
Supply chain cybersecurity has become a major business continuity and risk management concern as organizations rely on increasingly interconnected networks of software providers, cloud platforms, contractors, payment processors, and other third parties. A security weakness at one supplier can create a path into multiple customer environments, allowing a single incident to expose sensitive data, disrupt operations, or spread malicious software across an entire ecosystem.
The risk has grown alongside the widespread use of open-source components, SaaS applications, cloud infrastructure and complex software dependencies. Organizations must therefore look beyond their internal security controls and understand how vendors, fourth parties and software components affect their overall exposure. The following supply chain cybersecurity statistics highlight the latest trends in third-party breaches, software supply chain attacks, malicious packages, ransomware, supplier risk management and financial impact.
Editor’s Choice
- Researchers verified 136 major third-party breach events during 2025, the incident base analyzed for a major 2026 third-party breach study.
- Those incidents publicly affected 719 named downstream companies, showing how one compromised supplier can spread risk across many customers.
- Another approximately 26,000 companies were reported as affected in aggregate but were not individually named in public disclosures.
- Public disclosures associated with those incidents indicated that about 433 million people were affected.
- Each breached vendor in that dataset affected an average of 5.28 publicly identified downstream companies, the highest multiplier recorded in the report.
- Research published in 2026 found a median attack-detection period of 10 days for the third-party incidents it analyzed.
- However, public disclosure took an average of 117 days, creating a lengthy gap between detection and broader stakeholder awareness.
- Separately, the 2026 Data Breach Investigations Report found that 31% of breaches began with exploitation of software vulnerabilities, making vulnerability exploitation the leading breach entry point in that dataset.
Recent Developments
- The 2026 Data Breach Investigations Report found ransomware in 48% of breaches, indicating that ransomware remains deeply connected to the wider enterprise and supplier threat environment.
- The same 2026 research found that generative AI was bolstering 15% of identified attack techniques, as threat actors incorporated AI into activities ranging from vulnerability discovery to malware development.
- Mobile-focused social engineering generated 40% higher click rates than traditional email phishing in the 2026 findings, signaling a shift in how attackers target people with access to business systems.
- Open-source security research identified more than 454,600 new malicious packages during 2025, reflecting the growing scale of software supply chain manipulation.
- By 2026, researchers had identified and blocked more than 1.233 million malicious open-source packages across major software ecosystems.
- Cybersecurity researchers analyzed 4,875 incidents between July 1, 2024, and June 30, 2025, finding increasing abuse of cyber dependencies and interconnected digital services.
- Within that European threat dataset, phishing accounted for about 60% of observed initial intrusion methods.
- Vulnerability exploitation accounted for another 21.3% of observed initial intrusion methods, making software weaknesses the second-leading entry route in that analysis.
Supply Chain Cybersecurity Overview
- In the 2026 global third-party risk survey, 83% of executives said they planned to expand their partner networks during the next one to three years. Larger partner ecosystems can increase the number of dependencies organizations need to monitor.
- Yet 48% of executives said there was room to improve collaboration around risk management with third parties.
- Only 18% of organizations reported that third-party risk management was fully integrated with enterprise risk management in 2026.
- Another 53% described their third-party risk programs as mostly integrated with enterprise risk management rather than fully integrated.
- Looking forward, 71% of organizations planned further integration of third-party and enterprise risk management during the following three years.
- Data remains a constraint: only 17% rated the information supporting their third-party risk programs as fully reliable.
- More than 80% of organizations used managed services, outsourcing or a combination of the two for at least some core third-party risk activities.
- Despite that widespread outsourcing, only 5% had adopted an end-to-end managed service model for third-party risk management.
- Spending priorities also show how organizations are responding: 52% concentrated third-party risk spending on risk assessments and due diligence, while 51% prioritized technology and tools.
Supply Chain Breach Statistics
- Among breaches involving third parties in the 2025 breach dataset, 81% followed a system intrusion pattern.
- Social engineering represented 5% of breaches with third-party involvement in the same dataset.
- Basic web application attacks accounted for another 5% of third-party-involved breaches.
- Privilege misuse accounted for 3% of third-party-involved breaches, showing that trusted access can also contribute to supplier-related exposure.
