Skip to main content

CNiC Solutions

Data center with server racks showcasing managed IT and cybersecurity solutions for Houston businesses.

Third-party involvement in data breaches doubled from 15% to 30% in a single year, the sharpest jump Verizon has ever recorded. A supply chain compromise now costs an average of $4.9 million and takes 267 days to contain. The attack surface most businesses worry about least, their vendors and the software they install, has become one of the fastest-growing ways in. This 2026 reference gathers the third-party and software supply chain data from the primary sources that define the field.

  • Third-party involvement in breaches doubled to 30% in the Verizon 2025 DBIR, up from 15% the year before.
  • A supply chain compromise costs $4.9 million on average and takes 267 days to identify and contain, per IBM.
  • Gartner projected 45% of organizations worldwide would suffer a software supply chain attack by 2025, triple the 2021 rate.
  • 454,600+ new malicious open source packages were found in 2025 alone, a 75% year-over-year rise, per Sonatype.
  • Each breached vendor exposed 5.28 downstream companies on average, the highest ripple factor Black Kite has measured.
  • 66% of supply chain attacks target the supplier’s code, according to ENISA’s 2025 threat landscape.
  • The MOVEit campaign hit 2,559 organizations and 66 million people, showing how far a single software flaw can reach.

What’s in This Report

1How Common Supply Chain Attacks Are

For years, supply chain compromise was treated as a rare, nation-state problem. The 2025 data ended that assumption. The clearest signal came from Verizon, which analyzed 22,052 security incidents and 12,195 confirmed breaches for its 2025 report and found that the share involving a third party had doubled.

 

 

Infographic of key 2026 supply chain attack stats: 30% of breaches, $4.9M cost, 267 days, 5.28 ripple
Four headline figures that define supply chain risk in 2026 (Sources: Verizon, IBM, Black Kite).

 

 

30%
Share of data breaches that involved a third party in 2025, double the 15% recorded a year earlierSource: Verizon 2025 DBIR
45%
Organizations Gartner projected would experience a software supply chain attack by 2025, triple the 2021 levelSource: Gartner
63%
Organizations that reported falling victim to a software supply chain attack in the prior two yearsSource: Checkmarx global study

Supply Chain Risk by Measure (share of organizations or breaches)

Software supply chain victims, 2 years (Checkmarx)
63%
Orgs hit by 2025, projected (Gartner)
45%
Breaches involving a third party, 2025 (Verizon)
30%
Breaches involving a third party, 2024 (Verizon)
15%

The single-year doubling of third-party involvement is the sharpest shift Verizon has recorded. Sources: Verizon 2025 DBIR, Gartner, Checkmarx.

These figures measure different things, which is why they differ. Verizon’s 30% counts breaches where a partner, supplier, or hosted service played a role. Gartner’s 45% is a forward projection of how many organizations would be touched by a software supply chain attack. Checkmarx’s 63% comes from a survey of organizations reporting whether they had been hit. Read together, they point the same direction: supply chain exposure is now the common case, not the exception, and it applies as much to a small firm running third-party software as to a Fortune 500 with hundreds of vendors.

Source: Verizon 2025 Data Breach Investigations Report | Gartner supply chain security research

Assess your third-party risk with a security review

2The Cost and Detection Gap

What makes supply chain attacks expensive is not only the initial breach but how long they hide. Because the intrusion arrives through a trusted vendor or a signed software update, it bypasses many of the alarms tuned for outside threats. IBM’s 2025 analysis put hard numbers on the penalty.

$4.9M
Average cost of a breach caused by a supply chain or vendor compromise, among the most expensive vectors trackedSource: IBM Cost of a Data Breach 2025
267 days
Average time to identify and contain a supply chain compromise, one of the longest lifecycles of any breach typeSource: IBM Cost of a Data Breach 2025
$1.14M
Extra cost of a breach that runs past 200 days ($5.01M) versus one contained sooner ($3.87M)Source: IBM Cost of a Data Breach 2025
Cost or timing measure Figure Source
Supply chain / vendor compromise, average cost $4.9 million IBM 2025
Supply chain compromise, time to identify and contain 267 days IBM 2025
Breach lifecycle over 200 days, average cost $5.01 million IBM 2025
Breach lifecycle under 200 days, average cost $3.87 million IBM 2025
Projected global cost of software supply chain attacks by 2025 $60 billion Cybersecurity Ventures

The 267-day lifecycle is the number to internalize. It means an attacker who slips in through a compromised vendor has, on average, most of a year inside connected systems before anyone confirms and closes the breach. For a small or midsize business, which rarely has a 24/7 security team watching for anomalies coming from trusted software, that window is often wider still. This is precisely the gap that continuous monitoring and managed detection are built to close. For the broader picture on breach economics, see our data on the average cost of a data breach.

