Service accounts are targeted by attackers for two reasons:
They are frequently configured to run as highly privileged accounts (example, Domain Admins)
Service accounts often log into many systems, expanding the attack surface for obtaining a password hash that can be reused to move laterally in an environment.