惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
J
Java Code Geeks
I
InfoQ
V
Visual Studio Blog
M
MIT News - Artificial intelligence
H
Help Net Security
博客园_首页
Blog — PlanetScale
Blog — PlanetScale
F
Fortinet All Blogs
Apple Machine Learning Research
Apple Machine Learning Research
人人都是产品经理
人人都是产品经理
G
Google Developers Blog
A
About on SuperTechFans
腾讯CDC
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
S
SegmentFault 最新的问题
WordPress大学
WordPress大学

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Huge “Shadow Layer” of Organizations Hit by Supply Chain ...
2026-03-03 · via www.infosecurity-magazine.com

Photo of Phil Muncaster

Security experts have claimed that the blast radius of third-party data breach incidents is far larger than at first thought, with more than 433 million individuals impacted by 136 events last year.

Black Kite compiled its seventh annual Third-Party Breach Report from analysis of verified public breach disclosures in 2025, external cyber risk telemetry and supply chain intelligence.

It said 136 verified breaches had 5.28 publicly named downstream victims per vendor, amounting to 719 companies and 433 million individual end customers.

However Black Kite said affected vendors also reported an additional 26,000 corporate victims without naming them. That could mean the total number of downstream individuals impacted is even greater.   

Read more on third-party breaches: SecurityScorecard Observes Surge in Third-Party Breaches.

The ground zero for these events tended to be software services vendors, which accounted for 38 (28%) of the 136 verified breaches, followed by professional and technical services (14) and healthcare services providers (10).

In terms of downstream corporate victims, most appear to be in healthcare (258), education (140) and financial services (101).

“These sectors tend to combine high data sensitivity with heavy reliance on external platforms, placing them downstream in complex dependency chains,” the report noted. “The pattern is consistent. Breach impact accumulates in data-rich sectors at the edges of the supply chain, while risk originates upstream, within a smaller set of centralized service providers.”

Less Visibility, More Risk

The report also highlighted delays in breach discovery and public disclosure. The median time for vendors to detect an intrusion was 10 days, while the average was 68 days.

While this indicates a problem with threat detection, delays in notification potentially reveal forensics and incident response issues. The report claimed that time to notify customers hit a median of 73 days and an average of 117 days.

“Let’s be clear: 73 days is not an ‘investigation period.' In the context of active exploitation it is an eternity,” the report noted. “This delay denies downstream customers the chance to revoke access, reset credentials or lock down their own systems. Transparency delayed is risk transferred.”

The chances of future breaches remain high. Of the 200,000 organizations monitored by Black Kite, over half (54%) had at least one critical vulnerability and 23% were found to have corporate credentials circulating on the dark web.

An analysis of the top 50 “most shared” vendors among Forbes Global 2000 customers found that:

  • 70% have at least one CISA KEV exposure, and 84% have critical vulnerabilities
  • 80% display exposure to phishing URLs, and 40% show signals of active targeting
  • 62% have corporate credentials exposed in stealer logs, and 30% have breached credentials in the past 90 days
  • 52% have a breach history, with 18% suffering an incident in the past year

“Traditional third-party risk management is not keeping pace with the reality of today’s threats,” argued Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “Over the past year, these risks have transformed from a series of isolated accidents into a systematic crisis.”