Third-Party Compromise
Third-party compromise happens when the attacker does not go at an organization directly but at a supplier, a partner, a service provider or an external associate who already holds some form of trust and authorized access. Instead of forcing the front door, the attacker looks for a side entrance somebody else has already opened.
Term
description · examples · notesThird-party compromise happens when the attacker does not go at an organization directly but at a supplier, a partner, a service provider or an external associate who already holds some form of trust and authorized access. Instead of forcing the front door, the attacker looks for a side entrance somebody else has already opened.
Description
Third parties often hold VPN access, support accounts, integrations, API keys, access to data, or the job of maintaining systems. If they are less well protected than the organization they reach into, they become the easier target and the bridge to a more serious one.
This risk is hard because it does not end at the company's own infrastructure. An organization can have solid internal controls and still depend on somebody else's password, somebody else's laptop, somebody else's EDR, somebody else's segmentation and somebody else's understanding of an incident.
Examples
- An attacker compromises a smaller IT service provider and uses its account to reach a large client's network.
- An HR agency serving a number of smaller companies is compromised, and the data of many clients leaks with it.
- A software vendor's technical support account is used to get into customers' internal systems.
Notes
- Trust in a supplier must not mean unlimited access. A partner is given what the work requires, not what is easiest to configure.
- A third party is part of your risk even when it is not part of your organization.
Mentioned in the news
- 13. AVG 2026. Za samo 40 minuta zatrovani LiteLLM izložio tajne 2.500 organizacija →
- 18. JUL 2026. Kroz platformu za podršku pokrali podatke klijenata EY-a →
- 22. JUN 2026. U Teksasu sve veliko, pa i curenja podataka →
- 28. APR 2026. Medtronic potvrdio upad nakon pretnje grupe ShinyHunters →
- 24. APR 2026. Vercel potvrdio proboj povezan sa Context.ai OAuth aplikacijom →
- 20. APR 2026. Vercel potvrdio proboj posle kompromitacije spoljnog AI dobavljača →
- 20. APR 2026. Seiko USA kompromitovan kroz izmenu sajta i tvrdnje o krađi Shopify podataka →
- 15. APR 2026. Rockstar Games potvrdio curenje podataka posle incidenta kod treće strane →
- 4. APR 2026. Hims & Hers upozorava na krađu podataka iz Zendesk support tiketa →
- 4. APR 2026. Upad u cloud Evropske komisije izložio podatke desetina EU entiteta →
- 28. MAR 2026. HackerOne prijavio krađu podataka zaposlenih posle upada u Navia sistem →
- 24. MAR 2026. Crunchyroll istražuje navodnu krađu podataka 6,8 miliona korisnika →
- 11. MAR 2026. Michelin potvrdio kompromitaciju podataka u napadu na Oracle E-Business Suite →
- 24. FEB 2026. Conduent pogođen incidentom: ukradeno 8 TB podataka →
- 20. FEB 2026. PayPal prijavio curenje podataka koje je izložilo lične informacije korisnika →
- 6. FEB 2026. Evropska komisija istražuje sajber napad na interne sisteme →
- 25. JUN 2026. Klue kompromitovan: OAuth tokeni otvorili Salesforce podatke klijenata →
- 27. FEB 2026. Marquis tuži SonicWall zbog kompromitovanog backup sistema i ransomver napada →
Techniques
carried out with 3Techniques used to carry it out. Select one to open its page.
Defenses
countered by 6How it is defended against. Select one to open its page.