Black Kite Third Party Breach Report 2024
Zero-Days Turned 81 Vendor Breaches Into 251 Downstream Victims in 2023
81 vendor compromises reached 251 companies in 2023. That ratio, 3.1 victims per breach, understates what happened. When a single file-transfer vulnerability cascaded through the National Student Clearinghouse to 890 schools, the multiplier reached 14.1. One vendor. One unpatched flaw. Fourteen times the collateral damage.
The Black Kite Research Group™ analyzed every documented third-party data breach in 2023 to produce the fifth annual Third-Party Breach Report. Sources included cybersecurity news platforms, dark web forums, Telegram channels, and intelligence proprietary to Black Kite. The analysis covers 81 distinct vendor-originating incidents and the 251 companies pulled into the fallout. Where a single education-sector incident expanded the victim count to 1,150, the report accounts for that scope without letting it distort the trend data.
Unauthorized network access drove 53.8% of all third-party breaches, up 26% from 2022. Ransomware accounted for 28.5%. Software vulnerabilities, led by MOVEit and GoAnywhere zero-days exploited at scale by the CL0P group, produced some of the year's most destructive cascading events. The healthcare sector absorbed 38.7% of all victim-company incidents. Technical services vendors were the source of breaches for the fourth consecutive year. For the first time since 2021, breach disclosure timelines shortened: companies reported incidents in 76 days on average, down from 108 days in 2022.
This report is your blueprint for building a third-party risk management program that closes the gap between how fast attackers move and how fast your team sees the threat.
Key Findings From the 2024 Black Kite Third-Party Breach Report
81 Vendor Breaches · 251 Downstream Victims in 2023
Eighty-one vendor-originating incidents produced 251 cascading breaches in 2023, compared to 63 vendor incidents and 298 affected companies in 2022. The raw victim count fell, but the nature of the events grew more complex. A single MOVEit exploitation chain pulled 890 schools into a single breach via the National Student Clearinghouse. The average revenue of companies affected by MOVEit-related incidents exceeded $27.96 billion. Scale, not frequency, defined 2023.
53.8% of Breaches Traced to Unauthorized Network Access — A 26% Spike From 2022
Unauthorized network access has led third-party breach disclosures for three consecutive years. In 2023 it accounted for 53.8% of all incidents, a 26% year-over-year increase. The concentration among companies with revenues above $6.10 billion was especially pronounced. This pattern reflects two compounding realities: attackers are getting better at exploiting network gaps, and organizations are often disclosing breaches without fully understanding the initial entry point.
40% of 2023 Third-Party Victims Were Downstream of CL0P's MOVEit and GoAnywhere Campaigns
The CL0P ransomware group's exploitation of zero-day vulnerabilities in MOVEit and GoAnywhere drove an outsized share of 2023 damage. 40% of companies that suffered a vendor-caused breach were indirectly caught in CL0P's mass exploitation campaigns. These were not targeted attacks. They were opportunistic sweeps through shared infrastructure, and they showed exactly how software supply chain risk propagates when a single tool is embedded across thousands of organizations.
Healthcare Absorbed 38.7% of All Victim Incidents — For the Fifth Consecutive Year
The healthcare sector's position as the leading victim industry is not a coincidence. Regulated data, aging infrastructure, and deep reliance on third-party clinical and administrative vendors make it a reliable target. At least 141 hospitals were directly affected by ransomware attacks on 46 hospital systems in 2023. The average cost of a healthcare data breach reached a record $11 million. Perry Johnson & Associates alone exposed records belonging to 8.95 million patients.
Technical Services Vendors Sourced 35% of Incidents. 60% Improved Their Cyber Ratings Post-Breach
Technical services vendors were the most breached vendor category for the fourth year running, representing approximately 35% of incidents. The notable counterpoint: 60% of breached technical services vendors improved their cyber ratings by more than 11 points following the incident. The second-largest improver group was healthcare services vendors, at 20%. Recovery is possible. The question is whether organizations can identify high-risk vendors before the breach rather than monitoring improvement after the fact.
76 Days — Breach Disclosure Timelines Dropped 30% From 2022
Vendors disclosed breaches in 76 days on average in 2023, compared to 108 days in 2022. Black Kite has tracked this statistic since 2021, and 2023 marks the first year the trend moved in the right direction. The drivers include advances in threat detection, AI-assisted anomaly identification, and regulatory pressure that has raised the cost of slow disclosure.
The caveat: CL0P and comparable groups moved faster than disclosure timelines. Detection improved, but attacker velocity improved more.
183 of 251 Victim Companies Were Headquartered in the United States
US-domiciled companies represented the majority of breach victims, a pattern consistent across every year of this report series. The US concentration reflects a combination of digital asset density, cloud adoption, financial scale, and mandatory breach reporting requirements that surface incidents which go unreported in other markets.
Key Stats from the Report:
- 81 vendor incidents – 251 downstream victims in 2023
- 53.8% of breaches caused by unauthorized network access
- 26% increase in unauthorized network access breaches vs. 2022
- 40% of 2023 victims were downstream of CL0P's MOVEit/GoAnywhere campaigns
- 38.7% of victim companies were in healthcare
- 141 hospitals directly affected by ransomware in 2023
- $11M average cost of a healthcare data breach — record high
- 76-day average breach disclosure window — down from 108 days in 2022
What's Inside the 2024 Black Kite Third-Party Breach Report
The Evolution of Third-Party Data Breaches
Examines the shift from 2022 to 2023 in breach volume, victim spread, and attacker strategy. It positions the CL0P group's exploitation campaigns as a turning point in how ransomware threats intersect with vendor ecosystems.
