Two pieces of software caused 63.5% of vulnerability-based breaches. That is the year's real finding.
In March we argued that third-party risk has two shapes, weakness and concentration, and that assurance only addresses the first. This is the second shape, measured, and it is larger than we expected.
- Published
- December 16, 2025
- Period covered
- October 1, 2025 – December 31, 2025
- Documentary cut-off
- December 16, 2025
Executive perspective
Six conclusions that close the first year
The third party is now the primary attack path, not a secondary one
35.5% of all breaches in 2024 originated from a third-party compromise, up 6.5 percentage points year over year, and the researchers call the figure conservative. More pointedly, 41.4% of ransomware attacks now begin through a third party. The supply chain is not a parallel risk to ransomware; it is the majority route into it.
Concentration, not supplier weakness, produced the year's largest single effect
Two file transfer products accounted for 63.5% of vulnerability-based breaches. No questionnaire, audit or certification would have changed that outcome for any affected organisation, because the failure was not in their supplier's diligence. It was in everyone depending on the same software at once.
Exfiltration has become the default, not a variant
Microsoft observed data collection in 80% of reactive engagements. In September we forecast that theft-only extortion would become the majority case. It is now the norm across incidents generally, whether extortion follows or not. The question has inverted: not whether an intrusion involved data theft, but whether you can establish that it did not.
The most basic identity attack still works, because the most basic control is still missing
More than 97% of identity attacks are password spray or brute force, and modern multifactor authentication blocks over 99% of unauthorised access attempts. The gap between those two numbers is not a technology problem. It is a deployment problem, and closing it remains the highest-yield action available to most mid-market organisations.
Cloud is now a destruction target, not only a theft target
Microsoft recorded an 87% increase in campaigns aimed at disrupting Azure customer environments. A destroyed cloud tenancy does not produce a disclosure event; it produces an outage the organisation cannot resolve from its own datacentre, because there is no datacentre.
Regional readings diverge sharply, and the divergence is informative
ENISA reports phishing as the dominant EU intrusion vector at 60%, while global breach telemetry shows phishing declining for three years. Both are correct: ENISA counts recorded incidents dominated by public administration and hacktivist denial of service, global telemetry counts confirmed breaches. Adopt EU control frameworks; do not import EU threat priorities unadjusted.
The quarter in numbers
63.5%
Vulnerability-based breaches caused by just two file transfer exploits
The clearest measurement of concentration risk we have seen. Diligence on your own suppliers would not have helped.
35.5%
Breaches originating from a third party, up 6.5 points
Described as a conservative count. Resolves a question we carried for two quarters, and exceeded the 30% we forecast.
41.4%
Ransomware attacks that start through a third party
Two in five. Most organisations run ransomware and third-party risk as separate programmes with separate owners.
80%
Reactive engagements showing data collection
Exfiltration has stopped being a variant of intrusion and become a feature of it. Every incident is now a potential disclosure event.
97%
Identity attacks that are password spray or brute force
Against multifactor authentication that blocks over 99% of unauthorised access. The dominant attack is one a deployed control already defeats.
+87%
Campaigns aimed at disrupting cloud customer environments
Cloud became a destruction target. Continuity plans that treat the cloud as the resilient tier were written for hardware failure.
4.5%
Breaches that extend to a fourth party
One supplier failure propagating through two contractual layers. The dependency graph is deeper than the register.
52.4%
Third-party breach rate in retail and hospitality
Energy and utilities follow at 46.7%. Over half of one sector's breaches now arrive through somebody else.
The board agenda
Five questions your board should be able to answer this quarter
They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.
What software do our suppliers have in common, and which single product could reach us through more than one of them?
Two exploits, 63.5% of vulnerability-based breaches.
Who owns the overlap between our ransomware plan and our third-party programme?
41.4% of ransomware starts with a supplier.
How many accounts still lack multifactor authentication, and what is the date?
97% of identity attacks are spray or brute force.
If our cloud tenancy were deliberately destroyed rather than breached, what is the plan?
Cloud disruption campaigns up 87%.
Do we have a procedure for notifying regulators and customers about a breach that happened at a supplier?
35.5% of breaches originate with a third party.
Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?
The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.
What the full edition adds
- What changed this quarter, and what only looks new
- Trend radar: direction, maturity and business impact
- The FortaRisks point of view, four convictions
- Looking ahead, next 3 to 6 months, with confidence levels
- The threat landscape, developments in detail
- Sector exposure, with OT and manufacturing broken out
- Prioritised recommendations, by theme and by risk addressed
- The prioritised action answering each question above, plus the source base and method
16 pages · 19 sources · immediate download, no wait
How this edition was built
This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. It closes the first full year of the series and scores every forecast issued: fourteen made, seven materialised, two partially, five unresolved or not yet evidenced. We publish the denominator as well as the numerator.
Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.
See where your organisation sits on these numbers
The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.