- Miscellaneous errors represented 1.3% of third-party-involved breaches in the dataset.
- A separate analysis examined 400 third- and fourth-party relationships connected to supply chain attacks, including 355 third-party and 45 fourth-party relationships.
- Cross-industry software and IT products or services represented 37.5% of the breach-enabling relationships in that study, the largest category identified.
- Industry-specific, nontechnical services represented 22% of supply chain breach enablers, demonstrating that cyber supply chain exposure extends beyond software providers.
- Cross-industry nontechnical services accounted for another 13%, while subsidiaries and acquisitions represented 11.75% of the analyzed relationships.

Supply Chain Cyberattack Frequency
- In 2025 breach research, third parties played a role in 30% of confirmed breaches, twice the share recorded in the preceding report.
- The underlying 2025 breach study examined more than 22,000 security incidents, providing a large dataset for measuring attack patterns.
- Of those incidents, 12,195 were confirmed data breaches, showing the scale of the evidence behind the annual findings.
- Vulnerability exploitation as an initial-access technique increased 34% year over year in the 2025 breach dataset. This trend matters for supply chains because vulnerable edge devices and third-party software can create shared entry points.
- Ransomware activity increased 37% in the 2025 breach research, reinforcing the connection between system intrusion, compromised suppliers and operational disruption.
- In separate 2025 research, 35.5% of analyzed breaches had a third-party nexus, compared with 29% a year earlier. Different methodologies explain why third-party breach estimates vary between datasets.
- A 2025 cybersecurity workforce survey found that 28% of participants had experienced an incident originating from a third-party vendor or supplier during the previous two years.
- The incidence rate climbed to 34% among enterprise organizations, suggesting that larger and more interconnected companies faced greater exposure to vendor-originated events.
- Financial services recorded an even higher rate: 37% of respondents in that sector said their organizations had experienced a vendor- or supplier-originating cybersecurity incident within the previous two years.
Third-Party and Vendor Cybersecurity Statistics
- In 2025, 70% of surveyed cybersecurity professionals said they were very or extremely concerned about supply chain cybersecurity risk.
- Concern reached 82% in financial services, the highest sector figure reported in that survey.
- Military and military-contractor organizations followed closely, with 81% reporting very great or extreme concern about supply chain cyber risk.
- In health care, 67% of respondents reported very high or extreme concern about cybersecurity risk across their supply chains.
- Organizations that had already suffered a third-party cybersecurity incident showed greater concern: 75% reported being very or extremely concerned about supply chain risk.
- By comparison, that level of concern fell to 63% among organizations without a previous supplier-originated incident.
- A 2026 survey found that 87% of organizations assessed fewer than all of their third parties, indicating that complete vendor-security coverage remains uncommon.
- Resource pressure contributes to that gap: 78% of security teams said insufficient staffing or tools limited either the number of third parties they could assess or the depth of those assessments.
- Government survey data published in 2026 found that only 15% of businesses formally reviewed cyber risks from their immediate suppliers, while just 6% assessed risks across their wider supply chains. Among large businesses, however, immediate-supplier reviews reached 48%.
Supplier Risk Management Statistics
- In 2026, only 15% of businesses formally reviewed cybersecurity risks associated with their immediate suppliers.
- Visibility dropped further into extended ecosystems: just 6% of businesses reviewed cybersecurity risks across their wider supply chains in 2026.
- Company size made a substantial difference. 48% of large businesses reviewed immediate supplier cyber risk, compared with 30% of medium-sized businesses.
- Among small businesses, 22% formally reviewed risks associated with immediate suppliers, while the rate fell to 12% among microbusinesses.
- Only 24% of large businesses assessed cybersecurity risk across their wider supply chains, showing that even larger organizations often lack visibility beyond direct suppliers.
- Supplier security requirements also remain limited. Just 11% of businesses required suppliers to hold cybersecurity standards or accreditations in the 2026 survey.
- At the same time, 2026 global research found that 52% of organizations concentrated third-party risk management spending on risk assessments and due diligence.
- Another 51% prioritized third-party risk management technology and tools, while 49% directed spending toward cybersecurity and data protection.
- Despite that investment, only 17% of organizations reported fully reliable, valid, consistent, and integrated third-party risk data in 2026.