The Root Causes of Breaches
Provides a category-level breakdown of the six primary breach vectors observed in 2023, including unauthorized network access, ransomware, software vulnerabilities, unsecured servers, unauthorized persons, and unclassified causes. Each category is quantified and traced to specific incident patterns.
The Most Affected Industries
Covers how healthcare, finance and insurance, manufacturing, education, and technical services absorbed disproportionate impact in 2023. Sector-specific data explains why each industry's vendor relationships created concentrated exposure.
Most Destructive Third-Party Breaches of 2023
Reconstructs the five incidents that defined the year's threat landscape:
- Perry Johnson & Associates (8.95 million patients)
- ESO Solutions (2.7 million individuals)
- Okta (all customer support system users affected)
- Credit Control Corporation breach
- MOVEit breach through PBI
Each case examines what happened, how it cascaded, and what it revealed about vendor risk monitoring gaps.
The Aftermath of a Cyber Attack
Tracks how breached vendors changed their cyber risk ratings in the months following disclosure. The data shows a broad distribution: some vendors improved substantially, others declined. The section examines what predicts recovery and what signals ongoing risk.
Lessons Learned
Four actionable conclusions from the 2023 data, including the domino effect of shared software vendors, the speed advantage attackers hold over disclosure timelines, and the cybersecurity cost of misallocated AI investment budgets.
Key Recommendations From the 2024 Third-Party Breach Report
Map Your Exposure to Shared Infrastructure Before CL0P Does It for You
The MOVEit and GoAnywhere campaigns demonstrated that a single vendor's technology stack can create concentration risk at industry scale. Organizations that knew which of their vendors used these tools before May 2023 had hours to act. Those without nth-party visibility found out through breach disclosures weeks later. Map shared technology dependencies across your vendor ecosystem now. Do not wait for a CVE to begin that inventory.
Treat Unauthorized Network Access as an Undisclosed Attack Vector
When 53.8% of breach disclosures cite unauthorized network access as the cause, and when the specific entry technique is left unspecified in the majority of those disclosures, the term functions as a placeholder, not an explanation. Build your vendor risk assessments to probe network access controls specifically, including authentication mechanisms, VPN configurations, and privileged access management posture. A vague disclosure does not mean a simple breach.
Replace Point-in-Time Assessments With Continuous Monitoring for High-Risk Vendors
The average breach disclosure took 76 days in 2023. CL0P exploited MOVEit within hours of the vulnerability becoming public. The gap between those two timelines cannot be closed by an annual questionnaire. Continuous monitoring tracks changes in vendor cyber posture in real time, surfaces FocusTags® as high-profile events emerge, and gives risk teams the signal they need before a breach becomes a headline.
Enforce Vendor-Specific Risk Thresholds for Healthcare and Finance Relationships
Healthcare vendors accounted for the largest share of victim companies for the fifth consecutive year. Financial services companies saw customers affected in numbers ranging from 10,000 to 37 million per incident. Both sectors carry outsized regulatory and reputational consequences when a vendor fails. Apply higher scrutiny thresholds during vendor evaluation, require documented patch management processes, and set monitoring triggers that fire on any change to a vendor's ransomware susceptibility profile — tracked through the Ransomware Susceptibility Index® (RSI™).
Shift Vendor Improvement Tracking Into Your Ongoing Risk Program
Forty percent of vendors increased their cyber scores following an attack. That signal has value, but only if you are watching closely. Post-breach cyber rating improvement is one indicator of vendor resilience, but organizations that monitor only after an incident miss the proactive posture data available before one. Integrate cyber risk intelligence feeds into your vendor lifecycle so improvement and deterioration are both visible in real time.
Pair Breach Response Workflows With Vendor Engagement Protocols
The Okta breach in late 2023 affected all customer support system users and required coordinated outreach across the entire customer base. Organizations that had pre-built vendor risk response playbooks moved faster. Those without them improvised. Build the response workflow before you need it: define notification thresholds, assign remediation owners, and connect your breach response process to your vendor engagement infrastructure.
Methodology: 81 Incidents Analyzed Across Public and Proprietary Sources
The Black Kite Research Group™ gathered data from cybersecurity news platforms, dark web forums, Telegram channels, and sources exclusive to the Black Kite platform. Each incident was curated and reviewed by human analysts before inclusion. The dataset covers 81 distinct third-party incidents from calendar year 2023, resulting in 251 documented downstream victims. Where a single vendor incident cascaded to 890 educational institutions through the National Student Clearinghouse, those institutions are counted as a single victim in trend calculations to prevent statistical distortion.
Because third-party breach disclosure is uneven across jurisdictions and industries, figures represent a documented sample rather than a total count of all incidents. US regulatory disclosure requirements produce higher visibility into US-domiciled victim companies, which is reflected in the geographic distribution.
Who Should Read This Third-Party Breach Report
CISOs and risk leaders building or maturing a third-party risk management program will find the sector-by-sector data and root-cause breakdowns directly applicable to their vendor prioritization decisions.
Procurement and vendor management teams will find the Most Destructive Breaches section valuable for understanding what vendor failure looks like operationally and what contractual and monitoring controls could have changed the outcome.
Healthcare security professionals, financial services risk officers, and technical services vendors will each find sector-specific findings that apply directly to their threat environment.