April 23, 2025 — Verizon’s 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled to 30 percent.
What happened
Verizon reported that third-party involvement appeared in 30 percent of breaches analyzed for its 2025 DBIR, double the prior report’s share. The finding covers partners and supply-chain relationships across a large incident dataset; it does not mean every vendor has the same probability of compromise.
Why it matters
Organizations increasingly depend on SaaS platforms, managed services, software components and connected contractors. A compromise outside the direct network can still inherit trusted access, shared data or administrative integration and produce a wide blast radius.
Security and infrastructure impact
Vendor assessment should extend beyond an annual questionnaire. Security teams need inventories of integrations and service accounts, least-privilege access, contract notification requirements, token revocation procedures and recovery plans for the loss of a critical supplier.
