensions, stole npm, GitHub and Open VSX tokens and used publishing tokens to spread.
Read breach analysis → NHI Leaked secretWiz found 550+ secrets in 500+ VS Code extensions, including 130+ publishing tokens that could push updates to about 150,000 installs.
Read breach analysis → Human identity Stolen credentialsHuntress saw attackers log in to more than 100 SonicWall SSL VPN accounts with valid credentials in October 2025. Source of logins unknown.
Read breach analysis → NHI Not disclosedThe Crimson Collective copied a Red Hat Consulting GitLab instance in 2025, exposing customer tokens, keys and connection strings in engagement reports.
Read breach analysis → NHI Vulnerability exploitA OneLogin API returned OIDC client secrets to any caller with valid API credentials (CVE-2025-59363). Fixed in 2025.3.0; no customers hit.
Read breach analysis →ForcedLeak let a Web-to-Lead form inject instructions into Salesforce Agentforce and exfiltrate CRM data via an expired, allowlisted $5 domain.
Read breach analysis → NHIAI agents Leaked secretA CrewAI error response exposed an internal GitHub token with admin rights over all private repositories. Fixed within five hours.
Read breach analysis → AI agentsNHILLM & AI platform Vulnerability exploitA Chinese state-sponsored group used Claude Code agents to attack about 30 organisations, with AI doing 80-90% of the work, including credential theft.
Read breach analysis → NHI Vulnerability exploitUndocumented Actor tokens and an Azure AD Graph flaw could let an attacker impersonate Global Admins in any Entra ID tenant. Fixed in July 2025.
Read breach analysis → NHI OAuth / SaaS integrationStolen Salesloft Drift OAuth tokens let attackers export Palo Alto Networks Salesforce data, including support case notes with credentials.
Read breach analysis →The 2025 JLR cyberattack halted production for five weeks and cost the UK an estimated £1.9bn. What is known about access, stolen credentials and lessons.
Read breach analysis → NHIAI agents Supply chainA stolen npm token let attackers publish malicious Nx versions that stole 2,349 secrets, abusing AI CLIs, then exposed private repositories.
Read breach analysis → NHIHuman identity Vulnerability exploitHow Cl0p exploited Oracle E-Business Suite zero-day CVE-2025-61882, ran commands as the applmgr account and sent extortion from stolen mailboxes.
Read breach analysis → NHI OAuth / SaaS integrationIn August 2025 UNC6395 used stolen Salesloft Drift OAuth tokens to export Salesforce data from hundreds of firms and mine it for AWS keys and passwords.
Read breach analysis →Tracebit found a poisoned README could make Google Gemini CLI silently run commands and send developer secrets out. Fixed in 0.1.14.
Read breach analysis → NHIAI agents Supply chainAn over-scoped GitHub token let an attacker add a wiper prompt to the Amazon Q Developer VS Code extension, which AWS shipped in v1.84.0.
Read breach analysis → AI agentsNHI AI agent misbehaviourReplit's AI coding agent deleted a live production database during a code freeze, then said recovery was impossible. Rollback worked.
Read breach analysis → NHI Vulnerability exploitHow ToolShell attackers exploited on-premises SharePoint in July 2025 and stole ASP.NET machine keys that kept access alive after patching.
Read breach analysis → NHIAI agents Weak or default credentialsResearchers logged in to McDonald's McHire AI hiring platform with 123456/123456 and found an IDOR exposing up to 64 million applicant records.
Read breach analysis → NHI Weak or default credentialsAruba Instant On access points shipped with hard-coded admin credentials (CVE-2025-37103, CVSS 9.8). Firmware 3.2.1.0 fixes it.
Read breach analysis →Attackers used an external user login, likely stolen by infostealer malware, to download insurance claim documents from a Scania portal.
Read breach analysis → LLM & AI platformAI agents Prompt injectionEchoLeak (CVE-2025-32711) let a single crafted email make Microsoft 365 Copilot leak data in its context, with no user click. How it worked and what to do.
Read breach analysis → NHIHuman identity Social engineeringCallers talked staff into approving malicious Salesforce connected apps, then bulk-exported CRM data from Google, Qantas, Allianz Life, Cisco and others.
Read breach analysis →A hacker called 303 claims to have leaked Deloitte GitHub credentials and source code in May 2025. Deloitte has not confirmed it.
Read breach analysis → Human identity InsiderHow criminals bribed Coinbase support agents to copy data on 69,461 customers, then demanded $20 million. Lessons for insider and access control.
Read breach analysis →Attackers linked to Scattered Spider social-engineered a password reset at Co-op and stole the personal data of all 6.5 million members.
Read breach analysis → Human identity Social engineeringAttackers impersonated a third-party user to get into M&S in April 2025, stole customer data and halted online orders, costing about £300 million.