Myth: supply chain attacks only hit large enterprises. The opposite is often true. Small and midsize businesses tend to run more third-party software with less oversight, and they are frequently the softer downstream target attackers use to reach a larger partner. Verizon’s 2025 data shows ransomware, a common payload of supply chain intrusions, present in 88% of breaches at small and midsize businesses. Size is not shelter here.

Source: IBM Cost of a Data Breach Report 2025 | Cybersecurity Ventures supply chain cost forecast

Build a recovery plan that limits breach dwell time

3Open Source and Software Under Siege

The largest and fastest-growing slice of supply chain risk lives in software itself, especially the open source packages that modern applications are assembled from. Attackers have shifted from hunting for accidental bugs to deliberately planting malicious code where developers will pull it in.

454,600+
New malicious open source packages Sonatype identified in 2025 alone, a 75% jump over the prior yearSource: Sonatype 2026 State of the Software Supply Chain
1.23M+
Cumulative malicious packages blocked across npm, PyPI, Maven Central, NuGet, and Hugging FaceSource: Sonatype 2026 State of the Software Supply Chain
66%
Share of supply chain attacks that focus on compromising the supplier’s own codeSource: ENISA Threat Landscape 2025
Software supply chain measure Figure Source
New malicious open source packages, 2025 454,600+ Sonatype 2026
Year-over-year growth in open source malware +75% Sonatype 2026
Cumulative malicious packages blocked to date 1.23 million+ Sonatype 2026
New malicious packages found in Q1 2025 alone ~18,000 Sonatype Malware Index
Supply chain attacks targeting supplier code 66% ENISA 2025
Increase in exposed secrets in repositories, 2023 to 2024 +25% ENISA 2025

The shift ENISA describes matters for defenders. When two thirds of supply chain attacks aim at the supplier’s code, the threat is no longer just a vendor with weak passwords. It is a poisoned dependency, a typosquatted package, or a backdoored update that carries the attacker’s code straight into your build. ENISA analyzed 4,875 incidents for its 2025 landscape and repeatedly found adversaries, including nation-state groups, planting malicious npm packages that mimic legitimate libraries to compromise developer environments.

Source: Sonatype 2026 State of the Software Supply Chain | ENISA Threat Landscape 2025

Get managed oversight of the software your business runs

 

CNiC Solutions — Cybersecurity

 

4The Ripple Effect Across Vendors

The defining feature of a supply chain attack is reach. Compromise one supplier and you touch every organization that depends on it. Black Kite’s 2026 Third-Party Breach Report quantified how far that blast radius now extends.

 

 

Diagram showing one breached vendor cascading to 5.28 downstream companies with 47% via unauthorized access
Each breached vendor compromises an average of 5.28 downstream companies (Source: Black Kite 2026).

 

 

5.28
Downstream companies publicly compromised for every single vendor breached, the highest ratio Black Kite has recordedSource: Black Kite 2026 Third-Party Breach Report
47%
Verified third-party breaches that began with unauthorized network access, the leading entry methodSource: Black Kite 2026 Third-Party Breach Report
~26,000
Additional affected companies vendors reported without naming, showing the true scope runs far past disclosed victimsSource: Black Kite 2026 Third-Party Breach Report
Ripple and concentration measure Figure Source
Average downstream companies compromised per breached vendor 5.28 Black Kite 2026
Third-party breaches starting with unauthorized network access 47% Black Kite 2026
Unnamed additional affected companies ~26,000 Black Kite 2026
Breaches involving a third party (context) 30% Verizon 2025

Source: Black Kite 2026 Third-Party Breach Report

Put third-party risk under expert governance

5Who Is Attacking and How

Supply chain attacks are not one technique but a set of entry paths, and the market behind them has professionalized. CrowdStrike’s 2025 Global Threat Report tracked a booming trade in ready-made access, while Verizon mapped how attackers actually get their first foothold.

