Industry breach research published in 2025 reported a substantial increase in breaches involving a third party, describing it as one of the year’s defining shifts.
The Corpus Has Been Arguing This For Three Hundred Files
Concentration is the largest theme in this database. Marquis at 25-0814, Chain IQ at 25-0613, PowerSchool at 25-0105, Episource at 25-0605, the back-office administrator at 25-0801, Eurofiber at 25-1128.
Having an external dataset report the same direction is worth recording, because a corpus built from disclosures could plausibly be over-representing supplier incidents simply because they generate more notifications — one breach, dozens of notifying customers.
Which Is Exactly The Caution To Apply Here Too
A breach at a supplier serving fifty customers produces up to fifty separate incidents in a dataset that counts by affected organisation. The share involving a third party rises mechanically as outsourcing rises, without any change in attacker behaviour.
That does not make the finding wrong. It means the finding is about the structure of the economy rather than about the threat landscape, which is a more durable and less urgent claim than the way it is usually reported.
And "Involving A Third Party" Is Doing A Lot Of Work
The category spans a supplier that was itself breached, a supplier whose credentials were used, a supplier whose software contained the vulnerability, and a supplier who merely held some of the data.
Those have different causes and different remedies. Reporting them as one share produces a large number and no actionable conclusion — the classification problem this desk filed at 25-1203. Graded medium accordingly.
Built on published reporting of industry breach research, listed below. Year-on-year shifts in such studies are affected by changes in contributing datasets, per 25-0423. Corrections: corrections@forensicpost.com.