All CosmicBytez Labs articles tagged #Third-Party Risk, across news, security advisories, how-to guides, and projects.
Canada's Hospital for Sick Children suffered a second cyber incident with employee data stolen via a compromised third-party app, four years after a 2022 ransomware attack.
Toronto's SickKids hospital disclosed a breach affecting current and former employees and job applicants via a third-party software flaw. Patients unaffected.
U.S. Bank confirmed exposure tied to a fourth-party vendor breach, stating no evidence of compromise to its own systems, networks, or data repositories.
Hackers stole names, SSNs, and financial data from a Heights Finance third-party platform, affecting over 1.2 million customers.
Pokemon Center is notifying UK and Germany customers of a third-party breach at logistics provider CEVA Logistics that exposed personal and order data.
Operation Klonen: Brazilian and German authorities arrest 7 suspects behind a €30M bank fraud exploiting a third-party payment processor vulnerability at Commerzbank.
Pharmaceutical giant Amgen disclosed a material data breach affecting cloud environments operated by third-party service providers, with threat actors exfiltrating patient protected health information and proprietary corporate data.
Australian energy giant Origin Energy confirmed a data breach exposing the personal and partial financial information of approximately 900,000 current and former customers, after a hacker exploited a third-party customer management platform and used credentials from a terminated employee.
Ernst & Young is notifying customers of a data breach stemming from the compromise of a third-party support ticket system used by its IT personnel,...
German supermarket giant Lidl has notified customers in Germany, Belgium, and the Netherlands that personal data was stolen following a breach at one of...
Healthcare device giant Medtronic is sending breach notification letters to customers after ShinyHunters gained unauthorized access to personal data held...
Roughly two dozen companies have notified their customers of impact from the Klue-Salesforce breach incident — a cascade that now includes the hackers...
Nintendo of America has confirmed that approximately 1GB of employee data — including W-9 forms, bank statements, and HR survey responses — was...
An unnamed oncology institute has disclosed a data breach originating from a third-party vendor compromise, with TriZetto cited as one possible candidate.
Small accounting firms in rural Alberta have become primary ransomware targets in 2025–2026. The reasons are structural: high-value data, weak security…
SecurityScorecard has acquired Driftnet to expand visibility into third-party ecosystems, addressing growing supply chain attack risks that continue to...
Vimeo has confirmed that customer and user data was accessed without authorization following a security breach at Anodot, a data anomaly detection...
Vercel's security breach originated from the compromise of Context.ai, a third-party AI tool used by a company employee, allowing attackers to gain...
Stolen OAuth tokens from a compromised employee AI tool enabled attackers to pivot into Vercel's internal systems. Security researchers warn that...
Telehealth giant Hims & Hers Health is warning customers of a data breach after support tickets were stolen from a third-party customer service platform,...
Texas fintech Marquis Software Solutions has confirmed a ransomware attack in August 2025 exposed data of 672,000+ individuals and disrupted operations at...
Ericsson's U.S. subsidiary has disclosed a data breach after attackers hacked a third-party service provider between April 17–22, 2025, exposing names,...