<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Third-Party Vendor Compromise on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/third-party-vendor-compromise/</link>
    <description>Recent content in Third-Party Vendor Compromise on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:45 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/third-party-vendor-compromise/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Allianz Life Insurance Company of North America Data Breach (July 2025)</title>
      <link>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</link>
      <pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</guid>
      <description>Executive Summary Incident summary On July 16, 2025, a threat actor used social engineering to access a third-party, cloud-based customer relationship management (CRM) system used by Allianz Life Insurance Company of North America. Allianz Life’s official account states that it became aware of suspicious activity on July 17 at 12:17 p.m. CDT and terminated access to accounts associated with that activity at 2:17 p.m. CDT. (agportal-s3bucket.s3.amazonaws.com ) The company reported no indication that the threat actor accessed its company network or systems outside the CRM; this does not establish that the CRM was deliberately isolated.</description>
    </item>
    <item>
      <title>Qantas Airways Customer Data Breach (June 2025)</title>
      <link>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</link>
      <pubDate>Sat, 28 Jun 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</guid>
      <description>Executive Summary On 30 June 2025, Qantas detected unusual activity on a third-party platform used by an overseas airline contact centre. The OAIC’s later account states that an agent had been socially engineered on 28 June and that the attacker used the agent’s legitimate CRM access to connect a third-party data-extraction application; Qantas froze and revoked the associated account on 30 June. (oaic.gov.au ) Qantas publicly disclosed the incident on 2 July and subsequently reported approximately 5.</description>
    </item>
    <item>
      <title>PowerSchool Student Information System Data Breach (December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</link>
      <pubDate>Thu, 19 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</guid>
      <description>Executive Summary On December 28, 2024, PowerSchool said it became aware that an unauthorized party had exfiltrated personal information from PowerSchool Student Information System (SIS) environments through the PowerSource customer-support portal. Later reporting and forensic summaries place unauthorized activity earlier: CrowdStrike found evidence beginning December 19, while customer guidance reported data first stolen on December 22. PowerSchool notified affected customers on January 7, 2025 and publicly posted an incident disclosure on January 13.</description>
    </item>
    <item>
      <title>U.S. Department of the Treasury BeyondTrust Breach December 2024</title>
      <link>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</link>
      <pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</guid>
      <description>Executive Summary Key facts:&#xA;Who: Treasury initially attributed the intrusion generically to &amp;ldquo;a China state-sponsored Advanced Persistent Threat (APT) actor&amp;rdquo; (wired.com ; bleepingcomputer.com ); a Wednesday Bloomberg report later attributed it to Silk Typhoon (formerly Hafnium); OFAC separately sanctioned contractor Yin Kecheng, a Shanghai-based, decade-active actor tied to China&amp;rsquo;s Ministry of State Security, on January 17, 2025, as &amp;ldquo;associated with the recent compromise&amp;rdquo; (bleepingcomputer.com ; techcrunch.com ; home.treasury.gov ). China&amp;rsquo;s embassy denied involvement (en.</description>
    </item>
    <item>
      <title>American Express Data Breach March 2024</title>
      <link>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</link>
      <pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</guid>
      <description>Executive Summary On March 4, 2024, American Express announced a data breach resulting from unauthorized access through a third-party merchant processor. This incident compromised customer information, including names, account numbers, and expiration dates, due to a point-of-sale attack affecting systems associated with American Express Travel Related Services Company. It highlights the vulnerabilities within third-party vendor systems in the financial sector. Source Severity of Impact The breach presented significant risks, potentially compromising critical cardholder information.</description>
    </item>
    <item>
      <title>Change Healthcare February 2024 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</link>
      <pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</guid>
