Third parties are in 48% of breaches. Ninety percent of leaders think they would be fine.
Breaches involving a third party rose 60% in a year to nearly half the total. Over the same window 86% of leaders reported concern, 90% stayed confident of seamless continuity, and 78% admitted covering less than half their vendor ecosystem.
- Published
- June 23, 2026
- Period covered
- April 1, 2026 – June 30, 2026
- Documentary cut-off
- June 23, 2026
Executive perspective
Six conclusions that matter for the year ahead
The third-party trend line is now the steepest in the series
15%, 30%, 35.5%, 48% across successive measurements. We forecast above 40% in March with medium-high confidence and the outcome exceeded it. At 48%, the next breach your organisation suffers is about as likely to involve someone else's failure as your own, while security programmes remain scoped to your own estate.
Vulnerability exploitation doubled and patching got worse
Exploitation reached 32% of breaches, double the prior all-time high. Over the same period the share of organisations that had fully remediated the known-exploited vulnerabilities present in their environment fell from 38% to 26%. The shortest, highest-confidence list in existence, and performance on it is going backwards.
Email phishing has effectively exited the top tier of initial access
Mandiant recorded it at 6% of 2025 intrusions, down from 14%, no longer a top vector. Exploits led for the sixth consecutive year at 32%. Awareness training addresses a vector that has more than halved in two years while the budget allocation has not moved with it.
Internal detection improved materially, and we should say so
52% of organisations detected malicious activity themselves in 2025, against 43% the previous year. In June 2025 we called visibility the binding constraint. It has moved in the right direction faster than we expected, and it is the first clearly positive capability movement across six editions.
Supplier remediation is the weak link, and now it is measured
Only 23% of third-party organisations fully remediated missing or improperly secured multifactor authentication on cloud accounts, though half of all findings were resolved within a month. The problem is not that suppliers never fix things. It is that they never finish, and a questionnaire cannot see a 23% completion rate behind a truthful yes.
Extortion has stabilised at a lower level while shifting its composition
Extortion-related intrusions were 23% of Mandiant's 2025 caseload, of which ransomware deployment accounted for 13%. Monetisation appeared in 30% of investigations, down from 35%. The category continues to move away from encryption and toward theft.
The quarter in numbers
48%
Breaches with third-party involvement
Up 60% year over year, from 15% two years ago. The steepest sustained trend anywhere in this series.
32%
Breaches involving exploitation of vulnerabilities
Double the previous all-time high, now level with stolen credentials at 36%. The method that grew needs no identity at all.
26%
Organisations fully remediating known-exploited vulnerabilities
Down from 38%. Partial remediation is the norm, and a partially patched known-exploited flaw is unpatched from the adversary's side.
6%
Email phishing as an initial intrusion vector
Down from 14% in 2024 and no longer a top vector. Exploits, stolen credentials and prior compromise replaced it.
52%
Organisations detecting malicious activity internally
Up from 43%. Real, measurable improvement in the visibility gap we flagged a year ago.
23%
Third parties fully remediating cloud MFA gaps
Half of findings were resolved within a month, but only a quarter were finished. An adversary needs one that was not.
90%
Leaders confident of seamless continuity through a supplier incident
Against 86% expressing concern and 78% covering less than half their ecosystem. Confidence calculated on the wrong denominator.
55%
Organisations still coordinating with vendors by phone and email during incidents
With 46% relying on monthly or quarterly monitoring. The operational reality behind the confidence.
The board agenda
Five questions your board should be able to answer this quarter
They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.
What percentage of our vendor ecosystem is under any form of monitoring?
78% of organisations cover less than half.
Of the findings we raise with suppliers, what proportion are fully closed rather than acknowledged?
23% full remediation on a simple control.
What share of the known-exploited vulnerabilities in our environment are fully remediated?
Industry figure fell from 38% to 26%.
Would we detect our next intrusion ourselves, and when did we last test that?
52% detect internally.
Does our security spending resemble a world where phishing is 6% and exploitation is 32%?
It probably does not.
Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?
The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.
What the full edition adds
- What changed this quarter, and what only looks new
- Trend radar: direction, maturity and business impact
- The FortaRisks point of view, four convictions
- Looking ahead, next 3 to 6 months, with confidence levels
- The threat landscape, developments in detail
- Sector exposure, with OT and manufacturing broken out
- Prioritised recommendations, by theme and by risk addressed
- The prioritised action answering each question above, plus the source base and method
16 pages · 25 sources · immediate download, no wait
How this edition was built
This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. It scores the five forecasts made in March: two materialised, three unresolved. It also corrects a comparability error we should have flagged a year ago about ransom payment figures, which are recomposed each year and are not a continuous series.
Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.
See where your organisation sits on these numbers
The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.