- Meanwhile, 83% of executives expected their partner networks to expand over the following one to three years, increasing the number of supplier relationships risk teams may need to oversee.

Software Supply Chain Security Statistics
- A 2026 North American survey of 400 IT, cybersecurity and application professionals found that 77% of organizations had experienced a software supply chain incident during the previous 12 months.
- Known vulnerabilities in third-party software accounted for the most common incident type, affecting 38% of organizations surveyed.
- Currently, 38% of surveyed organizations said more than half of their software code came from third-party sources. That proportion was expected to reach 58% within 12 months.
- Open-source software shows a similar trajectory. 31% of organizations said more than half of their code consisted of open-source software, with 51% expecting that threshold within 12 months.
- AI technology ranked as the leading software supply chain concern for 40% of organizations, narrowly exceeding third-party code at 39% and software dependencies at 38%.
- Despite the incident rate, developers retained substantial confidence in open source: 50% were confident and another 31% completely confident that their developers used only secure open-source software.
- Security-tool effectiveness remained uneven. Only one of 12 security-tool categories received a “very effective” rating from a majority of surveyed organizations.
- Developer involvement has therefore become a major priority: 98% of surveyed organizations placed importance on enabling developers to contribute to software supply chain security.
- The risk is translating into additional spending. 62% of organizations expected significant investment in software supply chain security, according to the 2026 survey data.
Malicious Package and Software Dependency Vulnerability Statistics
- Researchers identified more than 454,600 new malicious open-source packages in 2025, bringing the cumulative number known and blocked at that point to more than 1.233 million.
- A separate 2026 analysis recorded a 73% year-over-year increase in malicious open-source package detections during 2025.
- In the first quarter of 2026 alone, researchers identified another 21,764 malicious packages, pushing the cumulative count to 1,346,867.
- By the end of Q2 2026, the cumulative number of logged malicious packages had passed 1.8 million, illustrating how quickly malicious package activity continued to expand.
- npm accounted for 75% of malicious package activity identified during Q1 2026.
- Its share increased sharply in Q2, when npm represented 96.6% of malicious package counts recorded during the quarter.
- Across 2025 data, repository abuse represented 55.9% of logged malicious packages, making large-scale abuse of package registries the dominant identified behavior.
- Host-information exfiltration appeared in 5.7% of malicious packages, while secrets exfiltration appeared in 3.9%. These behaviors can expose credentials stored on developer machines and CI/CD systems.
- Among malicious packages associated with a prominent state-linked campaign, roughly 77% contained two or more threat behaviors, and nearly 9% contained four or more.
- One large 2025 npm campaign produced 169,538 packages and was designed to self-replicate approximately every seven seconds, demonstrating how automation can turn package repositories into high-volume attack channels.
Open-Source Software Supply Chain Statistics
- In 2025, 92% of open-source program offices participated in open-source security activities, while 42% held decision-making roles in those activities.
- However, only 44% of organizations checked a project’s community activity before adopting an open-source component in the 2025 global survey.
- Just 37% evaluated release frequency before adopting open-source software, despite release activity providing useful information about project maintenance.
- Only 36% of organizations examined the direct dependencies of an open-source component before adoption.
- Automated security testing formed part of the pre-adoption process for just 31% of surveyed organizations in 2025.
- Manual source-code inspection was even less common, reported by 28% of organizations evaluating new open-source components.
- In financial services, 52% of organizations identified vulnerabilities in open-source components as one of their leading open-source concerns in 2025.
- Another 37% of financial services organizations specifically identified supply chain attacks as an open-source concern.
- A 2026 open-source provenance dataset covered 105,533 package maintainers, 58,346 source repositories and 21.2 million release versions across 11 package ecosystems, illustrating the scale of the ecosystem that security teams must evaluate.
- The same 2026 research found that repositories with no release in two years averaged a security score of 2.6 out of 10, compared with 4.5 for active repositories.

Software Bill of Materials Statistics
- In a 2026 survey, 78% of organizations reported that they had already started their SBOM adoption journey.
- However, only 9% described their SBOM implementation as mature and fully supported by automation. Another 25% reported broad adoption across their products.
