<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Third-Party-Risk on CuraSec</title><link>https://curasec.metacog.co.kr/tags/third-party-risk/</link><description>Recent content in Third-Party-Risk on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 29 Aug 2026 15:36:18 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/third-party-risk/index.xml" rel="self" type="application/rss+xml"/><item><title>McKesson discloses breach; ShinyHunters claims 284M patient records</title><link>https://curasec.metacog.co.kr/insights/2026-08-29-mckesson-discloses-breach-after-shinyhunters-claims-patient/</link><pubDate>Sat, 29 Aug 2026 15:36:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-29-mckesson-discloses-breach-after-shinyhunters-claims-patient/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Breach was via unauthorized access to third-party applications, not a patchable CVE; reinforces the need to audit and restrict third-party SaaS access, but no concrete engineering action is available from this disclosure alone.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters attribution is a useful actor profile update, but no IOCs, TTPs, or detection-relevant technical detail are published yet; monitor for follow-on disclosures that include actionable indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> McKesson is a major healthcare and pharma supply chain vendor — if your organization has a relationship with them, confirm exposure scope this week and request their incident attestation; 284 million claimed patient records puts this in HIPAA notification and board-visibility territory.&lt;/li>
&lt;/ul></description></item><item><title>Hasbro discloses employee data breach</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-toy-making-giant-hasbro-disclose-data-breach-affecting-emplo/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-toy-making-giant-hasbro-disclose-data-breach-affecting-emplo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs published; monitor for follow-on phishing lures targeting Hasbro employees that could appear in broader campaigns.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Review whether your organization has vendor or partner relationships with Hasbro that involve shared employee or financial data; add to third-party breach tracker and revisit data-sharing agreements.&lt;/li>
&lt;/ul></description></item><item><title>Manchester Airports Group discloses traveler data breach</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-manchester-airports-group-says-hackers-stole-travelers-data/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-manchester-airports-group-says-hackers-stole-travelers-data/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A UK airport operator breach involving Wi-Fi registration data is a useful prompt to review what data third-party venue services collect on behalf of employees, but no immediate action is warranted for most non-UK enterprises given the regional scope and absence of published IOCs or attack detail.&lt;/li>
&lt;/ul></description></item><item><title>SickKids data breach exposes employee and applicant PII via third-party flaw</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-sickkids-data-breach-exposes-employee-and-job-applicant-info/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-sickkids-data-breach-exposes-employee-and-job-applicant-info/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A third-party software flaw exposed HR-category data (employee and applicant records) at a major hospital with no patient-record impact — a useful reference case for vendor risk assessments covering HR/recruiting platforms, particularly in healthcare.&lt;/li>
&lt;/ul></description></item><item><title>Hackers arrested for €30M bank fraud via service provider flaw</title><link>https://curasec.metacog.co.kr/insights/2026-08-15-hackers-arrested-over-30m-bank-fraud-exploiting-service-prov/</link><pubDate>Sat, 15 Aug 2026 11:32:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-15-hackers-arrested-over-30m-bank-fraud-exploiting-service-prov/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The attack vector — exploiting a third-party service provider to reach bank customer accounts — is a useful case study in lateral trust abuse, but no IOCs, TTPs, or detection artifacts are available to act on.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A €30M fraud executed through a service provider flaw reinforces third-party risk as a board-level concern; useful framing for vendor risk discussions, but no specific vendor exposure to assess here.&lt;/li>
&lt;/ul></description></item><item><title>RingCentral breach exposes 1.6M accounts via ShinyHunters</title><link>https://curasec.metacog.co.kr/insights/2026-08-14-ringcentral-data-breach-exposed-info-of-1-6-million-accounts/</link><pubDate>Fri, 14 Aug 2026 11:54:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-14-ringcentral-data-breach-exposed-info-of-1-6-million-accounts/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters claimed this breach in July; no IOCs or TTPs published yet, so no detection action is possible — file for actor-tracking context.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If RingCentral is in your vendor stack, confirm scope with your account rep, request their incident report, and assess whether affected data triggers customer or regulatory notification obligations.&lt;/li>
&lt;/ul></description></item><item><title>LexisNexis takes Diligence, Metabase API, Newsdesk offline after suspicious server activity</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-lexisnexis-shuts-down-services-after-suspicious-activity-on/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-lexisnexis-shuts-down-services-after-suspicious-activity-on/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection surface published; monitor for follow-up reporting that may yield hunt queries or indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> LexisNexis is a common enterprise vendor for due diligence and data enrichment — confirm this week whether your organization uses Diligence, Metabase API, or Newsdesk, and formally request a vendor incident report and data-exposure assessment.&lt;/li>
