Index live· 1,284 files · 148 editions
ForensicPost

Search the index

52 results
Try
Results for “Third party”Newest first
26-0806
File

Amgen Says Patient Health Data Was Taken From Third-Party Cloud Systems

Materiality asks whether an investor would want to know. Whether patients are harmed is a different question.

UnattributedThird-party cloud compromisePharmaThird party
Sev 4TargetAmgenActorUnattributedUSA
26-0731
File

Conduent Breach Affected More Than 62 Million People, Final Count Shows

The final count on the Conduent intrusion landed above 62 million people — third-largest in US healthcare history, at a processor most of them have never heard of.

SafePayRansomwareHealthcareThird party
Sev 5TargetConduent Business SolutionsActorSafePayUSA
26-0723
File

RevolutionParts Breach Exposed More Than Five Million Records

Five million records from a platform none of the customers knew they were using. Correlated failure, uncorrelated disclosure.

UnattributedUnder reviewRetailThird party
Sev 3TargetRevolutionPartsActorUnattributed
26-0721b
File

Patients Learned About an October 2025 Intrusion in July 2026

The remedy is 24 months of monitoring. The scanned passport stays valid for ten years.

UnattributedHealthcareThird party
Sev 4TargetUnlimited SystemsActorUnattributedUSA
26-0715b
File

They Shut the Network Down, and Forty-Two Million Relationships Went With It

A containment shutdown that locked members out of retirement accounts, and a credit union suing its own provider over the standards it contracted for.

UnattributedInsuranceThird party
Sev 4TargetTruStageActorUnattributed
26-0713
File

The Support Ticket Is the Breach

A compromise at a third-party ticketing platform used by EY’s IT staff. Ticket attachments hold whatever was needed to reproduce the problem.

UnattributedThird-party platformFinanceThird party
Sev 3TargetErnst & YoungActorUnattributed
26-0702
File

Qantas Customer Data Published a Year After Third-Party Platform Breach

Up to six million customers exposed in 2025; records published in 2026. Notification law assumes an incident that ends.

Scattered Lapsus$ HuntersThird-party platformRetailAviation
Sev 4TargetQantasActorScattered Lapsus$ Hunters
26-0628
File

Texas Parks and Wildlife Vendor Breach Exposed Three Million Licence Holders

Three million licence holders through a vendor the state chose. The data does not know it was collected for a fishing permit.

UnattributedThird-party vendorPublic sectorPublic sector
Sev 3TargetTexas Parks and WildlifeActorUnattributedUSA
26-0623
File

Third-party Flaw Exposed 14.2 Million Mailboxes at KDDI and Five Other ISPs

A third-party software flaw reached email accounts across six Japanese providers. Choosing a different ISP bought no independence.

UnattributedThird-party softwareTelecomThird party
Sev 3TargetKDDI and five other ISPsActorUnattributedJapan
26-0617
File

A Cardiac Monitor Produces a Continuous Record of You

Ambulatory cardiac data is continuous, and continuous physiology is a behavioural record collected for a clinical reason.

Extortion actor, unnamedThird-party applicationHealthcareMedical devices
Sev 3TargetiRhythmActorExtortion actor, unnamed
26-0327
File

Air France-KLM Named Among Organisations Hit in Third-Party Data Campaign

Customer data through a supplier, with the airline flying normally throughout. Aviation now appears here through both operations and data.

UnattributedThird-party platformLogisticsAviation
Sev 3TargetAir France-KLMActorUnattributedFrance
26-0322
File

Thirteen Million Support Tickets, Allegedly, Through a Contractor

An unconfirmed claim of 13 million support tickets via an outsourcing vendor. The access transfers; the control environment does not.

Mr. RaccoonBPO vendor phishingCloudThird party
Sev 3TargetAdobe (alleged)ActorMr. Raccoon
26-0228
File

A Third of School Breaches Happen at Somebody Else’s Company

Around 32% of K-12 breaches originate at a vendor. Districts outsourced the technology and kept the accountability.

MultipleThird-party vendorEducationEducation
Sev 3TargetK-12 school districtsActorMultiple
26-0211
File

Conduent Intrusion Affected 17,000 Volvo Group North America Staff

Employees of a customer of a processor. Three steps from the incident, with no point at which they could have exercised judgement.

SafePaySupplier intrusionManufacturingThird party
Sev 3TargetVolvo Group North AmericaActorSafePay
26-0209
File

BridgePay Ransomware Disrupted Payments for 70,000 Bryan Texas Utilities Customers

No data taken, no notification owed, 70,000 people unable to pay a bill. Availability fails independently of confidentiality.

UnattributedRansomwarePublic sectorThird party
Sev 2TargetBridgePay / Bryan Texas UtilitiesActorUnattributedUSA
26-0201
File

Chanel Named Among Organisations Hit in Third-Party Data Campaign

Another luxury house through another third-party platform. Discretion is part of what the customer is buying.

UnattributedThird-party platformRetailRetail
Sev 3TargetChanelActorUnattributed
26-0127
File

Sixty Institutions, One Technology Provider

Sixty institutions down through one provider. Pooling technology is what lets small member-owned banks exist, and it concentrates the risk.