- 44% of organizations remained in the pilot or limited-adoption stage, showing that SBOM deployment has yet to reach maturity for many businesses.
- Organizations expect rapid progress: 79% estimated that they would reach the necessary SBOM maturity level by the time the EU Cyber Resilience Act becomes fully applicable.
- Automation is developing faster in generation than consumption. 74% reported partially or fully automated SBOM generation for each software release or build.
- Yet only 7% of respondents said they had completely closed the gap between generating SBOMs and actually using the information. Another 44% reported a moderate gap and 23% a significant gap.
- SBOM completeness remains difficult: 62% of organizations rated achieving a high degree of completeness as a substantial technical challenge.
- Supplier delivery also remains inconsistent. 39% of organizations said they never received SBOMs for purchased commercial software, another 39% received them rarely, and only 2% said they always received them.
- Only 10% had mandatory SBOM requirements in supplier contracts, although 55% were working toward systematically adding such requirements.
- The most common machine-readable format was CycloneDX at 44%, followed by SPDX at 29%; meanwhile, 17% used proprietary formats and 11% reported no standard format.
Cloud and SaaS Supply Chain Security Statistics
- Analysis published in 2026 found that 83% of major cloud and SaaS incidents examined during the second half of 2025 involved identity issues as the route for initial access.
- Third-party software exploitation accounted for 44.5% of observed cloud initial-access activity in H2 2025, compared with only 2.9% during the first half of the year.
- Weak or missing credentials moved in the opposite direction, falling from 47.1% in H1 to 27.2% in H2 2025 as a share of observed initial access.
- Remote code execution exploitation increased nearly fivefold, from 2.9% to 13.6%, between the first and second halves of 2025.
- Compromised trusted relationships with third parties accounted for 21% of analyzed initial-access cases involving major cloud and SaaS environments.
- Software supply chain compromises accounted for another 3% of cases, including incidents in which compromised packages enabled credential theft and persistence.
- Stolen human and nonhuman credentials represented 21% of initial-access cases, including stolen access keys, tokens, and identities tied to cloud services.
- Voice-based social engineering accounted for 17% of cases, with attackers impersonating employees or support personnel to gain access to SaaS applications and identity systems.
- Email phishing accounted for another 12% of analyzed cases, including credential-harvesting campaigns and MFA fatigue attacks.
- Once attackers entered cloud environments, data became the primary target: 73% of cloud-related incidents involved attempts to access or steal data.
Fourth-Party and Extended Supply Chain Risk Statistics
- A 2026 risk-assessment study found that only 42% of organizations assessed fourth-party or subcontractor risk in some form.
- Within that group, just 23% of organizations assessed fourth-party or subcontractor risk broadly, while another 19% performed such assessments only for critical suppliers.
- Meanwhile, 38% of respondents reported either no trust or only slight confidence in their visibility into fourth parties that could affect their organizations.
- More broadly, only 6% of businesses formally reviewed cybersecurity risk across their wider supply chains in the 2025/2026 survey period.
- Among large businesses, wider supply chain reviews reached 24%, four times the overall business rate but still well below the 48% that reviewed immediate suppliers.
- Medium-sized businesses reported a 13% wider-supply-chain review rate, compared with 30% that reviewed immediate supplier risk.
- Small businesses recorded a 10% extended-supply-chain review rate, while only 5% of microbusinesses reported conducting such reviews.
- Charities showed an even larger visibility gap: 4% reviewed risks across their wider supply chains, compared with 9% reviewing immediate suppliers.
- The scale of the problem is likely to increase because 83% of executives said in 2026 that they expected their organizations to expand their partner networks during the next one to three years. More partners can create additional fourth-party dependencies even when the organization does not contract with them directly.
- Accordingly, multi-tier supplier exposure ranked as the second-leading perceived supply chain risk in a 2026 U.S. executive survey, behind cybersecurity threats. In the same study, 94% said their organizations were innovating in risk management and resilience already or planned to do so within three years.
Supply Chain Attack Methods
- Software vulnerability exploitation became the leading initial breach vector in 2026, accounting for 31% of breaches. That represents a 55% increase from the previous reporting period.
- In frontline investigations covering 2025, exploits accounted for 32% of initial infections, making them the most common entry method for the sixth consecutive year.