+50%
Year-over-year rise in access broker advertisements, with 4,486 tracked in 2024 as attackers buy and sell entry pointsSource: CrowdStrike 2025 Global Threat Report
35%
Cloud intrusions that were identity-based, often enabled through access broker markets and reused credentialsSource: CrowdStrike 2025 Global Threat Report
+34%
Growth in breaches that started with vulnerability exploitation, now the initial vector in roughly 20% of breachesSource: Verizon 2025 DBIR

How Attackers Get In: Initial Access Vectors, 2025

Third-party involvement
30%
Credential abuse
22%
Vulnerability exploitation
20%

Third-party involvement now leads the initial-access picture. Source: Verizon 2025 DBIR.

The access broker boom is what ties these together. When entry to a well-defended organization can simply be purchased, a supplier with a stolen credential becomes a product, sold to whichever ransomware crew wants a path into that supplier’s customers. That is why credential abuse and vulnerability exploitation both feed the supply chain problem: they are the wholesale supply of the footholds that later cascade downstream. For the deeper numbers on exploited flaws, see our 2026 vulnerability statistics.

Source: CrowdStrike 2025 Global Threat Report | Verizon 2025 DBIR

Secure and monitor the network access attackers exploit

6Lessons From the Landmark Attacks

The statistics describe the shape of the threat. The named incidents show what it does at scale. Each of these is a documented, primary-sourced event, and together they trace how supply chain attacks moved from novelty to norm.

18,000+
SolarWinds customers who received the trojanized Orion update in 2020, though only a subset were actively exploitedSource: CISA
66M+
Individuals whose data was exposed in the 2023 MOVEit campaign, across 2,559 organizationsSource: Emsisoft
CVSS 10.0
Severity of the 2024 XZ Utils backdoor (CVE-2024-3094), caught by a developer before it shipped widelySource: CISA / NVD
Incident Year Vector Documented reach
SolarWinds Sunburst 2020 Trojanized software update (Orion) 18,000+ customers received the malicious update
MOVEit Transfer (Cl0p) 2023 Zero-day flaw in file-transfer software 2,559 organizations, 66M+ individuals
3CX 2023 Cascading (double) supply chain compromise Affected a widely used business phone client
XZ Utils backdoor (CVE-2024-3094) 2024 Malicious code planted in an open source library CVSS 10.0; caught before wide deployment
Polyfill.io 2024 Compromised widely embedded web script 100,000+ websites loaded the tampered code

Two patterns run through the list. First, the vector keeps shifting: from a poisoned build system at SolarWinds, to a single zero-day at MOVEit, to a hijacked open source project at XZ Utils. Second, the reach is disproportionate to the effort. One tampered update or one embedded script reaches tens of thousands of organizations, which is exactly why the ripple math in the previous section is not theoretical. The XZ Utils case is the encouraging counterexample: a maintainer’s curiosity caught a near-perfect backdoor before it shipped broadly, a reminder that visibility and monitoring still work.

Source: CISA emergency directive on SolarWinds | Emsisoft MOVEit breach analysis

Talk to CNiC about layered infrastructure defense

Full Statistics Table

Statistic Figure Source Year
Breaches involving a third party 30% Verizon DBIR 2025
Third-party involvement, prior year 15% Verizon DBIR 2024
Security incidents analyzed 22,052 Verizon DBIR 2025
Confirmed data breaches analyzed 12,195 Verizon DBIR 2025
Vulnerability exploitation as initial vector 20% (+34%) Verizon DBIR 2025
Orgs projected hit by software supply chain attack 45% Gartner 2025
Orgs hit by software supply chain attack, past 2 years 63% Checkmarx 2024
Supply chain / vendor compromise, average cost $4.9 million IBM 2025
Supply chain compromise, time to identify and contain 267 days IBM 2025
Breach cost, lifecycle over 200 days $5.01 million IBM 2025
New malicious open source packages 454,600+ Sonatype 2025
Open source malware year-over-year growth +75% Sonatype 2025
Cumulative malicious packages blocked 1.23 million+ Sonatype 2025
Supply chain attacks targeting supplier code 66% ENISA 2025
Downstream companies compromised per breached vendor 5.28 Black Kite 2026
Third-party breaches via unauthorized network access 47% Black Kite 2026
Access broker advertisements tracked 4,486 (+50%) CrowdStrike 2024
MOVEit campaign, organizations affected 2,559 Emsisoft 2023
MOVEit campaign, individuals affected 66 million+ Emsisoft 2023
SolarWinds Orion, customers sent malicious update 18,000+ CISA 2020