Read breach analysis → NHIHuman identity InsiderCoupang breach 2025: a former developer kept a token signing key that was never revoked, forged access tokens and exposed 33.7 million accounts in Korea.
Read breach analysis → NHI Leaked secretUnit 42 traced the tj-actions attack to a SpotBugs maintainer PAT stolen in December 2024 through a pull_request_target workflow.
Read breach analysis →A stolen maintainer PAT let attackers poison reviewdog/action-setup@v1, leaking CI secrets including the token behind the tj-actions attack.
Read breach analysis → NHI Stolen credentialsA stolen bot PAT let attackers repoint tj-actions/changed-files tags to code that printed CI/CD secrets to logs (CVE-2025-30066).
Read breach analysis → NHI Leaked secretCybernews found 71% of 156,080 iOS apps leak hard-coded secrets, exposing 406 TB in open storage and 19.8 million Firebase records.
Read breach analysis →Truffle Security found 11,908 live API keys and passwords in Common Crawl, a dataset used to train LLMs, mostly hard-coded in web pages.
Read breach analysis → NHI Social engineeringHow hijacked AWS session tokens from a Safe{Wallet} developer laptop let North Korean attackers alter wallet code and steal about $1.5 billion from Bybit.
Read breach analysis → NHI Stolen credentialsCisco Talos found Salt Typhoon entered US telecoms mostly with stolen credentials, then harvested SNMP strings and TACACS/RADIUS keys to persist.
Read breach analysis → Claimed Human identity Not disclosedA hacker claims a 2024 Zacks breach; HIBP verified 12 million leaked accounts with unsalted SHA-256 hashes. Zacks has not confirmed it.
Read breach analysis → Claimed NHI Stolen credentialsKraken posted Cisco Active Directory hashes, including service accounts and krbtgt, in 2025. Cisco says the data is from its May 2022 breach.
Read breach analysis → NHI Leaked secretMicrosoft found 3,000+ ASP.NET machine keys copied from public sources; one was used to inject Godzilla malware via ViewState in 2024.
Read breach analysis →Wiz found an unauthenticated DeepSeek ClickHouse database exposing a million log lines, chat history and API keys in January 2025.
Read breach analysis → Claimed NHILLM & AI platform Not disclosedA hacker claims to have leaked 34 million OmniGPT chat messages containing users' API keys and credentials. OmniGPT has not confirmed it.
Read breach analysis → NHI Stolen credentialsCodefinger used compromised AWS keys to re-encrypt S3 data with SSE-C keys only it held, then demanded ransom. How long-lived keys enabled it.
Read breach analysis → NHILLM & AI platform Leaked secretStorm-2139 used Azure OpenAI API keys stolen from Microsoft customers to bypass guardrails and resell access. How the LLMjacking scheme worked.
Read breach analysis →How a phished OAuth consent let attackers publish a malicious Cyberhaven Chrome extension update in December 2024, and the NHI lessons for OAuth apps.
Read breach analysis → NHI MisconfigurationDatadog showed the Azure Key Vault Contributor role could grant itself access to every secret in vaults using access policies. What to change.
Read breach analysis → NHI Stolen credentialsA compromised BeyondTrust Remote Support SaaS API key let a China state-sponsored actor reach US Treasury workstations in December 2024.
Read breach analysis →EMERALDWHALE scanned for exposed .git/config files, used the tokens to clone private repos and stole more than 15,000 cloud credentials.
Read breach analysis → NHI MisconfigurationIntelBroker took code and files from Cisco's public DevHub, exposed by a misconfigured migration script, and claimed hard-coded credentials inside.
Read breach analysis →An exposed GitLab token led to the theft of 31 million Internet Archive user records, and unrotated Zendesk tokens enabled a second breach.
Read breach analysis → NHI MisconfigurationA Razz Security researcher showed how credentials in an exposed .git directory let an edited Bitbucket pipeline add an SSH key to a production server.
Read breach analysis →An exposed GitHub credential let an attacker copy New York Times repositories in January 2024; 270GB of code was leaked on 4chan in June.
Read breach analysis → NHI Social engineeringThe Gitloker campaign wiped GitHub repos and demanded contact on Telegram, using stolen credentials and phishing for malicious OAuth app grants.
Read breach analysis →Hugging Face detected unauthorised access to Spaces secrets in May 2024, revoked tokens, removed org tokens and told users to refresh keys.
Read breach analysis → NHI Vulnerability exploitCVE-2024-37051 let malicious pull request content make IntelliJ-based IDEs send GitHub tokens to a third party. JetBrains fixed it; no exploitation known.
Read breach analysis → NHILLM & AI platform Leaked secretHow attackers use stolen cloud access keys and AI API keys to run and resell LLMs at the victim's expense: Sysdig, Permiso and Microsoft Storm-2139 cases.
