Quick Facts
- Organizations now have 82 machine identities for every human, with 42% having privileged access
- Gartner’s ransomware playbook only addresses human credentials, ignoring API keys, tokens, and certificates
- 50% of organizations have suffered breaches from compromised machine identities in the past year
Most corporate ransomware response plans contain a critical blind spot that attackers are exploiting. While playbooks mandate resetting every employee password after an attack, they ignore the machine credentials that now outnumber humans 82 to 1.
CyberArk’s 2025 Identity Security Landscape found organizations worldwide average 82 machine identities for every human worker. Of those machine identities, 42% have privileged or sensitive access to critical systems.
Yet Gartner’s ransomware preparation guidance focuses entirely on human credentials. The April 2024 research note instructs teams to reset “impacted user/host credentials” during containment. All three credential reset steps target human accounts in Active Directory.
Service accounts, API keys, tokens, and certificates receive no mention in the playbook.
“Resetting every employee’s password after an incident is standard practice, but it doesn’t stop lateral movement through a compromised service account,” security researchers note. Pulling a compromised machine off the network doesn’t revoke the API keys it issued to downstream systems.
The oversight carries steep costs. Gartner warns recovery expenses can reach 10 times the ransom amount. Average ransom payments jumped from $400,000 in 2023 to $2 million in 2024, according to Sophos.
Half of organizations surveyed by CyberArk experienced security breaches tied to compromised machine identities in the past year. The incidents caused application launch delays for 51% of affected companies, outages for 44%, and unauthorized access to sensitive systems for 43%.
Ransomware incidents in the United States increased 149% year-over-year in early 2025, with 378 attacks compared to 152 in the same period last year, according to Cyble data.
“The race to embed AI into environments has inadvertently created a new set of identity security risks centered around the access of unmanaged and unsecured machine identities,” said Clarence Hinton, Chief Strategy Officer at CyberArk.
The problem extends beyond AI deployments. Organizations anticipate machine identities will spike by as much as 150% as digital transformation accelerates.
Only 38% of ransomware victims fixed the specific vulnerability that allowed attackers initial access. The remaining 62% invested in general security improvements without closing the actual entry point.
Despite the growing threat, just 30% of security professionals say they are “very prepared” to defend against ransomware, while 63% rate it as a high or critical threat.
Read more: Most ransomware playbooks don’t address machine credentials. Attackers know it.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
