Disclaimer: We sustain our work & review products through paid collaborations.
Data Breach Incidents Involving Third-Parties Has Doubled

Data Breach Incidents Involving Third-Parties Has Doubled

Verizon reports that in 2024, third-party service exploitation was responsible for 30% of data breaches, double the amount from 2023.

Additionally, Verizon’s 2025 Data Breach Investigations Report also found that vulnerability exploitation increased 34%, making up for 20% of the data breaches.

These findings were taken from a large data set of over 22,000 security incidents and more than 12,000 confirmed data breaches.

Data breach alerts

Third-party services and business security insights

  • Proliferation of specialized SaaS providers.
  • Attacks on third-party software doubled.
  • Ransomware increased by 37%, making up for 44% of data breaches.
  • Strong emphasis on zero-day exploits against perimeter devices and VPNs.
  • Supply chain attacks can lead to severe consequences.
  • Business interruption incidents increased.
  • Humans are responsible for a significant portion of data breaches, due to social engineering and credential abuse attacks.

According to the report, businesses outsourcing critical operations to third parties are increasing. While this enhances scalability and efficiency, it also provides cybercriminals with a larger attack surface, increasing the chances of falling victim to a cyberattack.

Additionally, Verizon’s report also emphasizes that high-profile data breach incidents involving supply chain attacks can be as nefarious, or even more so, than traditional breaches due to downtime and severe business continuity disturbances.

Business security

Protecting your business

Considering our increasing dependence on the internet, 2025 may well be the worst year so far for cybercrime. The lack of cybersecurity awareness, combined with the broad adoption of third-party services for essential business operations, makes for an explosive cocktail. It’s fundamental for businesses to have a clear understanding of the biggest cybersecurity threats to look out for and to adopt the best supply chain security measures.

Unfortunately, smaller businesses are especially vulnerable to cyberattacks. This is primarily due to budget restrictions and a lack of cybersecurity awareness, emphasizing the importance cybersecurity essentials.

No business is the same, which means protecting against data breaches may require different approaches. While different services can help, such as antivirus and internet security suites, we recommend implementing a VPNpassword manager, and online data backup software tailored to businesses.

Best VPN services for small businesses in 2026

Editors' choice

NordLayer

Editor's rating:
ZTNA
Cloud firewall
Device posture security
Site-to-site VPN
Remote teams

Perimeter 81

Editor's rating:
ZTNA
Secure Web Gateway
Firewall as a Service
Device posture checks
Budget-conscious businesses

Surfshark

Editor's rating:
Easy to use everywhere
Enhanced online privacy
Fast and secure connections
Protect unlimited devices
Simplicity

TunnelBear

Editor's rating:
45+ countries
Split tunnelling
Secure encryption protocols
User-friendly apps
International businesses

GoodAccess

Editor's rating:
Zero trust access control
Static dedicated IP
Access logs & SIEM integration
Rapid deployment
Small offices

Proton VPN

Editor's rating:
Great UX for all users
Strong, flexible protection
Trustworthy data practices
Consistent, fast connections

Discussions

Share your thoughts, ask questions, and connect with other users. Your feedback helps our community make better decisions.

©2012-2026 Best Reviews, a clovio brand – All rights reserved