UnattributedRansomwareFinanceThird party
Sev 4TargetCredit union technology providerActorUnattributed
26-0123
File

Vietnam Airlines Data Leaked Alongside Qantas Records

Publication is its own phase, timed for reasons unrelated to the victim. Nobody is required to tell affected people when it happens.

UnattributedThird-party platformLogisticsAviation
Sev 3TargetVietnam AirlinesActorUnattributedVietnam
26-0102
File

Commercial Counterparties Increasingly Litigate Supplier Security Failures Directly

A commercial claimant holds the contract, can quantify the loss and can fund discovery — which is where security practice actually gets examined.

UnattributedLitigationFinanceThird party
Sev 3TargetSupplier security obligationsActorUnattributed
25-1201
File

44% of 2025 Breaches Involved Ransomware and 30% a Third-Party Failure

Around 30% of 2025 breaches originated with a third party. The boundary an organisation defends stopped being the boundary that determines its exposure.

MultipleVariousMultipleAnalysis
Sev 4TargetGlobal breach landscapeActorMultiple
25-1128
File

Eurofiber Breach Exposed Documentation of European Network Infrastructure

Where fibre runs, which routes carry which customers, where the single points of failure sit — a dependency map for organisations that were never asked.

UnattributedTelecomThird party
Sev 4TargetEurofiberActorUnattributed
25-1112b
File

SitusAMC Attack Exposed Client Records Including JPMorgan Agreements

Vendor assessment at its most rigorous did not prevent this. The instrument measures whether a framework exists, not whether it operates.

UnattributedFinanceThird party
Sev 4TargetSitusAMCActorUnattributed
25-1121b
File

Salesforce Found Unauthorised Access to Customer Data via Gainsight App

The first case argues for stronger consent controls. The second shows they would not have helped, because nothing about the authorisation was wrong.

UnattributedIntegration compromiseCloudThird party
Sev 4TargetSaaS tenantsActorUnattributed
25-1110b
File

One Provider, Twenty Asset Managers

You can discover who your competitors bank with more readily than who runs their servers.

QilinMSP compromiseFinanceThird party
Sev 5TargetSouth Korean asset managersActorQilinSouth Korea
25-1013b
File

A Bank Said Its Clients’ Data May Have Been Exposed by Somebody Else

A client reads that their bank has had a breach. The bank’s systems were not compromised. Both are true.

UnattributedThird partyFinanceFinance
Sev 3TargetGoldman Sachs clientsActorUnattributed
25-1003b
File

Discord Breach Reached Billing Details via Third-Party Support Provider

The support function is where data is most accessible and least defended, because its purpose is to give people access to things.

UnattributedThird-party support providerCloudThird party
Sev 3TargetDiscordActorUnattributed
25-1005
File

Chess.com Breach Affected 4,541 People via Third-Party File Transfer

If the corpus only records incidents above an implicit size threshold, its picture is drawn from large organisations.

UnattributedThird-party file transferCloudThird party
Sev 2TargetChess.comActorUnattributed
25-0914b
File

The Organisation That Runs Everybody’s Trials

A CRO holds unpublished, market-moving results for competing sponsors simultaneously, and no register would record their exposure.

MultipleVariousPharmaThird party
Sev 4TargetContract research organisationsActorMultiple
25-0810
File

Two and a Half Million Records at a Company That Sells Security

Whatever the constraint was, it was not budget, headcount, expertise or tooling.

ShinyHuntersThird-party platformCloudCloud
Sev 3TargetGoogleActorShinyHunters
25-0801
File

The Biggest Health Breach of the Year Happened at a Company With No Patients

Every year the largest healthcare breach happens at a company patients have never heard of. That is where the data pools.

UnattributedHealthcareThird party
Sev 5TargetHealthcare back-office vendorActorUnattributed
25-0727
File

TransUnion Reports 4.4 Million Affected After Salesforce Database Reached

The bureau’s customers are lenders. The people in the database are its product.

ShinyHuntersThird-party platformFinanceFinance
Sev 4TargetTransUnionActorShinyHunters
25-0613
File

Chain IQ Breach Exposed 130,000 Employee Records Across 19 Clients

A function nobody considers sensitive — buying things — accumulated the staff directories of nineteen client organisations.

UnattributedFinanceThird party
Sev 3TargetChain IQ Group AGActorUnattributed
25-0605
File

Episource Ransomware Exposed Data on 5.4 Million People

5.4 million through a subsidiary of the group that had already produced the largest healthcare breach on record.

UnattributedRansomwareHealthcareThird party
Sev 4TargetEpisourceActorUnattributedUSA
25-0601b
File

They Used the Tool the Provider Used to Manage Everyone

An RMM platform is the purest case in this database: its entire purpose is executing commands on other people’s computers.

DragonForceUnpatched RMM platformCloudThird party
Sev 5TargetManaged service providerActorDragonForce
25-0529
File

Farmers Insurance Compromise Affected More Than 1.1 Million Customers

The peer-warning argument only helps organisations that are not first. Hindsight makes May look like August.

