Supply Chain Attacks


How One Vendor Becomes Many Victims

The defining supply chain problem of 2026 was that trusted systems became attack paths.


An organization could run a disciplined security program, patch on schedule, train its people, and still wake up to an extortion email, because the breach happened somewhere it never controlled. For many of the year's most visible incidents, the customer's core environment was not the clean boundary of the incident. Data, access, and leverage moved through the systems organizations rely on to operate: SaaS integrations, ERP applications, customer service platforms, OAuth tokens, and third party applications connected to high value business data. In that model, the vendor's identity, application permissions, and software exposure become part of the customer's ransomware surface.

How Trusted Vendor Relationships Become Attack Paths

The SaaS Trust Chain: Salesforce and the OAuth Problem


Salesforce made that shift visible. The Salesloft Drift campaign was not a traditional perimeter compromise of each affected customer. Public reporting tied the activity to compromised OAuth tokens associated with the Salesloft Drift third-party application, which were used to access Salesforce customer instances. The actor exported large volumes of Salesforce data and searched it for secrets such as AWS access keys, passwords, and Snowflake-related access tokens.

Gainsight showed the same trust problem from a different angle. Salesforce detected unusual activity involving Gainsight published applications and said the activity may have enabled unauthorized access to certain customers' Salesforce data through the applications' connection. Salesforce disabled the connection between Gainsight published applications and Salesforce on November 20, 2025.

The lesson is that SaaS ecosystems depend on chains of delegated trust, and any link in that chain can become the entry point. OAuth tokens, connected applications, AppExchange integrations, support platforms, and customer success tools can all sit close to sensitive customer data. When one link in that chain is abused, the customer experiences the breach even if the initial weakness sits somewhere else.

Black Kite's FocusTag® signals flag specific products and technologies carrying active, named vulnerabilities, giving security teams a targeted view of which third-party software surfaces are most exposed at any given time. In the current victim population, this layer shows why the supply chain story does not end with the incident. In the latest analysis of ransomware victims, Salesforce Aura and Salesforce Client were among the most visible CRM related signals in the dataset. These signals show that CRM and SaaS related exposure remains visible within the same victim population examined during a year shaped by SaaS and vendor-driven incidents. The full signal breakdown appears in Chapter 10.

Different actors, different platforms, one pattern. The target was the key, held by a vendor, trusted by design.

Enterprise Applications at Scale: The Oracle EBS Campaign

Oracle EBS showed the other side of the supply chain surface: enterprise application exploitation at scale. In Black Kite’s ransomware tracking, the Oracle EBS campaign fit the same high-impact operational model seen in Accellion, GoAnywhere, MOVEit, and Cleo: one platform, one vulnerability, and many organizations exposed at once.

The campaign involved claims of sensitive data theft from Oracle EBS environments and followed months of intrusion activity against customer environments. Public technical reporting tied the activity to possible exploitation of CVE-2025-61882 as a zero-day before a patch was available. For defenders, the lesson was straightforward: when a widely used enterprise application becomes the access path, the blast radius can extend far beyond a single breached organization.

The Pattern Continues: PeopleSoft

PeopleSoft extended that pattern into the post-period pulse. Google and Mandiant later identified an active compromise and extortion campaign attributed to UNC6240, also known as ShinyHunters, targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27 and June 9, 2026 and was consistent with exploitation of CVE-2026-35273, a critical remote code execution vulnerability. Because the activity preceded Oracle's June 10 advisory, Google assessed that the vulnerability was exploited as a zero-day. This should be treated as post-period context, not part of the primary 7,551 victim dataset.

Qantas is the cleanest short example of the same boundary problem. The airline said the incident involved unusual activity on a third party platform used by a Qantas airline contact centre, while Qantas systems remained secure. In other words, the customer data boundary sat outside the company's core systems.

The Supply Chain Lesson


Together, these cases explain why supply chain exposure became one of the year's defining ransomware pressures. The major incidents centered on the systems around breached companies: the vendor platform, the SaaS integration, the ERP application, the OAuth token, the support workflow, and the data store that customers depend on but do not fully control. An organization cannot directly patch a vulnerability it does not own, in a platform it does not run, exposed through a vendor relationship it does not fully control.

A vendor's exposed identity, SaaS access, and application surface can become the customer's attack path.

Next: Knowing who is most likely to be targeted next is where prevention begins.

Black Kite's Ransomware Susceptibility Index® was built to answer that question.

PREVIOUS
NEXT