CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Expanded Impact of Third-Party Breaches in 2025

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

In 2025, 136 verified third-party breaches impacted 433 million individuals and 719 downstream companies, with an additional 26,000 corporate victims unlisted. The median time for breach detection was 10 days, and notification took 73 days on average. Over half of monitored organizations had critical vulnerabilities, and 23% had credentials on the dark web. The report highlights significant delays in breach detection and notification, emphasizing the systemic risk posed by third-party breaches. Software services vendors were the primary source of breaches, affecting sectors like healthcare, education, and financial services. The analysis of top shared vendors revealed widespread critical vulnerabilities and active targeting, indicating a growing crisis in third-party risk management.

Timeline

  1. 03.03.2026 13:00 1 articles · 23h ago

    2025 Third-Party Breach Report Highlights Expanded Impact and Systemic Risks

    In 2025, 136 verified third-party breaches impacted 433 million individuals and 719 downstream companies, with an additional 26,000 corporate victims unlisted. The report highlights significant delays in breach detection and notification, emphasizing the systemic risk posed by third-party breaches. The analysis of top shared vendors revealed widespread critical vulnerabilities and active targeting, indicating a growing crisis in third-party risk management.

    Show sources

Information Snippets