&lt;/ul></description></item><item><title>Unlimited Technology Systems breach affects 3.8M healthcare records</title><link>https://curasec.metacog.co.kr/insights/2026-08-09-unlimited-technology-systems-breach-impacts-3-8-million-peop/</link><pubDate>Sun, 09 Aug 2026 11:41:42 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-09-unlimited-technology-systems-breach-impacts-3-8-million-peop/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs published; breach occurred in October 2025 with delayed disclosure — useful context on healthcare software supply-chain exposure but no detection action available.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If your organization uses Unlimited Technology Systems or any of their healthcare software products, confirm exposure this week and request an incident report; the 3.8M-record scale and healthcare data sensitivity may trigger notification obligations or customer questions.&lt;/li>
&lt;/ul></description></item><item><title>MCBS medical billing data breach exposes 1.26M patient records</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs published; this breach offers no immediate detection surface, but it reinforces the pattern of healthcare billing vendors as high-value targets worth monitoring for sector-specific threat campaigns.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If your organization uses MCBS or similar third-party medical billing vendors, confirm whether you are among the 1.26M affected and request an incident attestation letter; this breach carries HIPAA notification obligations and may prompt patient or board inquiries.&lt;/li>
&lt;/ul></description></item><item><title>OnTrac Parcel Delivery Discloses Customer Data Breach</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-ontrac-notifies-customers-of-data-breach-after-network-hack/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-ontrac-notifies-customers-of-data-breach-after-network-hack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs disclosed; breach at a logistics vendor with no actionable detection surface for enterprise defenders at this time.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If OnTrac is in your vendor portfolio or used by employees for business shipments, confirm exposure scope and request an incident report from OnTrac this week before customer or leadership questions surface.&lt;/li>
&lt;/ul></description></item><item><title>Stadler Rail rejects $12.3M ransom from Everest gang after supplier platform breach</title><link>https://curasec.metacog.co.kr/insights/2026-07-23-swiss-rail-giant-stadler-rejects-12-3m-ransom-demand-after-c/</link><pubDate>Thu, 23 Jul 2026 12:47:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-23-swiss-rail-giant-stadler-rejects-12-3m-ransom-demand-after-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The entry point was a data exchange platform shared with a supplier, reinforcing that third-party integrations need isolation and least-privilege access. No specific CVE or software named, so no patch action available.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Confirms Everest ransomware gang is active and targeting supplier-connected platforms, but no IOCs or TTPs are published here to hunt on. File for actor-tracking context.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates how a shared supplier portal becomes a ransomware entry point — a useful data point for third-party risk reviews and board-level ransomware briefings. No direct vendor relationship requiring immediate action for most organizations.&lt;/li>
&lt;/ul></description></item><item><title>Ernst &amp; Young discloses data breach via support system hack</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-ernst-young-discloses-data-breach-after-support-system-hack/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-ernst-young-discloses-data-breach-after-support-system-hack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The breach originated through a third-party support ticketing system, illustrating a lateral entry path worth reviewing in your own vendor-managed tool integrations — no IOCs or TTPs published to act on yet.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If EY is a vendor or auditor your organization uses, confirm whether your data was in scope and request EY&amp;rsquo;s incident report; brief leadership now, before this becomes a customer or auditor question.&lt;/li>
&lt;/ul></description></item><item><title>23andMe pays $18M settlement over genetics data breach</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-23andme-to-pay-18-million-in-new-genetics-data-breach-settle/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-23andme-to-pay-18-million-in-new-genetics-data-breach-settle/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A genetic-data breach resulting in an $18M multistate AG settlement illustrates the regulatory and financial exposure from third-party vendors handling sensitive biometric/health data — useful context for vendor risk assessments and board-level privacy risk discussions.&lt;/li>
&lt;/ul></description></item><item><title>Lidl discloses customer data breach via service provider hack</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-lidl-discloses-online-shop-breach-after-service-provider-hac/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-lidl-discloses-online-shop-breach-after-service-provider-hac/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A named retailer&amp;rsquo;s breach traced to an unnamed service provider is a clean case study for third-party risk reviews; no specific vendor is identified in reporting, so no immediate exposure check is actionable, but it reinforces the value of contractual breach-notification SLAs with SaaS and logistics vendors.&lt;/li>
&lt;/ul></description></item></channel></rss>