Key Takeaways
- In 2023, third-party vendor breaches contributed to 19% of all reported data breaches worldwide, impacting over 2.6 billion records
- Third-party incidents rose by 23% from 2022 to 2023, representing 28% of supply chain attacks
- 44% of organizations experienced a third-party data breach in the past year, up from 37% in 2021
- The average cost of a third-party data breach reached $4.88 million in 2023, 10% higher than company-direct breaches
- Third-party breaches cost organizations an average of $5.2 million including lost business in 2023
- Financial losses from third-party incidents averaged $1.76 million per megabyte of data exposed in 2023
- PII was the most common data type in 45% of third-party breaches in 2023, exposing 1.8 billion records
- Credentials compromised in 29% of third-party incidents, leading to 2.1 million unique logins stolen in 2023
- Financial data affected 22% of third-party breaches, with $3.4 billion in card data exposed 2023
- 61% of third-party breaches targeted healthcare organizations in 2023
- Financial services saw 29% of third-party incidents, highest exposure rate in 2023
- Retail sector vulnerable in 24% of third-party supply chain attacks 2023
- Average time to identify third-party breach was 204 days in 2023
- 78% of organizations lacked third-party breach response plans effective in 2023
- Third-party breach containment took average 77 days, costing extra $1.2M
Third-party data breaches are increasing rapidly, causing costly global business disruptions.
Characteristics
Characteristics Interpretation
Economic
Economic Interpretation
Prevalence
Prevalence Interpretation
Remediation
Remediation Interpretation
Vulnerabilities
Vulnerabilities Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2IBMibm.comVisit source
- Reference 3PONEMONponemon.orgVisit source
- Reference 4CROWDSTRIKEcrowdstrike.comVisit source
- Reference 5RISKBASEDSECURITYriskbasedsecurity.comVisit source
- Reference 6MANDIANTmandiant.comVisit source
- Reference 7IDTHEFTCENTERidtheftcenter.orgVisit source
- Reference 8UPGUARDupguard.comVisit source
- Reference 9SECURITYWEEKsecurityweek.comVisit source
- Reference 10CLOUDSECURITYALLIANCEcloudsecurityalliance.orgVisit source
- Reference 11ZDNETzdnet.comVisit source
- Reference 12SOPHOSsophos.comVisit source
- Reference 13AKAMAIakamai.comVisit source
- Reference 14HHShhs.govVisit source
- Reference 15CYBERNEWScybernews.comVisit source
- Reference 16PROOFPOINTproofpoint.comVisit source
- Reference 17ENISAenisa.europa.euVisit source
- Reference 18RISKRECONriskrecon.comVisit source
- Reference 19MICROSOFTmicrosoft.comVisit source
- Reference 20BREACHSENSEbreachsense.comVisit source
- Reference 21TENABLEtenable.comVisit source
- Reference 22HAVEIBEENPWNEDhaveibeenpwned.comVisit source
- Reference 23FINEXTRAfinextra.comVisit source
- Reference 24GARTNERgartner.comVisit source
- Reference 25BITSIGHTbitsight.comVisit source
- Reference 26PEWRESEARCHpewresearch.orgVisit source
- Reference 27DRAGOSdragos.comVisit source
- Reference 28NOWSECUREnowsecure.comVisit source
- Reference 29CLOUDFLAREcloudflare.comVisit source
- Reference 30MCAFEEmcafee.comVisit source
- Reference 31KEEPERSECURITYkeepersecurity.comVisit source
- Reference 32DELOITTEwww2.deloitte.comVisit source
- Reference 33SALESFORCEsalesforce.comVisit source
- Reference 34ENFORCEMENTTRACKERenforcementtracker.comVisit source
- Reference 35FORRESTERforrester.comVisit source
- Reference 36PWCpwc.comVisit source
- Reference 37HBRhbr.orgVisit source
- Reference 38EXPERIANexperian.comVisit source
- Reference 39IOT-ANALYTICSiot-analytics.comVisit source
- Reference 40COMPUSTATcompustat.comVisit source
- Reference 41MARSHmarsh.comVisit source
- Reference 42BAKERLAWbakerlaw.comVisit source
- Reference 43OAGoag.ca.govVisit source
- Reference 44MCKINSEYmckinsey.comVisit source
- Reference 45ITRCitrc.orgVisit source
- Reference 46GITHUBgithub.comVisit source
- Reference 47BIOMETRICUPDATEbiometricupdate.comVisit source
- Reference 48GEMALTOgemalto.comVisit source
- Reference 49SHRMshrm.orgVisit source
- Reference 50SYNOPSYSsynopsys.comVisit source
- Reference 51KASPERSKYkaspersky.comVisit source
- Reference 52IOTWORLDTODAYiotworldtoday.comVisit source
- Reference 53SECURITYMAGAZINEsecuritymagazine.comVisit source
- Reference 54GENOMEWEBgenomeweb.comVisit source
- Reference 55ESPORTSesports.netVisit source
- Reference 56LAWlaw.comVisit source
- Reference 57SUPPLYCHAINDIVEsupplychaindive.comVisit source
- Reference 58CISAcisa.govVisit source
- Reference 59EDWEEKedweek.orgVisit source
- Reference 60FREIGHTWAVESfreightwaves.comVisit source
- Reference 61HOLLYWOODREPORTERhollywoodreporter.comVisit source
- Reference 62ACCOUNTINGTODAYaccountingtoday.comVisit source
- Reference 63HOSPITALITYNEThospitalitynet.orgVisit source
- Reference 64NONPROFITTECHYnonprofittechy.comVisit source
- Reference 65LIGHTREADINGlightreading.comVisit source
- Reference 66AUTONEWSautonews.comVisit source
- Reference 67INMANinman.comVisit source
- Reference 68PHARMAINTELLIGENCEpharmaintelligence.comVisit source
- Reference 69PRECISIONAGprecisionag.comVisit source
- Reference 70SBAsba.govVisit source
- Reference 71DARKTRACEdarktrace.comVisit source
- Reference 72NISTnist.govVisit source
- Reference 73PREVALENTprevalent.netVisit source
- Reference 74DELPHIXdelphix.comVisit source
- Reference 75OKTAokta.comVisit source
- Reference 76EXABEAMexabeam.comVisit source
- Reference 77ISACAisaca.orgVisit source
- Reference 78FIREEYEfireeye.comVisit source
- Reference 79NSAnsa.govVisit source
- Reference 80GS1gs1.orgVisit source






