Your company did not get hacked, but one of your vendors had a cybersecurity incident.
Your firewall worked. Your employees did not click a phishing link. Nobody broke into your network.
Does that mean your business is safe?
Not necessarily.
This is the reality of third-party data breaches: your business can be affected even when your own network wasn’t the original point of compromise.
Modern businesses depend on outside companies to operate. Payroll processors, cloud software providers, accounting firms, payment processors, marketing platforms, IT companies, benefits providers, and industry-specific vendors may all hold your information or have some level of access to your systems.
Your security does not stop at the edge of your own network. A breach at a third party can expose your information, give attackers a way to target your employees or customers, interrupt an essential service, or even provide a path into your systems.
In September 2026, Veradigm disclosed that one of its third-party vendors experienced a cybersecurity incident affecting data associated with some Veradigm customers. Around the same time, Trezor reported that a breach involving its third-party email provider allowed attackers to send phishing messages through legitimate-looking channels and potentially exposed hundreds of thousands of newsletter email addresses.
None of this means businesses should stop using vendors. Businesses just need to understand what their vendors can access and what happens when one of those vendors is compromised.
What Is a Third-Party Data Breach?
A third-party breach happens when information or access connected to your business is exposed because another company you work with experiences a security incident.
A vendor may hold:
- Customer or employee information
- Financial or payment information
- Business documents
- Login credentials
- Email addresses
- Access to your network or cloud applications
Sometimes the impact is primarily exposed data. In other cases, compromised vendor credentials or integrations can become a route into another environment.
Attackers may also obtain enough information to launch convincing phishing or impersonation attacks against a vendor's customers.
In short, your company does not have to be the original target for you to become part of the incident.
A Vendor Breach Can Become Your Problem in Several Ways
Not every third-party incident has the same impact.
The first thing to consider is what the vendor has access to. That determines much of your potential exposure.
Your data may have been exposed
If the vendor stores customer, employee, financial, or business information for you, a breach may expose that information even though your own systems were never compromised.
Depending on what was involved, that could create notification obligations, customer concerns, regulatory questions, identity-theft risks, or contractual issues.
Attackers may use the information against you
A list of employee names and email addresses may not seem as serious as stolen passwords, but it can make phishing much more convincing.
If an attacker knows which payroll company you use, who works in accounting, or which vendor normally emails your team, they have more information to work with.
The attacker is no longer guessing. They are using real business relationships to make the fraud believable.
A compromised vendor account may provide access
Some vendors need direct access to business systems.
A software vendor may connect remotely for support. A billing company may access records. An IT provider may have administrative tools.
If one of those accounts or integrations is compromised, the question becomes whether the attacker can use that access to reach anything else.
This is why vendor access should be limited, rather than permanent and unrestricted, whenever possible.
Your business may lose an important service
Cybersecurity is not only about stolen data.
If a critical cloud provider, payment processor, phone system, scheduling platform, or other vendor becomes unavailable during an incident, your business may be unable to operate normally.
That makes third-party risk part of business continuity too.
Start With a Vendor Inventory
Your business should maintain a basic inventory of important technology and service providers. You cannot manage vendor risk if nobody knows which vendors have access to what.
For each important vendor, document:
- What service they provide
- What information they hold
- What systems they can access
- Who internally owns the relationship
- Whether they have remote or administrative access
- What happens when the relationship ends
Vendors Should Only Have the Access They Need
This is where the principle of least privilege becomes useful.
A vendor should have access to the systems and information required to perform its job—and not automatically everything else.
The Federal Trade Commission recommends limiting vendor access to a need-to-know basis and only for as long as the vendor needs that access. It also recommends using MFA for vendor access and putting security expectations into contracts.
Consider a company that supports one specialized application on three computers. Does it need administrator access across the entire network?
Does a temporary support session need to remain available permanently?
The smaller the access path, the smaller the potential impact if the vendor's credentials are compromised.
Do Not Assume a Contract Means the Risk Is Managed
Contracts matter. Security provisions can establish expectations around data handling, breach notification, encryption, access controls, data retention, cybersecurity standards, and insurance requirements.
But signing a contract is not the same as managing the relationship.
Vendor relationships change.
A company may add new services. Employees change. Applications gain new integrations. Your business may begin sharing information that was not part of the original agreement, which is why important third-party relationships should be reviewed periodically—not only when the contract is signed.
What Should You Do If a Vendor Reports a Breach?
Do not panic—but do not simply file the notification email away either.
Start by gathering facts.
Ask:
- What happened?
- What information associated with our business was involved?
- Were credentials exposed?
- Did the vendor have access to our environment?
- Has that access been disabled or secured?
- What has the vendor done to contain the incident?
- Does our IT or security provider need to investigate anything on our side?
If the vendor had access to your systems, work with your IT or security team to determine whether that access should be temporarily limited or disabled while the incident is understood.
Depending on the situation, leadership may also need to involve legal counsel, cyber insurance, regulators, law enforcement, customers, or other appropriate parties.
Watch for Secondary Attacks
The original breach may not be the end of the incident. Attackers frequently use exposed information to make later phishing attempts more believable.
If one of your vendors is breached, employees should be especially alert for:
- Password-reset messages
- Payment-change requests
- Fake support calls
- Unexpected invoices
- MFA requests
- “Security verification” emails
- Requests for confidential information
Employees should verify unusual requests through a known contact method—not the phone number or link supplied in the suspicious message.
Ask Better Questions Before the Next Breach
Vendor risk management does not mean demanding that every small vendor produce hundreds of pages of cybersecurity documentation.
It means understanding which relationships matter most.
Start with vendors that:
- Hold sensitive information
- Access your network
- Have administrative privileges
- Process money
- Host essential systems
- Would significantly interrupt operations if unavailable
Those relationships deserve more scrutiny.
Some questions you may consider asking include:
- Do you use MFA?
- How do you protect our data?
- How quickly will you notify us of a security incident?
- How is our information removed when we stop working together?
- What access do you actually need to our systems?
You do not need perfect visibility into every vendor's cybersecurity program, but you should have enough information to understand your own exposure.
Your Security Includes the Companies You Trust
Outsourcing a business function does not eliminate the risk associated with it. It changes who shares responsibility for managing that risk.
You need to know who has your information, who has access to your systems, what that access allows them to do, and what your business will do if that vendor experiences a security incident.
At STS, vendor coordination is part of the broader technology picture we help businesses manage. Because when a vendor gets hacked, you shouldn’t have to wonder what access they had or what to do next.
