Technology

Why 54% Of Organizations Say Third-Party Risk Is Their Biggest Security Challenge

When hackers stole $1.5 billion from the ByBit cryptocurrency exchange in February 2025, they didn’t break into ByBit’s systems directly.

Instead, they compromised one of ByBit’s suppliers and quietly altered digital wallet addresses. The exchange unknowingly transferred the funds straight to the attackers.

This massive heist perfectly illustrates why 54% of large organizations now consider supply chain challenges their biggest barrier to cyber resilience. 

The numbers tell a troubling story. Supply chain attacks have increased by 300% year-over-year, and nearly one-third of all data breaches in 2023 happened because of compromised third-party vendors.

The average organization now works with over 1,000 different suppliers, creating an enormous attack surface that traditional security measures simply cannot protect. 

The Multiplication Effect Makes Vendors Prime Targets

Cybercriminals have discovered something powerful about supply chains.

Why attack one company when you can compromise their vendor and gain access to dozens or hundreds of customers at once? This multiplication effect makes vendors incredibly attractive targets, especially smaller companies that may not have the same security resources as their enterprise clients. 

The Oracle Cloud breach in March 2025 demonstrates this perfectly. Attackers accessed Oracle’s Single Sign-On and LDAP systems, exposing 6 million records from more than 140,000 tenants.

One successful breach gave criminals access to sensitive data from thousands of organizations that trusted Oracle with their authentication systems. 

What makes these attacks so dangerous is the trust factor. When legitimate vendors have authorized access to your systems, their communications bypass many security controls that would normally flag suspicious activity.

Employees are trained to work with these vendors, making them less likely to question requests that appear to come from trusted partners. 

Recent Breaches Show The Growing Threat

The first few months of 2025 have already seen several major supply chain compromises. Beyond the ByBit and Oracle incidents, Iranian bank Sepah lost 42 million customer records through a third-party breach.

The Genea fertility clinic in Australia had 940GB of sensitive patient data stolen when ransomware attackers targeted their vendor systems. 

These attacks follow a predictable pattern. First, criminals compromise a third-party vendor, often through basic methods like phishing emails or unpatched software vulnerabilities.

Next, they move laterally within the vendor’s environment to find connections to customer systems.

Finally, they exploit the trust relationships between vendor and client to access valuable data or systems across multiple organizations. 

Why Traditional Security Falls Short

Most cybersecurity strategies still think in terms of protecting a defined perimeter around the organization. But supply chains create legitimate holes in that perimeter.

Vendors need access to do their jobs, and their communications are expected and trusted by employees. 

This trust creates unique vulnerabilities that standard security training often misses.

Employees learn to recognize suspicious emails from unknown senders, but they’re much less likely to question communications that appear to come from established business partners.

Attackers exploit this by impersonating vendors in their phishing campaigns, knowing that employees are more likely to click links or provide information when the request seems to come from a trusted source. 

The Human Element Requires Specialized Training

Addressing supply chain security requires more than just technical controls. Organizations need to train their employees to recognize when vendor relationships are being exploited by attackers.

This means going beyond generic awareness programs to include phishing simulation training that specifically addresses supply chain scenarios. 

Effective training should include realistic simulations of compromised vendor communications, teach employees how to verify vendor identity through secondary channels, and help them recognize the tactics attackers use to exploit business relationships.

When employees understand how supply chain attacks work, they become a critical line of defense against these sophisticated threats. 

Building Stronger Defenses

Organizations can take several steps to reduce their supply chain risk. Continuous monitoring of vendor security practices helps identify potential vulnerabilities before they’re exploited.

Zero-trust security architectures that don’t automatically trust vendor access can limit the damage when breaches occur.

Regular security assessments and clear contractual requirements ensure vendors maintain appropriate security standards. 

Network segmentation can limit how far attackers can move if they do compromise a vendor’s access. Multi-factor authentication for all vendor interactions adds another layer of protection.

Behavioral monitoring can detect when vendor accounts are being used in unusual ways that might indicate a compromise. 

The Stakes Keep Rising

With supply chain attacks increasing rapidly and affecting organizations across every industry, the time for action is now.

The 54% of organizations struggling with third-party risk management aren’t just dealing with a technical challenge. They’re facing a fundamental shift in how cyber threats operate. 

Supply chain security requires organizations to think beyond their own defenses and consider the security practices of every vendor they work with.

Those who adapt quickly to this new reality will be better positioned to protect their data, their customers, and their operations from the growing wave of supply chain attacks. 

Sweta Bose

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago