Vendor & Third-Party Risk
Real-World StoriesPart 1 of 4

The Breach That Wasn't Yours

You can lock down every system you own and still lose everything because of a vendor you trusted. Two real breaches show exactly how, and why the risk is bigger than most small organizations realize.

7 min read

Most of the security advice aimed at small businesses and nonprofits focuses on what happens inside your own four walls: your email, your backups, your staff. That advice is correct, and it is also incomplete, because a growing share of the breaches hitting organizations like yours never touch your own systems at all.

They touch a vendor's systems instead. Your payroll provider. Your donor database. The managed service provider that handles your IT. A cloud storage tool three staff members signed up for without asking anyone. Each one holds a piece of your organization's data or a way into your network, and each one is a decision you made about who to trust, whether you thought of it that way or not.

The core idea: Third-party risk is not a separate category of security problem. It is the same risk you already manage, extended to every vendor with access to your data or your systems. If you would not hand a stranger your donor list or your bank login, you should know exactly what you are handing your vendors.
48% of all breaches in 2025 involved a third party, according to Verizon's 2026 Data Breach Investigations Report
60% increase in third-party involvement in breaches year over year, per the same report
74% of companies do not know all the third parties that handle their data, according to Optiv research

Third-party involvement in breaches has more than tripled since 2023 by Verizon's measurement, and the reason is not that vendors have gotten careless. It is that attackers have figured out something small organizations have not fully absorbed yet: it is often easier to compromise one software vendor or MSP and reach a thousand downstream customers than it is to attack those thousand organizations one at a time.

Two breaches. Neither organization's fault. Both organizations' problem.

Incident 1

The IT vendor attack that hit up to 1,500 small businesses in a single weekend

Managed service provider software supply chain
Scope: ~60 MSPs, up to 1,500 downstream businesses

In July 2021, the ransomware group REvil exploited a vulnerability in Kaseya VSA, remote-monitoring software used by managed service providers to maintain client systems. Kaseya's own customers were not the ultimate target. The MSPs who used Kaseya to manage their clients' networks were the delivery mechanism.

Roughly 60 MSPs were compromised directly. Because each of those MSPs managed IT for dozens or hundreds of small businesses, the ransomware spread automatically to an estimated 800 to 1,500 downstream organizations, most of them exactly the kind of small business or nonprofit that has no in-house IT staff and relies entirely on an outside provider. REvil demanded $70 million for a universal decryption key.

None of the affected small businesses clicked a phishing link or reused a weak password. Their own security posture, whatever it was, was irrelevant. The vulnerability lived in software one layer removed from them, in a vendor most of them had never heard of and had no direct relationship with.

What this means for you

If you outsource your IT to an MSP, that MSP's software supply chain is now part of your attack surface, whether you asked for that or not. You cannot audit Kaseya's code. You can ask your own MSP what remote-management tools they use, how quickly they patch them, and what they would do if one of those tools were compromised tomorrow.

Incident 2

The donor database breach that exposed nonprofits that never touched a keyboard

Nonprofit CRM and fundraising software vendor
Scope: 536+ organizations, roughly 13 million people affected

In May 2020, ransomware attackers breached Blackbaud, one of the largest providers of donor management and fundraising software to nonprofits, universities, and hospital foundations. Blackbaud detected the intrusion, locked the attackers out, and paid the ransom in exchange for a promise that the stolen copy of the data would be destroyed. The promise had no independent verification behind it.

The breach ultimately affected more than 536 organizations and an estimated 13 million individuals, exposing Social Security numbers, financial account information, dates of birth, and detailed donor profiles, including giving history. Nearly every one of those 536 organizations had done nothing more than choose a well-established, widely used vendor to manage their donor relationships, a completely reasonable decision that nonprofits make every day.

The organizations themselves had to send breach notifications to their own donors, field the reputational fallout, and in some cases face regulatory scrutiny, even though the failure occurred entirely inside a vendor's systems they never had visibility into.

What this means for you

Choosing a large, reputable vendor is not the same as choosing a safe one. It reduces some risks and does nothing for others. Before donor, client, or financial data goes into any platform, it is worth knowing what that vendor has committed to about breach notification timelines and what data they retain longer than they need to.

The pattern underneath both stories

Neither of these organizations was breached because of something they did wrong on their own network. Both were breached because they depend, as every organization now does, on a web of vendors that hold their data or have a path into their systems. That dependency is not optional. You cannot run payroll, manage donors, process payments, or maintain a website entirely in-house, and no one is suggesting you try.

What is optional is whether you know which vendors matter most, what happens if one of them fails, and whether you asked any questions before signing up. Most small businesses and nonprofits never do, not out of carelessness, but because nobody told them it was a step worth taking.

The honest framing: You will never eliminate third-party risk. Every useful vendor relationship involves some transfer of trust. The goal is not zero vendors and zero risk. The goal is knowing which relationships carry the most exposure, and making sure you asked the right questions before, not after, something goes wrong.

What this series covers

Over the next three posts, this series will walk through what practical vendor risk management looks like for an organization with no procurement department and no security team: the specific questions worth asking before you sign with any vendor, the myth that outsourcing your IT means outsourcing your security responsibility, and what your board or leadership should be asking about who actually holds your data.

None of it requires a formal vendor risk management program with scorecards and quarterly audits. It requires a short list of questions, asked consistently, and a habit of not assuming that someone else already checked.

Not sure how much of your risk actually lives with your vendors?

A 30-day Security Business Review maps out your critical vendors and data flows alongside your internal risk, so you get one clear, prioritized picture instead of two separate blind spots.

Start a Conversation
Third-Party Risk Vendor Risk Real-World Incidents Nonprofit Security Small Business Supply Chain