Home Cyber Security

Machine identities and AI-driven attacks reshaping cloud security risks

As organisations race to deploy AI and cloud-native applications, a less visible but rapidly growing risk is emerging: the explosion of machine identities—and their increasing role in cyberattacks.

According to the latest Cloud Threat Horizons Report H1 2026 from Google Cloud Security, identity compromise is now at the centre of the majority of cloud breaches, with attackers increasingly targeting not just human users, but service accounts, API keys and automated workloads.

This shift marks a fundamental change in how cloud environments are attacked—and defended.

The rise of non-human identities

Traditionally, identity security focused on employees: usernames, passwords and multi-factor authentication. But modern cloud environments are now dominated by non-human identities—service accounts, containers, automation scripts and AI agents that interact with systems autonomously.

These identities often have broad access privileges and are rarely monitored as closely as human users.

The Google report highlights that compromised credentials and weak identity controls remain one of the most common entry points for attackers, reinforcing that identity is now the primary attack surface in cloud environments.

What makes machine identities particularly risky is their scale and persistence. In many environments, they significantly outnumber human users and operate continuously, often with elevated privileges.

Once compromised, they provide attackers with a powerful foothold.

Rather than triggering alerts through suspicious logins, attackers can quietly move laterally using trusted service accounts—accessing data, modifying workloads or escalating privileges without raising immediate suspicion.

From single credential to full compromise

The report also points to a concerning trend: the speed at which attackers can escalate access once inside a cloud environment.

With the help of automation and AI-assisted techniques, threat actors are increasingly able to pivot from a single compromised credential to broader administrative control in a matter of hours or days.

In some cases, attackers are leveraging AI tools to automate reconnaissance, privilege escalation and lateral movement—compressing what was once a multi-stage attack into a rapid, largely automated process.

This acceleration significantly reduces the window for detection and response.

It also challenges traditional security models that rely on manual investigation or delayed patch cycles.

AI is amplifying both sides of the equation

While much of the focus on AI has centred on productivity and innovation, the report makes clear that AI is also reshaping the threat landscape.

Attackers are beginning to use AI to:

  • Automate phishing and social engineering campaigns

  • Identify misconfigurations and exposed services faster

  • Analyse large cloud environments to find privilege escalation paths

  • Accelerate exploitation of newly discovered vulnerabilities

At the same time, AI-driven workloads themselves are becoming new targets.

Because AI systems often require access to large datasets, APIs and compute resources, they are frequently granted broad permissions—creating additional risk if compromised.

This convergence of AI adoption and identity sprawl is creating what security experts describe as a perfect storm” for cloud risk.

Why traditional controls are falling short

One of the key insights from the Google report is that traditional perimeter-based security models are no longer sufficient in cloud environments.

In a world where workloads are distributed, APIs are constantly interacting, and identities—both human and machine—are the primary control plane, security must shift accordingly.

Static controls such as network boundaries or one-time authentication checks offer limited protection when attackers can operate using legitimate credentials.

Instead, organisations need continuous visibility into how identities are being used—and abused—across their environments.

Rethinking identity security for the AI era

To address these challenges, the report recommends a stronger focus on identity governance and automation.

This includes:

  • Enforcing least-privilege access across all identities, including service accounts

  • Regularly auditing permissions and removing unused or excessive access

  • Monitoring identity behaviour in real time to detect anomalies

  • Securing API keys and machine credentials with the same rigour as human accounts

Importantly, organisations must also extend these controls to AI systems and automated workflows, which are increasingly acting as independent operators within cloud environments.

A new frontline in cloud security

The findings highlight a broader shift in cybersecurity: the frontline is no longer the network—it is identity.

As cloud adoption deepens and AI systems become embedded in business operations, attackers are following the path of least resistance—targeting the credentials, permissions and automated systems that underpin modern infrastructure.

For Australian organisations, this presents both a challenge and an opportunity.

Those that treat identity as a core security discipline—rather than a supporting function—will be better positioned to manage risk in an increasingly automated, AI-driven world.

Those that don’t may find that the very technologies designed to accelerate innovation are also expanding their attack surface in ways they have yet to fully understand.