Third-party involvement in data breaches doubled from 15% to 30% in a single year, the sharpest jump Verizon has ever recorded. A supply chain compromise now costs an average of $4.9 million and takes 267 days to contain. The attack surface most businesses worry about least, their vendors and the software they install, has become one of the fastest-growing ways in. This 2026 reference gathers the third-party and software supply chain data from the primary sources that define the field.
For years, supply chain compromise was treated as a rare, nation-state problem. The 2025 data ended that assumption. The clearest signal came from Verizon, which analyzed 22,052 security incidents and 12,195 confirmed breaches for its 2025 report and found that the share involving a third party had doubled.

Supply Chain Risk by Measure (share of organizations or breaches)
The single-year doubling of third-party involvement is the sharpest shift Verizon has recorded. Sources: Verizon 2025 DBIR, Gartner, Checkmarx.
These figures measure different things, which is why they differ. Verizon’s 30% counts breaches where a partner, supplier, or hosted service played a role. Gartner’s 45% is a forward projection of how many organizations would be touched by a software supply chain attack. Checkmarx’s 63% comes from a survey of organizations reporting whether they had been hit. Read together, they point the same direction: supply chain exposure is now the common case, not the exception, and it applies as much to a small firm running third-party software as to a Fortune 500 with hundreds of vendors.
Source: Verizon 2025 Data Breach Investigations Report | Gartner supply chain security research
Assess your third-party risk with a security review
What makes supply chain attacks expensive is not only the initial breach but how long they hide. Because the intrusion arrives through a trusted vendor or a signed software update, it bypasses many of the alarms tuned for outside threats. IBM’s 2025 analysis put hard numbers on the penalty.
| Cost or timing measure | Figure | Source |
|---|---|---|
| Supply chain / vendor compromise, average cost | $4.9 million | IBM 2025 |
| Supply chain compromise, time to identify and contain | 267 days | IBM 2025 |
| Breach lifecycle over 200 days, average cost | $5.01 million | IBM 2025 |
| Breach lifecycle under 200 days, average cost | $3.87 million | IBM 2025 |
| Projected global cost of software supply chain attacks by 2025 | $60 billion | Cybersecurity Ventures |
The 267-day lifecycle is the number to internalize. It means an attacker who slips in through a compromised vendor has, on average, most of a year inside connected systems before anyone confirms and closes the breach. For a small or midsize business, which rarely has a 24/7 security team watching for anomalies coming from trusted software, that window is often wider still. This is precisely the gap that continuous monitoring and managed detection are built to close. For the broader picture on breach economics, see our data on the average cost of a data breach.
Myth: supply chain attacks only hit large enterprises. The opposite is often true. Small and midsize businesses tend to run more third-party software with less oversight, and they are frequently the softer downstream target attackers use to reach a larger partner. Verizon’s 2025 data shows ransomware, a common payload of supply chain intrusions, present in 88% of breaches at small and midsize businesses. Size is not shelter here.
Source: IBM Cost of a Data Breach Report 2025 | Cybersecurity Ventures supply chain cost forecast
Build a recovery plan that limits breach dwell time
The largest and fastest-growing slice of supply chain risk lives in software itself, especially the open source packages that modern applications are assembled from. Attackers have shifted from hunting for accidental bugs to deliberately planting malicious code where developers will pull it in.
| Software supply chain measure | Figure | Source |
|---|---|---|
| New malicious open source packages, 2025 | 454,600+ | Sonatype 2026 |
| Year-over-year growth in open source malware | +75% | Sonatype 2026 |
| Cumulative malicious packages blocked to date | 1.23 million+ | Sonatype 2026 |
| New malicious packages found in Q1 2025 alone | ~18,000 | Sonatype Malware Index |
| Supply chain attacks targeting supplier code | 66% | ENISA 2025 |
| Increase in exposed secrets in repositories, 2023 to 2024 | +25% | ENISA 2025 |
The shift ENISA describes matters for defenders. When two thirds of supply chain attacks aim at the supplier’s code, the threat is no longer just a vendor with weak passwords. It is a poisoned dependency, a typosquatted package, or a backdoored update that carries the attacker’s code straight into your build. ENISA analyzed 4,875 incidents for its 2025 landscape and repeatedly found adversaries, including nation-state groups, planting malicious npm packages that mimic legitimate libraries to compromise developer environments.
Source: Sonatype 2026 State of the Software Supply Chain | ENISA Threat Landscape 2025
Get managed oversight of the software your business runs
The defining feature of a supply chain attack is reach. Compromise one supplier and you touch every organization that depends on it. Black Kite’s 2026 Third-Party Breach Report quantified how far that blast radius now extends.

| Ripple and concentration measure | Figure | Source |
|---|---|---|
| Average downstream companies compromised per breached vendor | 5.28 | Black Kite 2026 |
| Third-party breaches starting with unauthorized network access | 47% | Black Kite 2026 |
| Unnamed additional affected companies | ~26,000 | Black Kite 2026 |
| Breaches involving a third party (context) | 30% | Verizon 2025 |
CNiC Solutions Analysis: the trust multiplier. Combine two findings and the systemic risk comes into focus. Verizon reports that a third party is now involved in 30% of all breaches, while Black Kite finds that each breached vendor drags an average of 5.28 named downstream victims with it. In other words, nearly a third of breaches trace back to an outside party, and each of those parties, once compromised, becomes a distribution point to more than five further organizations. A single weak vendor is no longer a single point of failure. It is a multiplier. Calculation and interpretation original to CNiC Solutions, based on Verizon 2025 DBIR and Black Kite 2026 figures.
Source: Black Kite 2026 Third-Party Breach Report
Put third-party risk under expert governance
Supply chain attacks are not one technique but a set of entry paths, and the market behind them has professionalized. CrowdStrike’s 2025 Global Threat Report tracked a booming trade in ready-made access, while Verizon mapped how attackers actually get their first foothold.
How Attackers Get In: Initial Access Vectors, 2025
Third-party involvement now leads the initial-access picture. Source: Verizon 2025 DBIR.
The access broker boom is what ties these together. When entry to a well-defended organization can simply be purchased, a supplier with a stolen credential becomes a product, sold to whichever ransomware crew wants a path into that supplier’s customers. That is why credential abuse and vulnerability exploitation both feed the supply chain problem: they are the wholesale supply of the footholds that later cascade downstream. For the deeper numbers on exploited flaws, see our 2026 vulnerability statistics.
Source: CrowdStrike 2025 Global Threat Report | Verizon 2025 DBIR
Secure and monitor the network access attackers exploit
The statistics describe the shape of the threat. The named incidents show what it does at scale. Each of these is a documented, primary-sourced event, and together they trace how supply chain attacks moved from novelty to norm.
| Incident | Year | Vector | Documented reach |
|---|---|---|---|
| SolarWinds Sunburst | 2020 | Trojanized software update (Orion) | 18,000+ customers received the malicious update |
| MOVEit Transfer (Cl0p) | 2023 | Zero-day flaw in file-transfer software | 2,559 organizations, 66M+ individuals |
| 3CX | 2023 | Cascading (double) supply chain compromise | Affected a widely used business phone client |
| XZ Utils backdoor (CVE-2024-3094) | 2024 | Malicious code planted in an open source library | CVSS 10.0; caught before wide deployment |
| Polyfill.io | 2024 | Compromised widely embedded web script | 100,000+ websites loaded the tampered code |
Two patterns run through the list. First, the vector keeps shifting: from a poisoned build system at SolarWinds, to a single zero-day at MOVEit, to a hijacked open source project at XZ Utils. Second, the reach is disproportionate to the effort. One tampered update or one embedded script reaches tens of thousands of organizations, which is exactly why the ripple math in the previous section is not theoretical. The XZ Utils case is the encouraging counterexample: a maintainer’s curiosity caught a near-perfect backdoor before it shipped broadly, a reminder that visibility and monitoring still work.
What this means for a typical business. You will almost never be the SolarWinds or the MOVEit. You are far more likely to be one of the 18,000 or one of the 2,559, a downstream customer who installed a trusted product that turned hostile. The defensive question is therefore not only how to secure your own code, but how quickly you would detect and contain a compromise that arrived through software you were right to trust.
