Third-Party (Supply-Chain) Breach
A third-party breach, also called a supply-chain breach, happens when attackers compromise a vendor, service provider, contractor, software supplier, payment processor, or another external company that holds or has access to a business's data or systems. The main company does not need to be directly hacked for its customers' information to be exposed.
✦ Key Insight
Crypto and fintech companies depend on many external providers. These can include: Payment processors Merchant of Record services Cloud providers Email platforms Customer-support software Identity-verification vendors Analytics tools Marketing platforms Software libraries A user may therefore share information with more companies than they realise. Third-party breaches can expose data that attackers later use for phishing, SIM swapping, impersonation, account takeover, and targeted crypto scams.
✕ Common Misconceptions
Assuming a vendor breach means crypto funds were stolen
Ignoring breach notices because the main company was not hacked
Reusing passwords across vendors and financial accounts
Treating all leaked data as equally sensitive
Underestimating how leaked personal information supports phishing
Assuming deletion from the main company also deletes vendor copies
Detailed Explanation
How It Works
A company sends data to a vendor to provide a service.
For example, a customer-support provider may receive customer email addresses and ticket histories.
If attackers compromise the vendor, they can potentially access data belonging to many of the vendor's clients.
The original company may then need to determine:
What data the vendor held
Which customers were affected
How long the attacker had access
Whether credentials or financial information were exposed
Whether users need to take protective action
FAQs
Is a third-party breach the company's fault?
Responsibility depends on circumstances, contracts, security controls, and applicable law. The immediate compromise occurs at the third party, but companies still need to manage vendor risk.
Can a vendor breach expose my crypto wallet?
It usually cannot expose self-custody private keys unless those keys were somehow stored with the vendor. However, leaked personal data can support targeted attacks.
What should users do after a third-party breach?
Review exactly what information was exposed, change affected credentials where appropriate, strengthen account security, and watch for targeted phishing attempts.
In Practice
Dig Deeper
Phishing
Phishing is a scam where attackers trick users into revealing private information or signing harmful transactions.
Merchant of Record
A Merchant of Record, often shortened to MoR, is a third-party company that legally processes customer payments and orders on behalf of another business. The Merchant of Record usually appears as the seller or payment recipient in the transaction and may handle payment processing, taxes, refunds, chargebacks, fraud checks, billing records, and customer order data.
