Skip to content
supplychainattack.orgSupply chain attack incident catalog

Third-party vendor breach incidents

4 confirmed incidents involving the third-party-vendor-breach technique.

  1. activehigh

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials for company systems via a supply-chain attack. The breach was recently disclosed and the threat actor is actively claiming the incident.

    ShinyhuntersOtherThird-party vendor breach
  2. containedhigh

    Polymarket customers lose $3 million in supply-chain attack

    Polymarket customers lost approximately $3 million after attackers injected malicious scripts into the platform's frontend following a breach at a third-party vendor. Polymarket announced it will fully reimburse affected customers.

    OtherThird-party vendor breach
  3. containedhigh

    LastPass confirms data breach in Klue supply chain attack

    LastPass confirmed that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens during the Klue supply chain attack. The breach exposed customer information through a third-party vendor compromise.

    OtherThird-party vendor breach
  4. activehigh

    Context.ai OAuth Token Compromise

    Context.ai OAuth tokens were compromised, allowing attackers to conduct supply chain attacks through trusted SaaS integrations. Details on scope, timeline, and remediation steps are not provided in the source text.

    OtherAccount takeoverThird-party vendor breach