Saudi Aramco data breach leaking 1 TB of proprietary company information and full employee profiles came about due to a third party security lapse at an unnamed contractor.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A breach of a third party vendor used by some airlines to process pilot job applications has exposed at least 8,700 records, according to data breach disclosures made by American and Southwest Airlines. The impacted airlines have said that they have cut ties with the third party vendor.
Salesforce has confirmed another third-party breach affecting Gainsight applications integrated with customer instances, enabling attackers to exfiltrate customer data.
Artificial intelligence (AI) company OpenAI was impacted by a third-party breach affecting analytics company Mixpanel, exposing “limited” user data.
Another security breach involving US telecom companies has come to light, with a third-party contractor that interfaces between some of the industry's big names reporting discovery of unauthorized access to their systems by nation-state hackers that began in late 2024 and continued through much of 2025.
Snack giant Mondelēz International has suffered a third-party law firm data breach from its legal services provider, Bryan Cave Leighton Paisner LLP, leaking sensitive personal information of over 50,000 current and former employees.
A third-party data breach at the online DIY platform ManoMano has affected nearly 38 million customers after attackers breached its subcontractor’s Zendesk instance.
Spanish multinational fashion retailer MANGO has recently experienced a third-party data breach that exposed customer information from a marketing partner.
A third-party breach on a reputable service provider has leaked OpenSea API keys, exposing NFT holders’ accounts to exploitation by unauthorized external parties.
Harrods has disclosed a third-party data breach after cybercriminals claimed to have stolen over 430,000 customer records. The luxury department learned of the breach after the attackers approached the company and demanded a ransom to avoid leaking the stolen data online.










