Skip to main content
Cybersecurity

Third-Party Data Breach

A breach that occurs at a vendor, supplier, or partner organization and exposes data belonging to their customers or clients, often beyond the victim's direct control.

A third-party data breach occurs when a vendor, supplier, or service provider that your organization uses is compromised, exposing your data in the process. You may have perfect internal security, but if a third-party partner stores your credentials insecurely, you’re still at risk.

Third-party breaches are particularly frustrating because they’re outside your direct control. High-profile examples include the Target breach (via an HVAC vendor) and numerous incidents involving compromised SaaS providers.

Defenses include vendor security assessments, contractual security requirements, monitoring for breach notifications, and (critically) using unique passwords for every third-party service. When each vendor account has a unique password stored in a team password manager, a breach at one vendor doesn’t cascade to others.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide