Skip to content
FortaRisks
All quarterly reports
Q4 2025

Two pieces of software caused 63.5% of vulnerability-based breaches. That is the year's real finding.

In March we argued that third-party risk has two shapes, weakness and concentration, and that assurance only addresses the first. This is the second shape, measured, and it is larger than we expected.

Published
December 16, 2025
Period covered
October 1, 2025December 31, 2025
Documentary cut-off
December 16, 2025

Executive perspective

Six conclusions that close the first year

  1. The third party is now the primary attack path, not a secondary one

    35.5% of all breaches in 2024 originated from a third-party compromise, up 6.5 percentage points year over year, and the researchers call the figure conservative. More pointedly, 41.4% of ransomware attacks now begin through a third party. The supply chain is not a parallel risk to ransomware; it is the majority route into it.

  2. Concentration, not supplier weakness, produced the year's largest single effect

    Two file transfer products accounted for 63.5% of vulnerability-based breaches. No questionnaire, audit or certification would have changed that outcome for any affected organisation, because the failure was not in their supplier's diligence. It was in everyone depending on the same software at once.

  3. Exfiltration has become the default, not a variant

    Microsoft observed data collection in 80% of reactive engagements. In September we forecast that theft-only extortion would become the majority case. It is now the norm across incidents generally, whether extortion follows or not. The question has inverted: not whether an intrusion involved data theft, but whether you can establish that it did not.

  4. The most basic identity attack still works, because the most basic control is still missing

    More than 97% of identity attacks are password spray or brute force, and modern multifactor authentication blocks over 99% of unauthorised access attempts. The gap between those two numbers is not a technology problem. It is a deployment problem, and closing it remains the highest-yield action available to most mid-market organisations.

  5. Cloud is now a destruction target, not only a theft target

    Microsoft recorded an 87% increase in campaigns aimed at disrupting Azure customer environments. A destroyed cloud tenancy does not produce a disclosure event; it produces an outage the organisation cannot resolve from its own datacentre, because there is no datacentre.

  6. Regional readings diverge sharply, and the divergence is informative

    ENISA reports phishing as the dominant EU intrusion vector at 60%, while global breach telemetry shows phishing declining for three years. Both are correct: ENISA counts recorded incidents dominated by public administration and hacktivist denial of service, global telemetry counts confirmed breaches. Adopt EU control frameworks; do not import EU threat priorities unadjusted.

The quarter in numbers

  • 63.5%

    Vulnerability-based breaches caused by just two file transfer exploits

    The clearest measurement of concentration risk we have seen. Diligence on your own suppliers would not have helped.

  • 35.5%

    Breaches originating from a third party, up 6.5 points

    Described as a conservative count. Resolves a question we carried for two quarters, and exceeded the 30% we forecast.

  • 41.4%

    Ransomware attacks that start through a third party

    Two in five. Most organisations run ransomware and third-party risk as separate programmes with separate owners.

  • 80%

    Reactive engagements showing data collection

    Exfiltration has stopped being a variant of intrusion and become a feature of it. Every incident is now a potential disclosure event.

  • 97%

    Identity attacks that are password spray or brute force

    Against multifactor authentication that blocks over 99% of unauthorised access. The dominant attack is one a deployed control already defeats.

  • +87%

    Campaigns aimed at disrupting cloud customer environments

    Cloud became a destruction target. Continuity plans that treat the cloud as the resilient tier were written for hardware failure.

  • 4.5%

    Breaches that extend to a fourth party

    One supplier failure propagating through two contractual layers. The dependency graph is deeper than the register.

  • 52.4%

    Third-party breach rate in retail and hospitality

    Energy and utilities follow at 46.7%. Over half of one sector's breaches now arrive through somebody else.

The board agenda

Five questions your board should be able to answer this quarter

They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.

  1. What software do our suppliers have in common, and which single product could reach us through more than one of them?

    Two exploits, 63.5% of vulnerability-based breaches.

  2. Who owns the overlap between our ransomware plan and our third-party programme?

    41.4% of ransomware starts with a supplier.

  3. How many accounts still lack multifactor authentication, and what is the date?

    97% of identity attacks are spray or brute force.

  4. If our cloud tenancy were deliberately destroyed rather than breached, what is the plan?

    Cloud disruption campaigns up 87%.

  5. Do we have a procedure for notifying regulators and customers about a breach that happened at a supplier?

    35.5% of breaches originate with a third party.

Full edition

Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?

The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.

What the full edition adds

  • What changed this quarter, and what only looks new
  • Trend radar: direction, maturity and business impact
  • The FortaRisks point of view, four convictions
  • Looking ahead, next 3 to 6 months, with confidence levels
  • The threat landscape, developments in detail
  • Sector exposure, with OT and manufacturing broken out
  • Prioritised recommendations, by theme and by risk addressed
  • The prioritised action answering each question above, plus the source base and method

16 pages · 19 sources · immediate download, no wait

Your address tells us who is reading. No list, no sequence, no sharing with anyone.

How this edition was built

This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. It closes the first full year of the series and scores every forecast issued: fourteen made, seven materialised, two partially, five unresolved or not yet evidenced. We publish the denominator as well as the numerator.

Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.

See where your organisation sits on these numbers

The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.