Skip to content

Topic

Third-Party and Supply Chain Risk

Security discipline covering risks that vendors, suppliers and partners introduce, including breaches that spread through shared systems or outsourced services.

Current stories

security11 publishersConfirmed

FBI traces ShinyHunters breach of employee data to a patch a contractor failed to apply

FBI said a contractor's failure to apply a security patch on a third-party platform let ShinyHunters steal personal details of thousands of bureau employees. The patch had already been issued, so the breach came down to one missed update on a platform the Bureau did not manage itself.

Perspective Coverage

11 publishers
Builder
Builder 24%
Operator
Operator 60%
Investor
Investor 16%

Reality

Evidence68
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence66
security3 publishersConfirmed

Trezor says ShipMonk kept 67,000 customer records it had certified as deleted

The records cover orders placed between November 2019 and August 2021, years past the 90-day deletion window Trezor advertises. Trezor says it held repeated written confirmation from ShipMonk that the data was gone.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 55%
Investor
Investor 15%

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives64
Confidence66
leadership3 publishersConfirmed

ShinyHunters claims 2 to 3 terabytes of FBI personnel data from an Oracle PeopleSoft flaw

The bureau has not confirmed a breach and says it cannot yet tell whether its own systems or a third-party provider were the way in, while Reuters and 404 Media report that sample records match real personnel.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 63%
Investor
Investor 15%

Reality

Evidence55
Adoption45
Hype gap+30
Incentives80
Confidence60