The Alarming Rise of Non-Human Identities: A New Frontier in Security Vulnerabilities
Apr 09, 2025
Secrets Management / DevOps
The 2025 GitGuardian State of Secrets Sprawl report highlights the critical issue of secrets exposure in contemporary software environments. A key driver of this concern is the explosive growth of non-human identities (NHIs), which have consistently outnumbered human users for several years. It’s imperative that we proactively implement security measures and governance for these machine identities, as their ongoing deployment poses unprecedented security risks.
In 2024 alone, a staggering 23.77 million new secrets were leaked on GitHub—a 25% increase from the previous year. This dramatic surge underscores how the rapid proliferation of NHIs, including service accounts, microservices, and AI agents, is significantly expanding the attack surface for cyber threats.
The NHI Security Challenge
Within DevOps environments, non-human identity secrets, such as API keys and service accounts, now surpass human identities by a ratio of at least 45-to-1, fundamentally altering the security landscape.