Third-party vendor breach incidents
4 confirmed incidents involving the third-party-vendor-breach technique.
- activehigh
Ernst & Young data breach claimed by ShinyHunters extortion gang
ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials for company systems via a supply-chain attack. The breach was recently disclosed and the threat actor is actively claiming the incident.
ShinyhuntersOtherThird-party vendor breach - containedhigh
Polymarket customers lose $3 million in supply-chain attack
Polymarket customers lost approximately $3 million after attackers injected malicious scripts into the platform's frontend following a breach at a third-party vendor. Polymarket announced it will fully reimburse affected customers.
OtherThird-party vendor breach - containedhigh
LastPass confirms data breach in Klue supply chain attack
LastPass confirmed that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens during the Klue supply chain attack. The breach exposed customer information through a third-party vendor compromise.
OtherThird-party vendor breach - activehigh
Context.ai OAuth Token Compromise
Context.ai OAuth tokens were compromised, allowing attackers to conduct supply chain attacks through trusted SaaS integrations. Details on scope, timeline, and remediation steps are not provided in the source text.
OtherAccount takeoverThird-party vendor breach