Tag / 24 entries / page 1 of 3 / feed available

Third-Party Vendor Compromise

24 of the 76 analyses in Data Breaches carry this tag. All 24 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

075

Allianz Life Insurance Company of North America Data Breach (July 2025)

A threat actor used social engineering to access a third-party cloud-based CRM used by Allianz Life Insurance Company of North America and exfiltrated sensitive personal information. The incident affected approximately 1.5 million customers, financial professionals, and select employees, with exposed data potentially including names, addresses, dates of birth, Social Security numbers, email addresses, and phone numbers. The responsible threat actor or group was not confirmed, although the breach was linked in reporting to a broader campaign associated with ShinyHunters, Scattered Spider, and UNC6040.

074

Qantas Airways Customer Data Breach (June 2025)

An attacker socially engineered an overseas contact-centre agent into authorizing an attacker-controlled data-extraction application against the agent’s legitimate CRM access. Approximately 5.7 million unique Qantas customer records were affected, including names, email addresses, Frequent Flyer information and, for subsets, addresses, dates of birth, phone numbers, gender and meal preferences. Qantas said passwords, PINs, payment, financial, passport and Frequent Flyer login data were not accessed. The initial intruder attribution was not confirmed; later reporting identified Scattered Lapsus$ Hunters as the collective that reportedly published some records after extortion activity.

072

PowerSchool Student Information System Data Breach (December 2024)

Prevented by: HSF

An unauthorized party used a compromised credential with password-only access to the PowerSource customer-support portal and exported student and teacher data from PowerSchool SIS environments. Exposed information varied by customer and could include names, contact details, dates of birth, addresses, SSNs or SINs, medical information, grades, parent or guardian data, and passwords. DOJ-related reporting placed the affected population at approximately 62 million individuals, although other reported figures were not reconciled. Matthew D. Lane later pleaded guilty to conduct related to the breach, while subsequent extortion attempts indicated that stolen data may have remained available.

071

U.S. Department of the Treasury BeyondTrust Breach December 2024

A China state-sponsored APT (later attributed to Silk Typhoon) compromised a stolen BeyondTrust Remote Support SaaS API key, using it to reset local application account passwords and remotely access U.S. Treasury Department workstations and unclassified documents. The intrusion, detected by BeyondTrust on December 2, 2024 and disclosed to Congress on December 30, 2024 as a major cybersecurity incident, reached the Office of Foreign Assets Control, the Committee on Foreign Investment in the United States, the Office of Financial Research, and reportedly the Office of the Treasury Secretary. The attack exploited a critical unauthenticated command/argument-injection flaw (CVE-2024-12356, CVSS 9.8) and a second lower-severity flaw (CVE-2024-12686); OFAC later sanctioned contractor Yin Kecheng for his role in the compromise.

068

American Express Data Breach March 2024

Prevented by: EGR

In March 2024, American Express disclosed a data breach caused by unauthorized access to a third-party merchant processor, exposing customer names, account numbers, and expiration dates. The breach resulted from a point-of-sale attack, impacting vendor management systems, without directly compromising American Express’s internal databases. While the specific threat actors remain unidentified, the breach underscores potential risks to customer data integrity.

065

Change Healthcare February 2024 Data Breach

Prevented by: HSF, PEC, EGR

The Change Healthcare breach in February 2024 involved a ransomware attack by the BlackCat group, significantly disrupting pharmacy operations. Approximately 6TB of sensitive data, including health records, was potentially compromised. The attack exploited vulnerabilities in Citrix remote-access software, highlighting security weaknesses in multi-factor authentication.

061

Samsung Data Breach November 2023

A vulnerability in a third-party application used by Samsung led to a data breach affecting UK customers who made purchases via the Samsung UK online store. The breach exposed personal information including names, phone numbers, postal addresses, and emails. The unauthorized access was the result of exploiting the vulnerability, with the specifics around the threat actors and exact details remaining undisclosed.

058

MGM Grand Data Breach - September 2023

Prevented by: HSF, PEC · Contained by: EGR

In September 2023, MGM Resorts International experienced a major cyberattack orchestrated by the Scattered Spider group, leading to significant operational disruptions and an estimated $80 million in financial losses. The attackers exploited social engineering methods, particularly vishing, to breach MGM’s systems and compromise personal data including names, driver’s license numbers, and Social Security numbers. This attack underscores vulnerabilities in service desk operations and highlights the use of sophisticated ransomware tactics.

056

MOVEit Data Breach June 2023

Contained by: PEC

The June 2023 MOVEit data breach began with the exploitation of a zero-day SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer software; over 200 organizations were confirmed affected within the first weeks, a toll that climbed to more than 2,700 organizations and over 95 million individuals as disclosures continued into 2024. The Clop ransomware group was responsible, utilizing web shell deployment and data exfiltration methods to access and steal personal and sensitive information, highlighting substantial risks in application security and third-party systems.

052

Discord Data Breach March 2023

Prevented by: HSF

In March 2023, a data breach occurred at Discord due to security vulnerabilities at a third-party service provider, compromising sensitive personal information of approximately 180 users including names and driver’s license numbers. The breach was facilitated through unauthorized access, likely achieved via compromised credentials due to phishing or social engineering. No specific threat actors were identified in the report.

RSS feed for this tag →

Now playing Bandcamp