What is a Third-Party Data Breach?
A third-party data breach is a security incident where an organization's sensitive data is compromised or stolen due to a vulnerability or cyber attack on one of its third party vendors. This type of breach happens outside the primary organization's own IT infrastructure but still impacts them, as the third-party vendor, contractor, or service provider has access to their data.
Stolen data may include sensitive, proprietary, or confidential information such as credit card numbers, trade secrets, customer, or patient data. Third party breaches cost millions of dollars every year to companies of all sizes. The average total cost of a data breach is $4.35 million, and in the United States, it rises to $9.44 million.
Because attackers target a member of the victim’s supply chain, a third party data breach might also be called a supply chain attack. These attacks are often successful because third parties, including vendors, suppliers, contractors, or business partners, may have weaker security controls than the organizations they provide services to.
7 Recent Third-Party Data Breaches
Third-party vendors are critical to your business – but they also introduce cyber risk. Indeed, supply chain attacks are now the preferred method used by threat actors, and 62% of network intrusions originate with a third-party – often someone in your software supply chain.
The alarming aspect of a third-party data breach is the sheer scale of impact. Hackers have the potential to attack thousands of organizations in one fell swoop. According to a study by KPMG, 73% of organizations have experienced at least one significant disruption from a third-party cyber incident within the last three years.
Managing third-party cyber risk can be complex, but neglecting it poses substantial risks. Let’s look at five of the biggest third-party data breaches in recent years, how they happened, and their impact. We’ll also offer a step-based approach for maturing your third-party risk management (TPRM) program.
1. NotPetya (2017)
Although supply chain-based attacks have grown tremendously in the past year or two, one of the more notable ones happened in 2017. A Petya ransomware variant called NotPetya was used to target a Ukrainian accounting software package -- using a vulnerability previously exploited in the WannaCry supply chain attack as well as a credential-stealing technique for non-vulnerable machines -- before deploying ransomware.
Impact
The malware quickly spread beyond Ukrainian targets, affecting numerous multinational corporations, resulting in extensive financial losses, operational disruptions, and data destruction.
2. SolarWinds (2020)
In December 2020, SolarWinds (a provider of network and system monitoring software) confirmed that its network had been penetrated by a malicious actor and a complex malware program inserted into software updates of its technology platform – SolarWinds OrionⓇ. The program comprised a multistage process, scanning downstream customer networks to detect security tools it could avoid or disable, and stealthily connecting to the attacker’s command and control servers. The malware persisted for months before initial detection.
Impact
Because SolarWinds owned “the keys to the kingdom” for many organizations, it was an ideal target for disseminating an attack. Even organizations who did not use SolarWinds products were exposed to risk due to the prevalence of the company’s solutions within the supply chain. It’s estimated that 18,000 customers (including government agencies and 14% of the Fortune 1000) were impacted.
The financial fallout was also significant. Incident response and forensic services cost companies 11% of their annual revenue (an average of $12 million). Moreover, Bitsight’s analysis quantified the insured losses from the attack at $90,000,000. The breach also set the stage for other supply chain attacks.
Read more about The Future of Supply Chain Cyber Risk Management After SolarWinds and lessons learned from the failures that led to the attack.
3. Microsoft (2021)
Because most security tools trust anything implicitly signed by Microsoft, the tech giant is a frequent target of cyber attacks, and many of these exploit the interconnected supply chain. In March 2021, a series of breaches, known as the HAFNIUM attacks, compromised the on-premises Microsoft Exchange Servers of 30,000 global organizations. The attacks allowed hackers to access employee email accounts and install malware to facilitate long-term access.
Impact
Further demonstrating the surge in software supply chain security hacks, just months later, 38 million records were exposed due to a vulnerability in Microsoft Power Apps (a popular low-code business intelligence tool). Perpetrators gained access to COVID-19 testing, tracing, and vaccination records, as well as employee information for major organizations using the tool, such as Ford Motor Company, American Airlines, and the New York Metropolitan Transportation Authority.
4. Toyota (2022)
According to McKinsey, an auto manufacturer has around 250 tier-one suppliers, but the number proliferates to 18,000 across the full value chain – making these companies highly vulnerable to a third-party data breach.
For example, in March 2022, Toyota suspended production at 14 manufacturing plants in Japan after a supplier of plastic parts – Kojima Industries – was hit by a cyber attack. Toyota subsequently suspended operations of “all 28 lines at 14 domestic plants,” according to a company statement. The impacted output accounted for a third of global Toyota production.
Per McKinsey, even a short disruption of 30 days or fewer can put three to five percent of EBITDA margin at stake.
5. Uber (2022)
In December 2022, ride hailing giant Uber experienced a third-party data breach as a result of a compromised vendor. Teqtivity, which helps Uber track, monitor, and manage IT assets, confirmed that a hacker breached its systems and gained access to email addresses and other information pertaining to more than 77,000 Uber employees.
The hack follows a similar incident targeting DoorDash, where bad actors leveraged a connected vendor’s stolen credentials to access the food delivery giant’s internal systems and breach customer information, including credit card details.
6. U.S. School Districts (2022)
School districts are a lucrative target for hackers due to the volume of PII on their networks and limited security resources. Moreover, as EdTech tools gain traction, software supply chains have become a favored attack vector.
For example, a 2022 attack on Illuminate Education, a leading provider of student-tracking software, resulted in data breaches at the nation’s two largest school systems – New York City Public Schools and Los Angeles Unified School District – and countless more. The same year, 495,000 student records at Chicago Public Schools were exposed as a result of an attack on a third-party provider.
7. MOVEit (2023)
File transfer solutions are frequent targets of cybercriminals, due to their role in facilitating the exchange of sensitive data across the supply chain. In June 2023, three critical SQL injection vulnerabilities were discovered in Progress Software’s MOVEit Transfer platform, a tool designed to securely transfer sensitive files used by close to 1,700 organizations. Zellis, a UK-based payroll and HR solutions provider, was affected by the MOVEit vulnerability and targeted by the Cl0p ransomware gang.
Impact
This attack resulted in unauthorized access to sensitive personal information of both Zellis and its clients. The MOVEit supply chain attack also affected dozens of other organizations, including British Airways, the BBC, and the Minnesota Department of Education, and posed a significant risk to millions of individuals globally.