What happened

In late July 2026, the extortion group ShinyHunters claimed it had stolen Ernst & Young credentials through a third-party technical support platform, threatening to publish client tax documents. EY confirmed the data theft.

Days later, on 3 August, biotech giant Amgen disclosed that patient data had been stolen from third-party cloud systems. July also saw Medtronic notifying customers caught up in a separate ShinyHunters campaign, and Lidl disclosing an online-shop breach caused by a hacked service provider. The pattern is unmistakable: the front door is locked, so attackers are walking through the supplier's door.

Why it matters to your business

Every SaaS platform, support tool and IT provider with access to your systems is a potential entry point — and smaller businesses are attractive precisely because their vendor security is thinner. If a firm with EY's resources can be breached through a supplier, so can your accountant, your payroll provider, or you.

This also cuts the other way: if you're a supplier to other businesses, their security questionnaires are coming. Demonstrable controls — managed endpoint protection, monitored access, documented backup and recovery — increasingly decide whether you keep contracts.

What you should do

Inventory your suppliers' access. List every vendor with credentials, integrations or data access — most businesses have never done this.

Apply least privilege to vendors. Give suppliers the minimum access, for the minimum time, with MFA enforced.

Monitor the access you grant. Central management consoles and monitoring catch supplier-side compromise faster.

Ask your own providers hard questions. Who holds your data, where, encrypted how, and what's their breach-notification process?

Source: Cybersecurity Management Alliance / BleepingComputer