- Voice phishing surged to 11% of initial infections in the same investigation dataset, becoming the second-most frequently observed initial vector.
- Traditional email phishing moved in the opposite direction, falling from 14% in 2024 to 6% in 2025 as attackers increased their use of interactive social engineering.
- Prior compromise accounted for 10% of initial infections globally, showing how access obtained in an earlier intrusion can become the starting point for another attack.
- For ransomware operations specifically, prior compromise accounted for 30% of initial infections in 2025, twice the 15% recorded in 2024.
- Attackers also accelerated the transfer of compromised access. Median time between initial access and handoff to another threat group fell from more than eight hours in 2022 to only 22 seconds in 2025.
- Cloud-focused investigations found that compromised trusted third-party relationships represented 21% of initial-access cases, while software supply chain compromises accounted for another 3%.
- The 2026 threat intelligence dataset recorded a 44% year-over-year increase in exploitation of publicly exposed software and applications. In addition, 56% of disclosed vulnerabilities analyzed could be exploited without authentication.
- Mobile social engineering is also becoming more effective. Simulations showed 40% higher median successful click rates for attacks entering through voice or text channels than for email-based attacks.

Ransomware, Malware, and Malicious Code Statistics
- Ransomware appeared in 48% of breaches in the 2026 breach dataset, increasing from 44% in the previous reporting period.
- However, 69% of ransomware victims did not pay a ransom, continuing the multiyear shift toward lower payment rates.
- Among victims that paid, the median ransom payment declined to $139,875, compared with $150,000 in the preceding dataset.
- Separate ransomware research recorded 6,046 publicly disclosed victims between April 2024 and March 2025, representing a 24% year-over-year increase.
- That research tracked 96 active ransomware groups, including 52 groups that were new entrants to the ransomware ecosystem.
- Ransomware accounted for 66.7% of analyzed third-party breaches for which researchers could identify the attack method, demonstrating its role in turning vendor compromises into downstream incidents.
- Active ransomware groups increased 49% year over year in another 2026 threat intelligence dataset, adding further evidence that ransomware operations remain fragmented and active.
- In manufacturing, malware appeared in 75% of breaches analyzed in the 2026 industry dataset, while ransomware alone appeared in 61%.
- Malicious software distribution is expanding beyond conventional ransomware. Detection of malicious open-source packages increased 73% during 2025, reflecting growing attacks against development ecosystems and package registries.
- European threat data for 2025 found that ransomware deployment represented 40% of analyzed financially motivated cybercrime events, while data breaches represented 31% and fraud or impersonation accounted for 19%.
Supply Chain Cybersecurity Costs and Financial Impact
- The global average cost of a data breach reached a record $4.99 million in 2026, a 12% increase from the previous year.
- Extensive use of AI and automation in security produced an average $1.93 million in breach-cost savings compared with organizations that did not use those technologies.
- Insurance-claims analysis found that business interruption generated 50% of known losses associated with supply chain and third-party incidents.
- Business interruption appeared in approximately 25% of supply chain and third-party claims, showing that it occurs less frequently than some other loss categories but can produce disproportionately large financial damage.
- For ransomware claims across the broader 2019-2025 insurance dataset, extortion represented 32% of overall losses, while business interruption accounted for another 26%.
- Small and medium-sized businesses can face particularly severe proportional losses. Among the most extreme 2.5% of SMB breach cases, financial losses exceeded 7% of annual revenue.
- In India, the average organizational cost of a breach reached INR 255 million in 2026, up 15.9% from INR 220 million in 2025. The average number of compromised records also increased from 38,200 to 39,500.
- In the Middle East, third-party vendor and supply chain compromises represented 17% of breaches in 2025 research and produced an average cost of SAR 29.6 million.
- The financial effect is not limited to direct breach expenses. In manufacturing, recent incident analysis highlights how ransomware can halt production and shipments, meaning supply chain disruption can add operational losses beyond ransom and technical recovery costs.
Supply Chain Cybersecurity Statistics by Industry and Region
- Manufacturing recorded 3,627 security incidents and 2,713 confirmed breaches in the 2026 industry dataset. Third parties were involved in 61% of manufacturing breaches.
