Total Tests:

Your vendor may be the weakest link: Percentage of third-party breaches doubled in a year

The Register
By Connor Jones for The Register
Thursday, April 24, 2025

It found that the proportion of breaches involving third parties rose from 15 percent in last year's dataset to 30 percent in this year's report. This figure includes those breaches (incidents in which data loss was confirmed) caused by exploited software vulnerabilities and supply chain compromises.

Ilia Kolochenko, CEO at ImmuniWeb and fellow at the British Computer Society, said during a launch event for the report that cybercriminals are increasingly looking at organizations such as accountants and law firms as ways to reach their intended targets.

"Criminals are smart and pragmatic; they count every cent and are cost-conscious," he said, explaining why more vulnerable companies can act as reliable gateways into much bigger target environments.

Verizon said that vendors and other business partners are expanding the attack surface by failing to enforce proper access controls, including preventing credential misuse. In particular, weak third-party practices continue to expose organizations to downstream risks. Read Full Article


Ask a Question