Threat models include failure without an attacker

Not every threat has a person behind it.

A dependency going away, a certificate expiring, a supplier failing, a component behaving unexpectedly under load. These produce the same outcomes as an attack and are considerably more likely. Threat models that only consider adversaries miss the majority of things that will actually go wrong.

More on Threat modelling