- Vulnerability exploitation initiated 38% of manufacturing breaches, compared with phishing at 13% and credential abuse at 11%.
- Manufacturing breaches overwhelmingly involved outside attackers: 95% involved external actors, and 87% had a financial motive.
- Health care showed a different but still significant supplier exposure, with third parties involved in 32% of breaches in its 2026 industry dataset.
- Public administration recorded 3,634 incidents and 2,410 confirmed breaches. Third parties appeared in 36% of breaches, while the human element appeared in 69%.
- Vulnerability exploitation represented 40% of initial access in public administration breaches, followed by phishing at 20% and credential abuse at 8%.
- Across Asia-Pacific, third parties appeared in 69% of breaches in the regional 2026 dataset. Vulnerability exploitation accounted for 42% of initial access, while credential abuse represented 25%.
- Third-party involvement reached 54% of breaches in Europe, the Middle East and Africa, where vulnerability exploitation represented 47% of initial access and phishing represented 28%.
- Latin America and the Caribbean recorded the highest third-party share among the four reported regions at 74% of breaches. Vulnerability exploitation represented 44% of initial access.
- In North America, third parties appeared in 43% of breaches, while exploitation of vulnerabilities represented 30% of initial access, credential abuse 20%, and phishing 12%.

Supply Chain Attack Detection, Response, and Recovery Statistics
- The global median attacker dwell time reached 14 days in 2025, increasing from 11 days in 2024.
- Organizations first detected malicious activity internally in 52% of investigations, up from 43% a year earlier.
- External organizations provided the initial notification in 34% of investigations, down from 43% in 2024. Attackers themselves notified victims in the remaining 14% of cases.
- Ransomware cases followed a different pattern: attackers notified victims in 44% of cases, while organizations detected 41% internally and outside entities identified 15%.
- Cyberespionage and North Korean IT worker investigations had a median dwell time of 122 days, nearly nine times the overall 14-day median.
- Some stealth-focused attacks lasted considerably longer. Cases involving the BRICKSTORM backdoor averaged 393 days of dwell time, far beyond common 90-day log-retention windows.
- In verified third-party incidents from 2025, vendors detected compromise in a median of 10 days, although the average reached 68 days because some intrusions remained undetected for much longer.
- Public disclosure took an average of 117 days after discovery in the same third-party incident dataset. The median disclosure delay was 73 days.
- Critical vulnerability remediation also slowed: median time to full resolution reached 43 days, almost two weeks longer than in the preceding reporting period.
- Third-party cloud security findings show another remediation gap. Only 23% of organizations fully fixed missing or improperly secured MFA findings, while resolving half of weak-password and permission-misconfiguration findings took almost eight months.
Frequently Asked Questions (FAQs)
Third parties are involved in 48% of all breaches, up 60% from the previous reporting period.
A third-party breach affected an average of 5.28 downstream companies in 2025, the highest level recorded in the analyzed dataset.
Researchers identified 454,648 new malicious packages in 2025, bringing the cumulative known and blocked total to more than 1.233 million packages.
Software vulnerability exploitation accounts for 31% of breaches, making it the leading initial breach vector in the 2026 dataset.
Third-party breaches were detected in a median of 10 days, but public disclosure took an average of 117 days in the analyzed 2025 incidents.
Conclusion
Supply chain cybersecurity statistics show that cyber risk increasingly extends beyond an organization’s own systems and security controls. Vendors, cloud services, open-source components, software dependencies and fourth-party relationships can all provide indirect paths for attackers, while a compromise at one widely used provider can affect numerous downstream organizations.
The data also highlights persistent challenges in supplier visibility, vulnerability remediation, malicious package detection, third-party assessments, and incident disclosure. As organizations expand their digital ecosystems, effective supply chain security will increasingly depend on understanding which external services and components they rely on and how those dependencies change over time.
For organizations in the U.S. and globally, reducing exposure requires stronger supplier oversight, faster vulnerability remediation, better software component visibility, and continuous monitoring of critical third-party relationships. These measures cannot eliminate supply chain cyber risk, but they can help organizations identify weaknesses earlier, limit downstream exposure, and respond more effectively when a supplier or software dependency is compromised.