The Rising Threat of Third-Party Cyber Breaches in 2025

Listen to this Post

A Growing Concern in Cybersecurity

The landscape of cyber threats is evolving, with third-party vulnerabilities emerging as a critical attack vector. A recent 2025 Global Third-Party Breach Report by SecurityScorecard reveals a significant surge in cyber breaches linked to third-party access, underscoring the need for robust cybersecurity strategies.

According to the report, 35.5% of all cyber breaches in 2024 were caused by third-party vulnerabilities—marking a 6.5% increase from the previous year. Ransomware attacks fueled by third-party breaches also rose, accounting for 41.4% of all ransomware incidents, with the Clop ransomware group leading the exploitation of third-party access vectors.

Surprisingly, only 46.75% of third-party breaches in 2024 stemmed from technology products and services, a sharp decline from 75% in 2023. This shift suggests that cybercriminals are diversifying their attack surfaces beyond tech-focused supply chains.

Industries and Regions Most Affected

Certain industries faced higher exposure to third-party breaches:

  • Retail & Hospitality experienced the highest breach rate at 52.4%

– Technology followed with 47.3%

– Energy & Utilities suffered 46.7%

Despite not having the highest percentage, healthcare recorded the most third-party breaches overall (78 incidents), though these accounted for only 32.2% of total breaches in the sector.

Geographically, Singapore led the world in third-party breach rates at 71.4%, followed by the Netherlands (70.4%) and Japan (60%). The United States, however, saw a comparatively lower rate of 30.9%, below the global average.

Mitigation Strategies for Third-Party Risks

To counteract these threats, SecurityScorecard recommends several best practices:

  • Align risk management strategies with organizational risk profiles
  • Address fourth-party risk by enforcing third-party security policies across vendor networks

– Demand secure by design technology from suppliers

  • Fortify high-risk infrastructure, such as cloud platforms, VPNs, and industry-specific services, with frequent patching, multifactor authentication (MFA), and continuous monitoring
  • Break the ransomware cycle by refusing ransom payments to disrupt attacker incentives

Ryan Sherstobitoff, SVP of SecurityScorecard’s STRIKE Threat Research and Intelligence, emphasized that companies need to shift from periodic vendor assessments to real-time monitoring to prevent supply chain cyber risks from escalating.

What Undercode Say:

Analyzing the Growing Third-Party Breach Threat

The 2025 Global Third-Party Breach Report highlights a concerning trend in cybersecurity: organizations remain highly vulnerable to breaches originating from external vendors and suppliers. The rising percentage of third-party-related cyber incidents suggests that attackers recognize the efficiency and scalability of targeting supply chains.

Why Third-Party Breaches Are Growing

  • Expanded Digital Ecosystems: Businesses rely on an extensive network of vendors, cloud providers, and software suppliers, increasing the number of access points attackers can exploit.
  • Interconnected Supply Chains: A security flaw in a single supplier can ripple through multiple organizations, amplifying the impact of an attack.
  • Persistent Ransomware Evolution: Groups like Clop have demonstrated the ability to efficiently exploit third-party vulnerabilities, refining their tactics to maximize damage and ransom payouts.
  • Regulatory Blind Spots: Many organizations fail to adequately assess the cybersecurity posture of third-party vendors, leaving gaps in compliance and security protocols.

The Changing Face of Third-Party Risk

One of the most intriguing findings in the report is the drop in tech industry breaches from 75% to 46.75%. This suggests cybercriminals are broadening their target range, moving beyond traditional IT service providers and into sectors like retail, healthcare, and utilities. Attackers understand that non-tech industries often lack the same cybersecurity rigor, making them easier targets.

Which Industries Should Be Most Concerned?

  • Retail & Hospitality: Holding massive customer databases, these industries are gold mines for cybercriminals seeking financial and personal data.
  • Healthcare: A prime target due to the sensitive nature of medical records and the high value of stolen patient data on the black market.
  • Energy & Utilities: Attacks on these industries can lead to national security risks, making them attractive targets for state-sponsored cyber threats.

How Businesses Can Strengthen Their Defenses

The solution isn’t just better vendor contracts—it’s about proactive cyber hygiene, real-time monitoring, and zero-trust frameworks:

  • Continuous Vendor Risk Monitoring: Traditional, annual security assessments are outdated—businesses need real-time tracking of third-party risks.
  • Stronger Authentication Measures: Mandating MFA and zero-trust principles across third-party access points can significantly reduce breach risks.
  • Mandatory Cybersecurity Audits: Organizations should require regular security compliance checks from all vendors to ensure risk levels stay within acceptable thresholds.
  • Cybersecurity Awareness Training: Employees and third-party partners should undergo regular training to recognize phishing attempts and social engineering attacks.

Final Thoughts

The rise in third-party breaches is not just an IT issue—it’s a business risk that affects every industry. Companies must rethink how they assess, manage, and monitor third-party security risks, ensuring that vulnerabilities in their supply chain do not become their weakest link.

Fact Checker Results

  1. The report confirms a clear increase in third-party breaches (35.5% in 2024 vs. 29% in 2023), reinforcing concerns about supply chain security.
  2. The tech industry is no longer the sole target—while still impacted, the shift toward retail, healthcare, and utilities suggests cybercriminals are expanding their focus.
  3. Singapore, the Netherlands, and Japan report alarmingly high breach rates, indicating that global businesses must reassess vendor security standards across borders.

References:

Reported By: https://www.infosecurity-magazine.com/news/securityscorecard-surge-third/
Extra Source Hub:
https://www.medium.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image