Frequently Asked Questions

How common are supply chain attacks in 2026?

Third-party involvement in data breaches doubled from 15% to 30% in a single year, the largest such jump the Verizon 2025 Data Breach Investigations Report has recorded. Gartner had already predicted that by 2025, 45% of organizations worldwide would experience an attack on their software supply chain, a threefold rise from 2021. Supply chain risk is now a mainstream breach vector, not an edge case.

How much does a supply chain attack cost?

According to the IBM 2025 Cost of a Data Breach Report, a breach caused by a supply chain or vendor compromise averaged about $4.9 million and took 267 days to identify and contain, among the longest lifecycles of any attack vector. Breaches that ran longer than 200 days cost $5.01 million on average, versus $3.87 million for those contained faster.

What is the most common type of supply chain attack?

Software and open source compromise dominates. ENISA found that about 66% of supply chain attacks focus on the supplier’s code. Sonatype identified more than 454,600 new malicious open source packages in 2025 alone, a 75% year-over-year increase, bringing the cumulative total of blocked malware to over 1.23 million packages across npm, PyPI, Maven Central, NuGet, and Hugging Face.

What was the biggest supply chain attack?

Two stand out for scale. The 2020 SolarWinds Sunburst attack pushed a trojanized Orion update to more than 18,000 customers, though only a smaller subset were actively exploited. The 2023 MOVEit campaign by the Cl0p ransomware group ultimately hit 2,559 organizations and exposed data on more than 66 million individuals, according to Emsisoft’s final tally.

How do supply chain attacks spread to so many companies at once?

Through a ripple effect. Black Kite’s 2026 Third-Party Breach Report found that every single breached vendor publicly compromised an average of 5.28 downstream companies, the highest level it has recorded. Unauthorized network access was the entry point in 47% of verified third-party breaches, meaning one compromised supplier can cascade into thousands of dependent organizations.

Methodology & Sources

Third-party involvement figures (30% in 2025, up from 15%), the incident and breach counts (22,052 and 12,195), the initial-access vectors, and the vulnerability-exploitation growth come from the Verizon 2025 Data Breach Investigations Report. Cost and lifecycle figures for supply chain and vendor compromise ($4.9 million, 267 days, and the over-200-day cost penalty) come from the IBM Cost of a Data Breach 2025 report. The projection that 45% of organizations would experience a software supply chain attack by 2025 is from Gartner; the 63% two-year victimization figure is from a global Checkmarx study. Open source malware figures (454,600+ new malicious packages in 2025, +75% year over year, and 1.23 million+ cumulative) come from Sonatype’s 2026 State of the Software Supply Chain report and its Open Source Malware Index. The 66% code-targeting share, the 25% rise in exposed secrets, and the 4,875-incident base come from the ENISA Threat Landscape 2025. The ripple factor (5.28 downstream companies per breached vendor), the 47% unauthorized-access share, and the ~26,000 unnamed affected companies come from Black Kite’s 2026 Third-Party Breach Report. Access broker figures (4,486 advertisements, +50% year over year) and the 35% identity-based cloud intrusion figure come from the CrowdStrike 2025 Global Threat Report. Incident reach figures come from primary reporting: CISA for SolarWinds (18,000+ customers), and Emsisoft for the MOVEit final tally (2,559 organizations, 66 million+ individuals). The $60 billion global cost projection is a forecast from Cybersecurity Ventures and is labeled as such. Only Tier 1 primary sources and named vendor reports with disclosed methodology are used. This article is informational and is not a security assessment of any specific business.

 

back to blog