      <description>Executive Summary The Change Healthcare data breach involved a ransomware attack in February 2024, attributed to the BlackCat group, also known as ALPHV. This cyber assault led to considerable disruptions within pharmacy operations and potentially exposed sensitive client data. source Severity of Impact The breach significantly impacted Change Healthcare&amp;rsquo;s extensive network, which comprises over 1.6 million healthcare professionals, 70,000 pharmacies, and 8,000 healthcare facilities. The breach&amp;rsquo;s financial impact is estimated at $872 million, highlighting the substantial economic consequences.</description>
    </item>
    <item>
      <title>Samsung Data Breach November 2023</title>
      <link>https://securityblueprints.io/data-breaches/samsung-data-breach-november-2023/</link>
      <pubDate>Mon, 13 Nov 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/samsung-data-breach-november-2023/</guid>
      <description>Executive Summary On November 13, 2023, Samsung Electronics detected a data breach originating from a vulnerability in a third-party application. This breach affected customers who made purchases through the Samsung UK online store between July 1, 2019, and June 30, 2020, exposing personal information, including names, phone numbers, postal addresses, and email addresses. Samsung notified affected customers on November 16, 2023.&#xA;Severity of Impact The breach&amp;rsquo;s significance lies in the exposure of sensitive personal information, even though financial data and passwords were not compromised.</description>
    </item>
    <item>
      <title>MGM Grand Data Breach - September 2023</title>
      <link>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</link>
      <pubDate>Fri, 08 Sep 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</guid>
      <description>Executive Summary In September 2023, MGM Resorts International experienced a major cyberattack attributed to the hacking group Scattered Spider, known for its association with the ALPHV/BlackCat ransomware group. The attack resulted in significant disruptions to operations at MGM&amp;rsquo;s Las Vegas venues, including the MGM Grand and Bellagio, with estimated financial losses ranging from $80 million to $100 million. This incorporates direct impacts on revenue and heightened cybersecurity expenses. The attackers exploited vulnerabilities in service desk operations through social engineering tactics like vishing, which allowed unauthorized system access.</description>
    </item>
    <item>
      <title>MOVEit Data Breach June 2023</title>
      <link>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</link>
      <pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</guid>
      <description>Executive Summary In June 2023, a significant data breach involving the MOVEit Transfer software began; within its first weeks it had affected over 200 organizations globally, a toll that continued climbing for more than a year afterward (Axios ). This breach was triggered by exploiting a zero-day vulnerability, CVE-2023-34362, within the MOVEit Transfer tool by Progress Software Corporation. The Clop ransomware group, using its Ransomware as a Service (RaaS) model, claimed responsibility for the data theft operations.</description>
    </item>
    <item>
      <title>Discord Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</link>
      <pubDate>Wed, 29 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</guid>
      <description>Executive Summary Incident Overview In March 2023, Discord faced a data breach due to security vulnerabilities at a third-party service provider. This led to the compromise of customer data. The breach was identified on March 29, 2023, publicly disclosed by May 12, 2023, and user notifications commenced on August 21, 2023 (BleepingComputer ).&#xA;Severity of Impact The breach exposed sensitive personal information of approximately 180 users, including names and state or driver&amp;rsquo;s license numbers, highlighting privacy concerns despite its limited scope relative to Discord&amp;rsquo;s extensive user base (HackRead ; Economic Times ).</description>
    </item>
    <item>
      <title>ChatGPT Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/chatgpt-data-breach/</link>
      <pubDate>Mon, 20 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/chatgpt-data-breach/</guid>
      <description>Executive Summary Overview of the Incident In March 2023, OpenAI&amp;rsquo;s ChatGPT platform experienced a data breach caused by a bug in the open-source library, Redis-py, used by the service. This issue resulted in the exposure of sensitive user data, including names, emails, payment addresses, and partial credit card details (last four digits and expiration dates). The breach was identified on March 20, 2023, during a service outage, revealing private information in error source .</description>
    </item>
    <item>
      <title>PharMerica Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</link>
