惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
Y
Y Combinator Blog
I
InfoQ
美团技术团队
罗磊的独立博客
B
Blog RSS Feed
GbyAI
GbyAI
小众软件
小众软件
IT之家
IT之家
Engineering at Meta
Engineering at Meta
Blog — PlanetScale
Blog — PlanetScale
V
V2EX
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
MyScale Blog
MyScale Blog
博客园 - 聂微东
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO
Security snafus caused by third parties up from 15% to 30%
Connor Jones Connor Jones · 2025-04-24 · via The Register - Security: CSO

CSO

Your vendor may be the weakest link: Percentage of third-party breaches doubled in a year

Cybercriminals are targeting software shops, accountants, lawyers

The percentage of confirmed data breaches involving third-party relationships doubled last year as cybercriminals increasingly exploited weak links in supply chains and partner ecosystems.

That's according to Verizon's Data Breach Investigations Report (DBIR) —one of the industry's most-watched autopsies on what actually goes wrong in infosec. This year's edition, released Wednesday, covers incidents that occurred between November 1, 2023, and October 31, 2024.

It found that the proportion of breaches involving third parties rose from 15 percent in last year's dataset to 30 percent in this year's report. This figure includes those breaches (incidents in which data loss was confirmed) caused by exploited software vulnerabilities and supply chain compromises.

Ilia Kolochenko, CEO at ImmuniWeb and fellow at the British Computer Society, said during a launch event for the report that cybercriminals are increasingly looking at organizations such as accountants and law firms as ways to reach their intended targets.

"Criminals are smart and pragmatic; they count every cent and are cost-conscious," he said, explaining why more vulnerable companies can act as reliable gateways into much bigger target environments.

Verizon said that vendors and other business partners are expanding the attack surface by failing to enforce proper access controls, including preventing credential misuse. In particular, weak third-party practices continue to expose organizations to downstream risks.

One example: in third-party environments, the median time to remediate leaked secrets, such as API keys or tokens discovered in public GitHub repositories, was 94 days, giving attackers ample opportunity to exploit them.

Leaked secrets weren't the only problem. The report also highlights how credential reuse played a key role in several high-profile incidents, including a major Snowflake-related breach, where attackers used previously exposed credentials to access customer accounts due to the lack of mandatory multi-factor authentication (MFA).

Other key takeaways:

There are other juicy tidbits in the 117-page report — here are some of the highlights:

  • Exploiting vulnerabilities for initial access is up 34 percent year over year, now accounting for one in five breaches.
  • Only 54 percent of perimeter device vulnerabilities were fully remediated, and it took organizations 32 days to do so on average.
  • 44 percent of breaches involved ransomware, a yearly increase of 37 percent.
  • However, the median ransom payment was down to $115,000, and 64 percent refused to pay up at all.
  • The human element was a factor in 60 percent of breaches – a figure that's statistically unchanged from the previous year.
  • State-sponsored attacks with a clear financial focus comprised 28 percent of all those carried out by those with state backing. Espionage-focused operations accounted for only 17 percent overall.
  • The percentage of malicious emails featuring AI-generated content doubled over the past two years, rising from around 5 percent to roughly 10 percent.
  • 15 percent of employees routinely accessed generative AI platforms on work devices which Verizon claimed increased the risk of corporate data leaks.

Major organizations such as Santander and Ticketmaster got hit after threat actors from the ShinyHunters group used stolen credentials to access Snowflake customer accounts last summer, affecting hundreds of millions of records.

Verizon noted that it wasn't solely Snowflake's fault - roughly 80 percent of the affected customer accounts had previously exposed credentials, which amplified the fallout.

However, the lack of mandatory MFA across Snowflake accounts made the campaign particularly effective. This gap was one of the first things Snowflake moved to address after the incident.

"Only in a perfect world with no conflict of responsibilities would the challenge of securing infrastructure (or platform) as a service providers be the same as that of securing on-premise assets for areas they don't explicitly cover," the report reads. 

"That means managing credentials will likely be harder in an environment you don't control. Secure-by-default standards on those platforms make a significant difference in the security bottom line, as the quick post-incident policy updates from Snowflake would suggest."

Other major incidents involving software providers over the past year include CDK Global, Blue Yonder, and Change Healthcare. Verizon classified these as ransomware breaches that not only compromised of millions of personal records, but also triggered widespread business interruption for customers - particularly across healthcare, retail, and food service sectors.

Securing the source

Organizations looking to mitigate the risk of third-party breaches should be ensuring cybersecurity is treated as a priority during the procurement process, Verizon recommends.

That's not always possible for organizations with existing contracts, especially when there are no viable alternatives on the market. Even then, removing a deeply entrenched provider from an environment is an arduous task.

But during your next sales call, it may be worth asking vendors how they handle cyber hygiene and how they ensure access to data is limited. Then, during the contract-drawing phase, ensure the third party's responsibilities toward security are clearly codified. This will makes it easier to hold vendors accountable when things go sideways.

That's all in addition to ensuring the basics are covered: MFA by default, network segmentation, strict authentication policies, and API key aging.

In the end, some threats are impossible to avoid, but collaboration can help mitigate the risks. "At the end of the day, there is no simple or infallible method of avoiding some of the threats we discuss in this report," Verizon said. 

"Holding vendors accountable is certainly part of the equation. However, it is only through collaborating with transparency and increased information sharing that organizations can build good, structured frameworks for threat modeling, and as a result, make better and more sustainable decisions for safeguarding their data and the customers they serve." ®