tag: Third-Party-Risk · 14 items
- Engineer — Learn: Breach was via unauthorized access to third-party applications, not a patchable CVE; reinforces the need to audit and restrict third-party SaaS access, but no concrete engineering action is available from this disclosure alone.
- SOC/IR — Learn: ShinyHunters attribution is a useful actor profile update, but no IOCs, TTPs, or detection-relevant technical detail are published yet; monitor for follow-on disclosures that include actionable indicators.
- Leader — Act: McKesson is a major healthcare and pharma supply chain vendor — if your organization has a relationship with them, confirm exposure scope this week and request their incident attestation; 284 million claimed patient records puts this in HIPAA notification and board-visibility territory.
- Engineer — Skip
- SOC/IR — Learn: No IOCs or TTPs published; monitor for follow-on phishing lures targeting Hasbro employees that could appear in broader campaigns.
- Leader — Plan: Review whether your organization has vendor or partner relationships with Hasbro that involve shared employee or financial data; add to third-party breach tracker and revisit data-sharing agreements.
- Engineer — Skip
- SOC/IR — Skip
- Leader — Learn: A UK airport operator breach involving Wi-Fi registration data is a useful prompt to review what data third-party venue services collect on behalf of employees, but no immediate action is warranted for most non-UK enterprises given the regional scope and absence of published IOCs or attack detail.
- Engineer — Skip
- SOC/IR — Skip
- Leader — Learn: A third-party software flaw exposed HR-category data (employee and applicant records) at a major hospital with no patient-record impact — a useful reference case for vendor risk assessments covering HR/recruiting platforms, particularly in healthcare.
- Engineer — Skip
- SOC/IR — Learn: The attack vector — exploiting a third-party service provider to reach bank customer accounts — is a useful case study in lateral trust abuse, but no IOCs, TTPs, or detection artifacts are available to act on.
- Leader — Learn: A €30M fraud executed through a service provider flaw reinforces third-party risk as a board-level concern; useful framing for vendor risk discussions, but no specific vendor exposure to assess here.
- Engineer — Skip
- SOC/IR — Learn: ShinyHunters claimed this breach in July; no IOCs or TTPs published yet, so no detection action is possible — file for actor-tracking context.
- Leader — Act: If RingCentral is in your vendor stack, confirm scope with your account rep, request their incident report, and assess whether affected data triggers customer or regulatory notification obligations.
- Engineer — Skip
- SOC/IR — Learn: No IOCs, TTPs, or detection surface published; monitor for follow-up reporting that may yield hunt queries or indicators.
- Leader — Act: LexisNexis is a common enterprise vendor for due diligence and data enrichment — confirm this week whether your organization uses Diligence, Metabase API, or Newsdesk, and formally request a vendor incident report and data-exposure assessment.
- Engineer — Skip
- SOC/IR — Learn: No IOCs or TTPs published; breach occurred in October 2025 with delayed disclosure — useful context on healthcare software supply-chain exposure but no detection action available.
- Leader — Act: If your organization uses Unlimited Technology Systems or any of their healthcare software products, confirm exposure this week and request an incident report; the 3.8M-record scale and healthcare data sensitivity may trigger notification obligations or customer questions.
- Engineer — Skip
- SOC/IR — Learn: No IOCs or TTPs published; this breach offers no immediate detection surface, but it reinforces the pattern of healthcare billing vendors as high-value targets worth monitoring for sector-specific threat campaigns.
- Leader — Act: If your organization uses MCBS or similar third-party medical billing vendors, confirm whether you are among the 1.26M affected and request an incident attestation letter; this breach carries HIPAA notification obligations and may prompt patient or board inquiries.
- Engineer — Skip
- SOC/IR — Learn: No IOCs or TTPs disclosed; breach at a logistics vendor with no actionable detection surface for enterprise defenders at this time.
- Leader — Act: If OnTrac is in your vendor portfolio or used by employees for business shipments, confirm exposure scope and request an incident report from OnTrac this week before customer or leadership questions surface.
- Engineer — Learn: The entry point was a data exchange platform shared with a supplier, reinforcing that third-party integrations need isolation and least-privilege access. No specific CVE or software named, so no patch action available.
- SOC/IR — Learn: Confirms Everest ransomware gang is active and targeting supplier-connected platforms, but no IOCs or TTPs are published here to hunt on. File for actor-tracking context.
- Leader — Learn: Illustrates how a shared supplier portal becomes a ransomware entry point — a useful data point for third-party risk reviews and board-level ransomware briefings. No direct vendor relationship requiring immediate action for most organizations.
- Engineer — Skip
- SOC/IR — Learn: The breach originated through a third-party support ticketing system, illustrating a lateral entry path worth reviewing in your own vendor-managed tool integrations — no IOCs or TTPs published to act on yet.
- Leader — Act: If EY is a vendor or auditor your organization uses, confirm whether your data was in scope and request EY’s incident report; brief leadership now, before this becomes a customer or auditor question.
- Engineer — Skip
- SOC/IR — Skip
- Leader — Learn: A genetic-data breach resulting in an $18M multistate AG settlement illustrates the regulatory and financial exposure from third-party vendors handling sensitive biometric/health data — useful context for vendor risk assessments and board-level privacy risk discussions.
- Engineer — Skip
- SOC/IR — Skip
- Leader — Learn: A named retailer’s breach traced to an unnamed service provider is a clean case study for third-party risk reviews; no specific vendor is identified in reporting, so no immediate exposure check is actionable, but it reinforces the value of contractual breach-notification SLAs with SaaS and logistics vendors.