SecurityScorecard today released the 2025 Global Third-Party Breach Report. Using the world’s largest proprietary risk and threat data set, SecurityScorecard’s STRIKE Threat Intelligence Unit anal...
NEW YORK: SecurityScorecard today released the 2025 Global Third-Party Breach Report. Using the world’s largest proprietary risk and threat data set, SecurityScorecard’s STRIKE Threat Intelligence Unit analyzed 1,000 breaches across industries and regions to uncover key attack patterns, measure the impact of third-party security failures and identify the most commonly exploited vendor relationships.
Ryan Sherstobitoff, SVP of SecurityScorecard’s STRIKE Threat Research and Intelligence, said: "Threat actors are prioritizing third-party access for its scalability. Our research shows ransomware groups and state-sponsored attackers increasingly leveraging supply chains as entry points. To stay ahead of these threats, security leaders must move from periodic vendor reviews to real-time monitoring to contain these risks before they escalate throughout their supply chain."
Key Findings:
Actionable Strategies to Reduce Third-Party Breach Risk
Based on third-party breach patterns, SecurityScorecard offers these targeted recommendations for security teams:
For more in-depth analysis and to download the report, visit: securityscorecard.com/resource/global-third-party-breach-report
Methodology
The findings in this report are based on a multi-source analysis of open-source intelligence (OSINT), security research, lawsuits, corporate filings, government disclosures, mainstream news media and underground criminal forums. This breach sample came from SecurityScorecard's intelligence feed, which is used in SecurityScorecard’s SCDR platform to inform risk scoring and initiate incident response workflows.
Unlike other reports that rely solely on self-reported data, this study integrates real-world breach intelligence gathered by SecurityScorecard's STRIKE Threat Intelligence team. Most breaches in the sample were not third-party related—this was intentional to provide a broader comparison sample.
About SecurityScorecard
SecurityScorecard created Supply Chain Detection and Response (SCDR), transforming how organizations defend against the fastest-growing threat vector—supply chain attacks. Our industry-leading security ratings serve as the foundation and core strength, while SCDR continuously monitors third-party risks using our factor-based ratings, automated assessments and proprietary threat intelligence, to resolve threats before they become breaches. MAX enables response and remediation capability, working through our service partners to protect the entire supply chain ecosystem while strengthening operational resilience, enhancing third-party risk management and mitigating concentrated risk.
Trusted by over 3,000 organizations—including two-thirds of the Fortune 100—and recognized as a trusted resource by the U.S. Cybersecurity & Infrastructure Security Agency (CISA). Backed by Evolution Equity Partners, Silver Lake Partners, Sequoia Capital, GV, NGP, Intel Capital and Riverwood Capital, SecurityScorecard delivers end-to-end supply chain cybersecurity that safeguards business continuity.
Learn more at securityscorecard.com or follow us on LinkedIn.
Fonte: Business Wire
Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…
G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes
Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries
Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…
Market News Alerts Reports: Inspira Technologies (NASDAQ: IINN)* is reported beginning deployment of its FDA-cleared INSPIRA ART100 system at a leading…
The "Middle East & Africa Existing & Upcoming Data Center Portfolio" database has been added to ResearchAndMarkets.com's offering. This database…
#FPT--FPT announced it received a SAP® APJ Award for Partner Excellence 2025 for Regional Strategic Services Partner. Awards were presented by SAP to…
Motive, the AI Platform for Physical Operations, today announced it has been named to G2’s 2025 Best Software Awards, placing #1 on the Best Supply Chain…