      <pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, PharMerica, a prominent U.S. pharmacy services provider, encountered a notable data breach affecting approximately 5,815,591 individuals. This incident compromised sensitive patient information, impacting both PharMerica and its parent company, BrightSpring Health Services (source ).&#xA;Breach Timeline Intrusion Period: Unauthorized access was gained from March 12 to 13, 2023. Discovery Date: The breach was discovered on March 14, 2023. Public Disclosure: Notifications were issued to individuals on May 12, 2023.</description>
    </item>
    <item>
      <title>Google Fi Data Breach Linked to T-Mobile Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</guid>
      <description>Executive Summary Incident Overview: In February 2023, Google Fi suffered a data breach due to vulnerabilities originating from a prior T-Mobile security incident. This breach exposed Google Fi customers&amp;rsquo; phone numbers and related technical details, posing significant risks such as SIM swap attacks and unauthorized account activities (source ).&#xA;Key Dates: The association with T-Mobile&amp;rsquo;s broader data breach was identified on January 19, 2023. Affected individuals received notifications in early February 2023 (source ).</description>
    </item>
    <item>
      <title>NCB Management Services Data Breach February 2023</title>
      <link>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</guid>
      <description>Executive Summary In February 2023, NCB Management Services experienced a significant data breach due to an unauthorized system compromise, exposing sensitive personal and financial information. The breach was detected on February 4, 2023, affecting clients associated with major financial institutions including Capital One, Bank of America, and TD Bank.&#xA;Severity of the Impact The breach compromised data for over 1 million individuals, with specific numbers varying by institution: approximately 16,779 Capital One customers and nearly 495,000 Bank of America customers were directly impacted.</description>
    </item>
    <item>
      <title>MailChimp January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</link>
      <pubDate>Wed, 11 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</guid>
      <description>Executive Summary Incident Overview In January 2023, MailChimp was subjected to a data breach due to a social engineering attack that affected its internal customer support tool. This breach, the second in a span of six months, indicates potential weaknesses in MailChimp&amp;rsquo;s defensive measures.&#xA;Key Dates and Discovery Details The breach was discovered on January 11, 2023, during a routine security review and was publicly disclosed on January 19, 2023. This prompt notification ensured that stakeholders were adequately informed.</description>
    </item>
    <item>
      <title>SolarWinds Supply Chain Attack</title>
      <link>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</link>
      <pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</guid>
      <description>Executive Summary The SolarWinds Supply Chain Attack represents a pivotal cyber incident with substantial global repercussions. This sophisticated breach resulted in the compromise of SolarWinds&amp;rsquo; software development infrastructure, spreading malicious updates within their Orion software. The attack, initiated in September 2019, culminated with the distribution of malicious updates starting in March 2020, which were installed by over 18,000 SolarWinds customers. This infiltration allowed attackers unauthorized access for data theft and espionage, as publicly disclosed in December 2020.</description>
    </item>
    <item>
      <title>Copay Cryptocurrency Wallet Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</link>
      <pubDate>Tue, 27 Nov 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</guid>
      <description>Executive Summary In November 2018, the Copay cryptocurrency wallet, developed by BitPay, experienced a data breach due to a malicious update to the event-stream Node.js library, specifically within its flatmap-stream dependency. Unauthorized access to users&amp;rsquo; private keys and cryptocurrency funds was achieved, significantly impacting wallets containing over 100 Bitcoins or 1000 Bitcoin Cash source .&#xA;Key Dates August 5, 2018: Initial release of the flatmap-stream package. September 9, 2018: Integration of flatmap-stream into event-stream.</description>
    </item>
    <item>
      <title>NotPetya Ransomware Attack</title>
      <link>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</link>
      <pubDate>Tue, 27 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</guid>
      <description>Executive Summary The NotPetya ransomware attack in June 2017 is considered one of the most destructive cyber incidents on record. Originating through a compromised update of MeDoc, a Ukrainian accounting software, the malware propagated swiftly, impacting organizations across more than 65 countries within hours of being detected on June 27, 2017. The event highlighted significant vulnerabilities in software supply chains.&#xA;Severity of the Impact NotPetya inflicted damages exceeding $10 billion globally, with significant disruptions in healthcare, logistics, and government sectors.</description>
