• Solutions
  • Partners
  • Company
  • Resources
Solutions
IT Asset Management - Optima
Facilities Management - JLL Serve
Partners
TD SYNNEX
Jones Lang LaSalle
AWS
Company
About Us
Careers
Resources
Blogs
Case Studies
Connect with us on

Solutions

  • IT Asset Management – Optima
  • Facilities Management – JLL Serve

Partners

  • TD SYNNEX
  • Jones Lang LaSalle
  • AWS

Company

  • About Us
  • Careers

Resources

  • Blogs
  • Case Studies
Connect with us on
© 2026 All rights reserved.Terms & ConditionsPrivacy PolicySecurity Practices
blogs background
Blogs|Internet Of Things

Top 7 Third-Party Data Breaches to Focus On

Posted on September 8, 2025|05 Minutes Read
Share
Third-party data breach risks symbolized by a glowing shield on a digital interface.

Third-party data breaches have become one of the most significant cybersecurity challenges today. When organizations share sensitive data with external vendors, they extend their own attack surface, and the consequences of a security breach can be devastating. From financial information to private healthcare records, these supply chain cyber-attacks have exposed billions of records and cost companies millions. The biggest incidents over the last decade show just how vulnerable modern businesses are to attacks that originate outside their direct control.

Understanding the anatomy of these events is more than just a history lesson. It is about recognizing the evolving threat landscape, which now includes IoT security threats, facilities management cybersecurity gaps, and smart building vulnerabilities. To prepare for the inevitable, organizations must accept that third-party relationships, while essential for growth, introduce major cybersecurity risks.

The breaches we will explore are among the largest ever, demonstrating how a single compromised vendor can trigger a domino effect. A third-party breach can impact hundreds of organizations and millions of people all at once.

Why are third-party breaches surging?

As businesses increasingly rely on outside vendors and partners, the risk of a third-party breach grows. Recent data highlights just how much these external relationships amplify cybersecurity exposure and why data leak prevention is more critical than ever.

  • Companies now give weekly network access to an average of 89 vendors, and most expect their dependency on third parties to continue growing.
  • A staggering 98% of organizations worldwide has integrations with at least one third-party vendor that has been breached in the last two years, according to a report from SecurityScorecard and the Cyentia Institute.
  • Alarmingly, nearly three-quarters of organizations admit their vendor selection process misses key risks, with many prioritizing cost over security.

Ignoring vendor-related risks can lead to catastrophic consequences, including severe financial loss and lasting reputational damage for organizations in every industry.

“Statistics Spotlight: 35.5% of all data breaches in 2024 originated from third-party compromises.”

As reliance on external vendors grows, so do the risks:

  • Organizations now grant access to an average of 89 vendors every week.
  • 71% anticipate using even more third parties within the next two years, increasing exposure.
  • The number of third party-related breaches has increased by 22% since 2015.
  • 74% say their vendor selection process overlooks critical risks, and 64% admit outsourcing decisions often prioritize cost over security.

Top 7 Third-Party Data Breaches of All Time

1. SolarWinds Supply Chain Attack (2020)

The SolarWinds security breach is considered one of the most sophisticated supply chain cyber-attacks in history. Russian state-sponsored hackers compromised the SolarWinds Orion software platform, impacting approximately 18,000 customers, including major government agencies and Fortune 500 companies.

Impact:

  • Compromised the networks of over 18,000 organizations.
  • Affected critical U.S. government departments, including the Treasury, Commerce, and Homeland Security.
  • The estimated economic impact exceeded $100 billion globally.
  • It took months to understand the full scope of the data breach.

This incident showed how a single third-party breach can ripple through entire supply chains, marking it as a catastrophic failure in vendor risk management.

2. Kaseya VSA Ransomware Attack (2021)

Kaseya, a managed service provider (MSP) platform, was the victim of a ransomware attack that used its VSA software to deploy malware to downstream customers. This supply chain attack affected between 800 to 1,500 companies globally.

Key details:

  • Attackers demanded a $70 million ransom.
  • The attack primarily affected small to medium-sized businesses.
  • It occurred over the July 4th holiday weekend in the U.S.
  • Demonstrated the profound vulnerability of MSP ecosystems.

Impact:

  • Forced hundreds of businesses to halt operations.
  • Highlighted the interconnected nature of modern IT infrastructure and third-party cybersecurity risks.
  • Led to increased scrutiny of MSP vendor risk management.

3. Accellion File Transfer Breach (2021)

The Accellion FTA breach impacted over 100 organizations worldwide, including major corporations, government agencies, and universities. Hackers exploited vulnerabilities in the company's outdated File Transfer Appliance (FTA) software to exfiltrate sensitive data, making it a significant third-party breach involving legacy technology.

Notable victims included:

  • Shell Oil Company
  • University of Colorado
  • Australian Securities and Investments Commission (ASIC)
  • Multiple law firms and healthcare organizations

Impact:

  • Exposed the personal data of millions of individuals.
  • Resulted in multiple class-action lawsuits.
  • Caused some organizations to face regulatory fines.
  • Emphasized the risks of using legacy third-party systems, a key concern for data leak prevention.