Source: CISA emergency directive on SolarWinds | Emsisoft MOVEit breach analysis
Talk to CNiC about layered infrastructure defense
| Statistic | Figure | Source | Year |
|---|---|---|---|
| Breaches involving a third party | 30% | Verizon DBIR | 2025 |
| Third-party involvement, prior year | 15% | Verizon DBIR | 2024 |
| Security incidents analyzed | 22,052 | Verizon DBIR | 2025 |
| Confirmed data breaches analyzed | 12,195 | Verizon DBIR | 2025 |
| Vulnerability exploitation as initial vector | 20% (+34%) | Verizon DBIR | 2025 |
| Orgs projected hit by software supply chain attack | 45% | Gartner | 2025 |
| Orgs hit by software supply chain attack, past 2 years | 63% | Checkmarx | 2024 |
| Supply chain / vendor compromise, average cost | $4.9 million | IBM | 2025 |
| Supply chain compromise, time to identify and contain | 267 days | IBM | 2025 |
| Breach cost, lifecycle over 200 days | $5.01 million | IBM | 2025 |
| New malicious open source packages | 454,600+ | Sonatype | 2025 |
| Open source malware year-over-year growth | +75% | Sonatype | 2025 |
| Cumulative malicious packages blocked | 1.23 million+ | Sonatype | 2025 |
| Supply chain attacks targeting supplier code | 66% | ENISA | 2025 |
| Downstream companies compromised per breached vendor | 5.28 | Black Kite | 2026 |
| Third-party breaches via unauthorized network access | 47% | Black Kite | 2026 |
| Access broker advertisements tracked | 4,486 (+50%) | CrowdStrike | 2024 |
| MOVEit campaign, organizations affected | 2,559 | Emsisoft | 2023 |
| MOVEit campaign, individuals affected | 66 million+ | Emsisoft | 2023 |
| SolarWinds Orion, customers sent malicious update | 18,000+ | CISA | 2020 |
Third-party involvement figures (30% in 2025, up from 15%), the incident and breach counts (22,052 and 12,195), the initial-access vectors, and the vulnerability-exploitation growth come from the Verizon 2025 Data Breach Investigations Report. Cost and lifecycle figures for supply chain and vendor compromise ($4.9 million, 267 days, and the over-200-day cost penalty) come from the IBM Cost of a Data Breach 2025 report. The projection that 45% of organizations would experience a software supply chain attack by 2025 is from Gartner; the 63% two-year victimization figure is from a global Checkmarx study. Open source malware figures (454,600+ new malicious packages in 2025, +75% year over year, and 1.23 million+ cumulative) come from Sonatype’s 2026 State of the Software Supply Chain report and its Open Source Malware Index. The 66% code-targeting share, the 25% rise in exposed secrets, and the 4,875-incident base come from the ENISA Threat Landscape 2025. The ripple factor (5.28 downstream companies per breached vendor), the 47% unauthorized-access share, and the ~26,000 unnamed affected companies come from Black Kite’s 2026 Third-Party Breach Report. Access broker figures (4,486 advertisements, +50% year over year) and the 35% identity-based cloud intrusion figure come from the CrowdStrike 2025 Global Threat Report. Incident reach figures come from primary reporting: CISA for SolarWinds (18,000+ customers), and Emsisoft for the MOVEit final tally (2,559 organizations, 66 million+ individuals). The $60 billion global cost projection is a forecast from Cybersecurity Ventures and is labeled as such. Only Tier 1 primary sources and named vendor reports with disclosed methodology are used. This article is informational and is not a security assessment of any specific business.
Media and press: Journalists and researchers are welcome to cite these statistics with attribution to the original primary sources named above, and to CNiC Solutions for any analysis labeled as original.
A browser push notification scam hijacks a real, useful browser feature (the small alerts that news…
Business email compromise is the quiet giant of cybercrime. It rarely involves malware or a dramatic…
Email is still the front door attackers knock on first. In 2024 the FBI's Internet Crime…
A backup is the difference between a bad afternoon and a closed business. When ransomware hits,…