Verizon Business has unveiled its 2025 Data Breach Investigations Report (DBIR), shedding light on a troubling surge in cyberattacks where third-party entities are directly involved. These breaches have surged, now accounting for 30% of all incidents—a stark rise in just one year. This evolving trend presents formidable challenges for businesses worldwide.
The report highlights how cybercriminals are capitalizing on vulnerabilities within the supply chain, infiltrating multiple victims through a single breach point. This strategy allows attackers to maximize their reach while minimizing effort, intensifying the threat landscape.
Examining over 22,000 security events, including 12,195 confirmed data breaches, Verizon’s research reveals a disturbing 34% uptick in attacks leveraging exploited vulnerabilities as the entry point, now representing 20% of all incidents. This surge underscores the growing sophistication of cybercriminals, who are identifying and exploiting weaknesses before patches and defenses can be put in place.
A worrying pattern has emerged where attackers combine credential abuse—seen in 22% of incidents—with vulnerability exploitation, creating multi-layered attack chains that are increasingly difficult to detect. These sophisticated approaches allow threat actors to maintain unauthorized access, posing as legitimate users within compromised networks and evading detection for long periods.
Social engineering remains a key factor in successful attacks. Phishing campaigns targeting specific employees with access to critical systems are the preferred method of initial breach. The tactics used by cybercriminals reveal an alarming degree of planning and targeted execution, showing that attackers are more patient and strategic than ever.
Small and medium-sized businesses (SMBs) are particularly vulnerable, with ransomware being present in 88% of breaches affecting these organizations. Despite enhanced security awareness and increased investments, many SMBs lack the resources for robust cybersecurity, with the median ransom payment reaching $115,000—making these businesses prime targets.
The exploitation techniques observed in these third-party attacks showcase advanced reconnaissance and execution tactics. Cybercriminals begin by scanning partner networks for unpatched vulnerabilities, particularly targeting internet-facing applications and services. Once these vulnerabilities are discovered, they serve as a foothold for deeper network penetration.
The attack process typically follows a sequence: scanning, identifying weaknesses, exploiting vulnerabilities, moving laterally within the network, and exfiltrating data. In the most alarming cases, zero-day vulnerabilities—those with no available patches—are leveraged, allowing attackers to persist for an average of 187 days before being detected.
Exploitation often involves specially crafted HTTP requests designed to exploit memory management flaws in vulnerable web applications. These requests allow attackers to execute arbitrary code on the system, establishing a connection with command-and-control infrastructure, often using encrypted communications to evade detection.
Chris Novak, Vice President of Global Cybersecurity Solutions at Verizon Business, noted, “The growth of third-party integrations has greatly expanded the attack surface, a challenge that many organizations fail to properly address. Every external connection is a potential entry point that bypasses traditional security perimeters.”
To counter these evolving threats, Verizon stresses the need for robust third-party risk management programs. This includes vendor security assessments, continuous monitoring, and adopting zero-trust security frameworks. As supply chain attacks continue to rise, businesses must rethink their cybersecurity strategies and adopt comprehensive, multi-layered defense systems that address both technical vulnerabilities and human factors.
The Verizon 2025 DBIR is a stark reminder that businesses must urgently reassess their approach to third-party security. With cybercriminals continuing to refine their tactics and focusing more on supply chain vulnerabilities, companies must prioritize a holistic, proactive security approach that includes regular vulnerability assessments, rapid patching, employee training, and increased visibility into third-party connections. Only by adopting these strategies can organizations effectively navigate the increasingly complex and dangerous cyber threat landscape.