ShinyHuntersThird-party platformInsuranceInsurance
Sev 4TargetFarmers InsuranceActorShinyHunters
25-0515
File

Health IT Vendor Ransomware Exposed Data on 442,000 Patients

One vendor incident becomes many provider notifications on different dates. Anyone counting breaches sees several small ones.

UnattributedRansomwareHealthcareThird party
Sev 3TargetHealth IT vendorActorUnattributed
25-0426
File

Breaches Involving a Third Party Rose Sharply in 2025

The finding is about the structure of the economy rather than the threat landscape — more durable and less urgent than reported.

MultipleThird partyMultipleAnalysis
Sev 3TargetMultiple sectorsActorMultiple
24-1121
File

The Software That Tells the Supermarket What to Order

An American software vendor’s outage changed what was on sale in British supermarkets.

TermiteRetailThird party
Sev 4TargetBlue YonderActorTermiteUSA
24-1104
File

Nokia Source Code Leaked From a Contractor’s Server With Default Logins

Nokia was right that its systems were not breached. Its code was published anyway.

IntelBrokerThird-party contractor serverTechnologySupply chain
Sev 3TargetNokiaActorIntelBrokerFinland
24-0716
File

Advance Auto Parts Notified 2,316,591 People After Snowflake Theft

Applied for a job, was not hired, and handed over a social security number to be considered.

UNC5537Third-party cloud platform accessRetailRetail
Sev 4TargetAdvance Auto PartsActorUNC5537USA
24-0625
File

Neiman Marcus Confirmed Breach of a Cloud Database Platform

Customers learned their data had gone, and could not learn from whom.

UNC5537Third-party cloud database accessRetailRetail
Sev 3TargetNeiman MarcusActorUNC5537USA
24-0514
File

Santander Customer Data Listed for Sale After Third-Party Access

A customer can change bank. An employee handed the details over as a condition of the job.

UnattributedThird-party database accessFinancial servicesFinance
Sev 4TargetSantanderActorUnattributedSpain
24-0314
File

Giant Tiger Vendor Breach Put 2.8 Million Customer Records Online

Data for sale reaches whoever pays. Data published free reaches everyone, permanently.

UnattributedThird-party vendor compromiseRetailThird party
Sev 3TargetGiant TigerActorUnattributedCanada
24-0306
File

American Express Card Numbers Exposed Through a Merchant Processor

Each hop between merchant and issuer is a copy, and the cardholder chose none of them.

UnattributedThird-party processor compromiseFinancial servicesThird party
Sev 3TargetAmerican ExpressActorUnattributedUSA
23-0907
File

Caesars Paid About $15 Million While MGM Refused in the Same Week

Paying bought silence about data already copied. None of the $15m was spent on the members.

Scattered SpiderSocial engineering — third-party help deskHospitalityAftermath
Sev 4TargetCaesars EntertainmentActorScattered SpiderUSA
23-0601
File

CISA and FBI Say Cl0p Exploited a MOVEit Zero-Day to Steal Transfer Databases

A product bought to move sensitive files safely became the reason thousands of organisations lost them at once.

Cl0pSQL injectionMultipleThird party
Sev 5TargetMOVEit Transfer customersActorCl0pUSA
23-0512c
File

Discord Says a Support Vendor’s Agent Account Exposed Ticket Contents

People write to support when something has gone wrong, and they explain it.

UnattributedThird-party account compromiseTechnologyThird party
Sev 2TargetDiscordActorUnattributed
23-0331
File

Capita Took 58 Hours to Quarantine the Device That Started Its Breach

The alert fired in ten minutes. The device stayed on the network for 58 hours.

Black BastaMalicious file executionPublic sectorThird party
Sev 5TargetCapitaActorBlack BastaUnited Kingdom
23-0203
File

Cl0p Exploited a GoAnywhere MFT Zero-Day Four Months Before MOVEit

The same operators, the same product category, four months before MOVEit. The rehearsal nobody treated as one.

Cl0pCommand injectionMultipleThird party
Sev 5TargetGoAnywhere MFT customersActorCl0p
22-0815
File

Signal Says Twilio Breach Exposed 1,900 Users, With Three Numbers Targeted by Name

1,900 is the exposure. Three is the objective. No notification scheme has a field for that.

UnattributedThird-party compromise — TwilioTechnologyThird party
Sev 3TargetSignalActorUnattributedUSA
22-0328
File

Shields Health Breach Reached 2 Million Patients After an Alert Was Closed as Not Reportable

Something noticed on day eleven. The judgement applied to it is what failed.

UnattributedHealthcareThird party
Sev 4TargetShields Health Care GroupActorUnattributedUSA
22-0120
File

The Identity Provider Was Reached Through Its Outsourced Support Desk

The alert fired on day one. The customers heard on day sixty-one, from the attackers.

Lapsus$Contractor remote accessTechnologyThird party
Sev 4TargetOktaActorLapsus$USA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging