Skip to content

Topic

Third-Party and Supply Chain Risk

A cybersecurity risk category covering compromises that originate in vendors, contractors, or software suppliers rather than an organization's own systems.

Current stories

invest4 publishers

Bitget's CEO doubts the $387.5 million lost through a vendor-linked backend will come back

Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 41%
Investor
Investor 34%

Reality

Evidence68
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence70
build1 publisher

Confluent Cloud gains an OSPAR attestation for Singapore bank outsourcing reviews

Confluent Cloud now holds an OSPAR attestation, adding Singapore's bank-sector audit to the four reports already in its Trust Center. Singapore banks vetting Confluent as an outsourced provider can start from one audit built on the banking association's own control baseline.

Publishers:confluent.io

Reality

Evidence35
Adoption
Insufficient
Hype gap+15
Incentives80
Confidence40
invest2 publishers

DriveWealth's September intrusion exposes customer data at Stake in Australia and Hatch in New Zealand

DriveWealth's systems were accessed on 4 and 5 September, exposing contact details and account balances of Stake and Hatch customers, the brokers say. Stake says DriveWealth serves several Australian platforms, so one intrusion reaches customers of competing apps.

Publishers:hellostake.comhelp.hatchinvest.nz

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives65
Confidence55
security5 publishers

Heights Finance says its loan systems held. 1.2 million records went anyway.

The lender reports no intrusion into its own networks. The loss happened inside a third-party cloud store holding Social Security numbers, bank details and files on people who only ever applied.

Perspective Coverage

5 publishers
Builder
Builder 17%
Operator
Operator 61%
Investor
Investor 22%

Reality

Evidence72
Adoption
Insufficient
Hype gap−10
Incentives55
Confidence68
invest1 publisher

DriveWealth's breach reached Revolut customer records up to 33 months after Revolut stopped sending them

DriveWealth's September breach reached records on Revolut's UK, EEA and Australian customers that Revolut stopped sending 15 to 33 months earlier. Revolut's new trading model cut off fresh transfers but left older copies with the broker, where an intrusion could still reach them.

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives60
Confidence50
invest1 publisher

Former Philadelphia Fed president urges examiners to police AI model vendors under a 1962 law

Former Philadelphia Fed president wants examiners to use a 1962 law on AI vendors after the April 17 SR 11-7 rewrite excluded generative AI. The plan skips Congress but still asks for a new supervisory letter within 12 months, aimed at the few suppliers whose models many banks share.

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence40
security6 publishers

IDScan confirms breach in noindexed notice, as reports peg leaked database at 153 million licenses

The company says it learned on or around September 1 that data in customer accounts on its cloud may have been copied, and its notice lists names and ID numbers but not the licence scans Nexus was selling.

Publishers:bleepingcomputer.comcyberinsider.comgadgetreview.comhelpnetsecurity.comidscan.netrisky.biz

Perspective Coverage

6 publishers
Builder
Builder 17%
Operator
Operator 52%
Investor
Investor 31%

Reality

Evidence74
Adoption62
Hype gap+14
Incentives71
Confidence70

Earlier coverage

  1. Credit unions call AI model risk critical at a third the national-bank rate

    Invest · September 2, 2026 · 1 publisher

  2. Six to nine vendors, five obligations each: the first AI security exercise is arithmetic

    Build · August 26, 2026 · 1 publisher

  3. 88 breaches, 2.15 billion records, and 41 leaks that nobody can reset

    Security · August 26, 2026 · 1 publisher

  4. CareCloud's breach count grew almost 11x, five months after the first filing

    Security · August 21, 2026 · 1 publisher

  5. CareCloud's Breach Went From 350,000 to 3.7 Million, and the State Filings Still Say 350,000

    Security · August 19, 2026 · 3 publishers

  6. One vendor, 19 million patients: the MyDr breach is a lesson in whose perimeter matters

    Security · August 18, 2026 · 1 publisher

  7. NYDFS says a vendor's flaw reached its banks, and there is no regulator for the vendor

    Invest · August 17, 2026 · 1 publisher

  8. A North Korean IT worker got hired by a federal agency. Vetting is a security control now.

    Security · August 14, 2026 · 1 publisher

  9. Eight warehouses down, six brands notifying: the Ceva outage nobody's plan modelled

    Security · August 14, 2026 · 2 publishers