Security

Attackers aren't breaching your agents. They're stealing their credentials.

A supply chain attack on an AI plugin ecosystem sat undetected for six months using harvested agent credentials. The agent's logic was never touched. Its API key was the entire attack.

In early 2026, a supply chain attack on the OpenAI plugin ecosystem harvested credentials from 47 enterprise deployments, giving attackers access to customer data, financial records, and proprietary code for six months before anyone noticed. Nobody exploited a flaw in the agent's reasoning. They exploited a flaw in how its credentials were stored and rotated — and that is where nearly all agent compromise happens now.

The pattern is consistent, and it is not exotic

For non-human identities, the key targets are API keys and access tokens, not the model or the prompt. Seventy-one percent of non-human identities are not rotated within recommended timeframes, and 97% of organizations that suffered an AI-related breach lacked proper AI access controls. The Salesloft Drift incident followed the identical shape: compromised OAuth tokens were used to pivot into Salesforce environments belonging to major enterprises including Google, Cisco, and Zscaler. In every case, the sophisticated-sounding "AI security incident" reduces to a credential-management failure that would have looked familiar a decade ago in any other system.

Why agents make a familiar problem much worse

A stale credential on a static service account is bad, but bounded — the account can typically only do what it was originally scoped to do. An AI agent's credential is a different order of risk because agents acquire permissions dynamically at runtime, spawn sub-agents, and chain actions across dozens of systems in sequence. A single compromised agent credential does not just grant a single door. It grants whatever the agent itself could reach in the moment it was compromised, which for a capable agent can be a much larger blast radius than the person who provisioned it ever intended.

The fix is unglamorous and already exists

None of this requires a new category of defense. It requires applying identity hygiene that already exists in security playbooks — short-lived credentials, aggressive rotation, least-privilege scoping, real-time revocation — to a population of accounts that has been treated as an afterthought because it is not human. The technology to do this is mature. The gap is that most organizations have not yet decided an agent's credential deserves the same operational discipline as a human's.

Audit your agent credentials with the same rigor you audit employee access, on the same rotation schedule, with the same kill switch available. The 2026 breaches that matter are not failures of the model. They are failures of the key left in the ignition.

What this reacts to

The daily brief

CIOReview, in your inbox before standup

The headlines technology leaders are reading, synthesized and source-linked. One email each morning. No filler.