4. MOVEit Transfer Breach (2023)

Progress Software's MOVEit Transfer platform was targeted by the Clop ransomware group, affecting over 2,000 organizations and approximately 62 million individuals. This event stands as one of the largest third-party data breaches ever recorded.

Major victims:

  • BBC
  • British Airways
  • Ernst & Young
  • Johns Hopkins University
  • Multiple U.S. federal agencies

Impact:

  • One of the biggest third-party breaches in history, showing the devastating scope of a single data breach.
  • Exposed sensitive government and corporate data.
  • Showcased the vulnerability of file transfer services, reinforcing the need for robust vendor risk management.

5. Okta Third-Party Breach (2022)

Identity management giant Okta revealed that hackers had accessed a third-party customer support system, creating a security breach that potentially compromised data from hundreds of its customers. As a leader in authentication, this incident highlighted the persistent risk posed by third-party vendors to even the most secure systems.

Key facts:

  • Affected approximately 2.5% of Okta's customer base.
  • Involved a compromise of Sykes, Okta's customer support vendor.
  • Attackers had access for several months before being detected.
  • There was no evidence of a direct compromise of Okta's core systems.

Impact:

  • Raised critical questions about vendor risk management and data leak prevention.
  • This led to heightened scrutiny of identity provider security protocols.
  • Highlighted the risks associated with third-party customer support vendors.

 Monitor screen showing hacked alert on third-party data breach

6. Microsoft Exchange Server Breach (2021)

While a software vulnerability rather than a classic third-party breach, the Microsoft Exchange Server compromise affected over 250,000 servers worldwide. It demonstrated how widely used third-party software can become a massive attack vector.

Attack characteristics:

  • Exploited four zero-day vulnerabilities.
  • Attributed to the state-sponsored group HAFNIUM.
  • Allowed for remote code execution and data theft.
  • Affected organizations across all sectors.

Impact:

  • Compromised email systems for hundreds of thousands of organizations.
  • Led to widespread data theft, cementing its place among the biggest security incidents.
  • Prompted global emergency patching efforts and a renewed focus on vendor risk management.

7. TeamViewer Breach (2016)

TeamViewer, a popular remote access tool, suffered a major security breach that may have affected millions of users. The company's delayed and unclear response became a cautionary tale for handling a data breach.

Breach details:

  • Affected millions of TeamViewer accounts.
  • Users reported unauthorized access to their systems.
  • Attackers potentially accessed banking and financial information.
  • The company was criticized for its initial communication.

Impact:

  • Damaged trust in remote access software.
  • Led to the implementation of enhanced security measures for remote access tools.
  • Highlighted the significant risks posed by third-party remote access software.

Conclusion

Third-party vendors make modern facilities smarter and more efficient, but they also expand the attack surface. The top breaches of the past decade prove that organizations cannot afford to overlook vendor security. A robust data leak prevention strategy like unidirectional gateways for vendors must account for these external risks.

For facilities and IT leaders, this means integrating third-party risk management into core operational strategy. By tightening access controls, demanding higher security standards from vendors, and maintaining constant vigilance, businesses can embrace innovation without becoming the next major data breach headline. Sclera does exactly that with its unidirectional approach to network security, which gives the system the visibility and connectivity it needs without exposing it to external threats.

Previous
Previous BlogPrevious
Share it on
Next BlogNext
Next

Related Blogs

Corporate employees discussing the implication of the FM system to their facility

Is Changing to an FM System the Key to Corporate Success?

August 31, 2023Read more
AI in Property Management: 6 Key Benefits for Facilities

AI in Property Management: 6 Key Benefits for Facilities

July 28, 2025Read more
5 Costly Manual Asset Tracking Mistakes Companies Make

5 Costly Manual Asset Tracking Mistakes Companies Make

August 18, 2025Read more
What is a Digital Asset Passport & Why Organizations Need It

What is a Digital Asset Passport & Why Organizations Need It

August 28, 2025Read more
The Future of IT-OT Convergence—Better When Together!

The Future of IT-OT Convergence—Better When Together!

November 11, 2025Read more
The Adoption of Remote Asset Monitoring in Hospitality

The Adoption of Remote Asset Monitoring in Hospitality

February 9, 2024Read more
AI in Facilities Management: A Breakthrough in Future Buildings

AI in Facilities Management: A Breakthrough in Future Buildings

September 1, 2025Read more
From Cloud to Edge Computing: Predictive Power, Zero Delay

From Cloud to Edge Computing: Predictive Power, Zero Delay

November 13, 2025Read more
A Simple Guide to Property Management and its Types

A Simple Guide to Property Management and its Types

February 7, 2024Read more
Traditional asset onboarding v/s AI automated asset onboarding

Why Traditional Asset Onboarding Fails - What Comes Next?

September 24, 2025Read more