    </item>
    <item>
      <title>Deep Root Analytics Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</link>
      <pubDate>Mon, 12 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</guid>
      <description>Executive Summary In 2017, a data breach at Deep Root Analytics exposed the sensitive information of approximately 198 million U.S. voters. This information, linked to the Republican National Committee (RNC), was leaked due to a misconfigured Amazon Web Services (AWS) S3 bucket, which lacked adequate security settings. The breach included personal information such as names, addresses, birth dates, phone numbers, political affiliations, and predictive modeling data on ethnicities and religious orientations.</description>
    </item>
    <item>
      <title>Office of Personnel Management Data Breach 2015</title>
      <link>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</link>
      <pubDate>Wed, 01 Apr 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</guid>
      <description>Executive Summary In 2015, the U.S. Office of Personnel Management (OPM) faced a significant data breach resulting in the exposure of sensitive information of approximately 21.5 million individuals. This incident, one of the largest in U.S. government history, involved an initial breach affecting 4.2 million personnel records and a subsequent larger breach involving detailed background investigation data. This report details the technical and organizational failures that led to the breach and assesses its impact.</description>
    </item>
    <item>
      <title>Home Depot Data Breach April 2014</title>
      <link>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</link>
      <pubDate>Tue, 01 Apr 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</guid>
      <description>Executive Summary In April 2014, Home Depot faced a significant data breach resulting in the theft of over 56 million payment card records. Custom-built malware targeted Home Depot&amp;rsquo;s point-of-sale (POS) systems, affecting customers across the United States and Canada. The breach was detected in September 2014.&#xA;Severity of Impact The breach is among the largest recorded in retail history, with anticipated financial consequences projected to potentially reach $179 million, encompassing immediate response and legal costs.</description>
    </item>
    <item>
      <title>Target Data Breach 2013</title>
      <link>https://securityblueprints.io/data-breaches/target-data-breach-2013/</link>
      <pubDate>Wed, 18 Dec 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/target-data-breach-2013/</guid>
      <description>Executive Summary In December 2013, Target Corporation fell victim to a major data breach, impacting its operational security and customer trust by exposing approximately 110 million customer records, including financial and personal information. The breach became public after security researcher Brian Krebs disclosed it, revealing that unauthorized access was gained via compromised credentials from a third-party vendor, Fazio Mechanical Services (1) (2) .&#xA;Severity of Impact The breach led to the disclosure of 40 million credit and debit card numbers and 70 million records containing personal information, marking it as one of the significant incidents in retail data breaches.</description>
    </item>
    <item>
      <title>Court Ventures (Experian) Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/court-ventures-experian-data-breach/</link>
      <pubDate>Tue, 01 Oct 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/court-ventures-experian-data-breach/</guid>
      <description>Executive Summary In October 2013, a significant data breach involving Court Ventures was publicly reported. This breach followed Experian&amp;rsquo;s acquisition of Court Ventures in March 2012 and involved unauthorized access to a database containing sensitive information of approximately 200 million individuals. The breach was perpetuated by Hieu Minh Ngo, a Vietnamese national, exploiting the database via a business relationship between Court Ventures and US Info Search. Compromised data included Social Security numbers and credit card details (source ).</description>
    </item>
    <item>
      <title>California Department of Child Support Services Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</link>
      <pubDate>Mon, 12 Mar 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</guid>
      <description>Executive Summary Breach Name: California Department of Child Support Services Breach Date: 2012 Discovery Date: March 12, 2012 Disclosure Date: March 29, 2012 Incident Overview In 2012, the California Department of Child Support Services (DCSS) suffered a data breach due to the loss of magnetic tape cartridges, which occurred during a disaster recovery exercise managed by IBM and Iron Mountain Inc. Between Boulder, Colorado, and Sacramento, California, four of fifteen tapes went missing, containing the sensitive information of approximately 800,000 individuals.</description>
    </item>
  </channel>
</rss>