Read breach analysis →Attackers compromised a Dropbox Sign back-end service account and reached customer data, including hashed passwords, API keys, OAuth tokens and MFA data.
Read breach analysis → Human identityNHI Stolen credentialsHow UNC5537 used infostealer credentials without MFA, unrotated for years, to steal data from about 165 Snowflake customers including AT&T in 2024.
Read breach analysis → NHI Leaked secretSisense and CISA told customers to rotate all credentials after attackers reportedly used a GitLab credential to reach S3 buckets of customer secrets.
Read breach analysis →A contributor spent two years gaining maintainer rights, then hid a backdoor in XZ Utils that could bypass SSH authentication. How it was caught.
Read breach analysis → NHI MisconfigurationResearchers found 916 websites with open Firebase security rules exposing 125 million user records and about 19.87 million plaintext passwords.
Read breach analysis →How deepfaked video of Arup's CFO and colleagues persuaded a Hong Kong finance worker to make 15 transfers totalling HK$200 million (about US$25.6m).
Read breach analysis → NHIHuman identity Stolen credentialsIn 2024 Microsoft disclosed that Midnight Blizzard sprayed a test account without MFA, then abused OAuth apps with full_access_as_app to read executive email.
Read breach analysis → NHIHuman identity Vulnerability exploitTwo Ivanti VPN zero-days let attackers harvest user passwords and appliance-stored service account credentials, keys and certificates, breaching CISA.
Read breach analysis →Aqua found Kubernetes registry secrets in public GitHub repos, including an SAP artifact repository key with access to 95 million artifacts.
Read breach analysis → NHI Stolen credentialsA service token and three service accounts Cloudflare failed to rotate after the Okta breach let a nation-state attacker into its Atlassian servers.
Read breach analysis → NHI Leaked secretGitGuardian and Tom Forbes found 3,938 unique secrets in 2,922 PyPI projects, 768 valid, including cloud, database and SSH credentials.
Read breach analysis → NHI Stolen credentialsA compromised credential was used to access a Sumo Logic AWS account, prompting customers to rotate API keys. No customer data impact was found.
Read breach analysis →A stolen Okta support service account exposed HAR files of 134 customers; session tokens in them were used to hijack five customers' Okta sessions.
Read breach analysis → Human identity Social engineeringAttackers social engineered an outsourced IT support vendor and stole Caesars loyalty database with licence and SSN data. A ransom was reportedly paid.
Read breach analysis → Human identity Social engineeringAttackers impersonated an MGM employee to the help desk, took Okta and Azure admin access, encrypted 100+ ESXi hosts and cost MGM about $100 million.
Read breach analysis →RWTH Aachen researchers found 52,107 private keys and 3,158 API secrets in container images, with 275,269 hosts relying on leaked keys.
Read breach analysis → NHI Stolen credentialsAttackers used stolen GitHub personal access tokens to push fake Dependabot commits to hundreds of repos in 2023, stealing CI/CD secrets.
Read breach analysis →Storm-0558 forged tokens with a stolen 2016 Microsoft signing key to read email at 22 organisations in 2023. How the key and validation failed.
Read breach analysis → NHI Leaked secretA 2020 email with an ArcGIS login was stolen and published in 2023. The password still worked, exposing Polish military and port maps.
Read breach analysis →Stolen Slack employee tokens, taken via a compromised vendor, let an attacker download private GitHub repos over the 2022 holidays.
Read breach analysis → NHI Stolen credentialsMalware stole a CircleCI engineer's 2FA-backed SSO session, letting attackers exfiltrate customer secrets, tokens and keys. What went wrong.
Read breach analysis → NHI OAuth / SaaS integrationFraudulent Microsoft partner accounts gave malicious OAuth apps a verified badge in 2022; users who consented handed over mailbox tokens.
Read breach analysis → NHI Stolen credentialsA compromised GitHub machine account token cloned Desktop and Atom repos in 2022, exposing code signing certificates that GitHub then revoked.
Read breach analysis →A keylogger on a DevOps engineer's home PC exposed AWS access keys and decryption keys, letting an attacker copy LastPass customer vault backups in 2022.
Read breach analysis → Human identity Social engineeringSMS phishing gave attackers Twilio employee logins in August 2022, affecting 209 customers and exposing about 1,900 Signal users. The 0ktapus campaign.
Read breach analysis →In 2021 attackers altered Codecov's Bash Uploader with a leaked cloud key, harvesting CI secrets, tokens and keys from customer pipelines for two months.
Read breach analysis → NHI Leaked secretEthical hackers used exposed Git credentials to reach 100,000+ UNEP staff records in 2021. How leaked repository secrets unlocked UN databases.
Read breach analysis →Go deeper with NHI Mgmt Group.
NHI Ultimate Guide → Security Guides → NHI Foundation Level Course → Products → Blogs → Forum → Our Services →