Hackers are attacking businesses through their trusted tech suppliers

Companies can spend millions securing their own networks, but attackers are increasingly finding another way in: the technology providers and vendors businesses already trust.

A new report from Databarracks found that 26 percent of organizations experienced a cyber incident originating from a supplier or third party during the past year.

The finding highlights a growing problem for businesses that depend on outside companies for everything from software and cloud services to infrastructure and managed IT.

The concerning part is that many organizations know they have supplier security risks but continue working with those vendors anyway.

Nearly half of organizations surveyed, 48 percent, said they continued working with suppliers despite known security or resilience concerns.

The reason is simple: replacing a critical supplier is not always easy. Twenty-six percent of respondents said dependence on suppliers was a major barrier to improving resilience.

For attackers, this creates an opportunity. Instead of trying to break through a heavily protected corporate network, they can target a weaker company that already has access.

The security problem companies cannot ignore

The Databarracks Data Health Check 2026 report surveyed 500 IT decision-makers about cybersecurity, resilience, and disaster recovery.

Most companies are not ignoring supplier security completely. Nine out of ten organizations assess supplier resilience when onboarding vendors, and many continue reviewing suppliers afterward.

The challenge is that modern supply chains are complicated. A business may know the primary vendors it works with, but it may have less visibility into the companies connected behind those vendors.

Security questionnaires and compliance checks can help, but they do not always reveal how prepared a supplier really is when something goes wrong.

“When something goes wrong at a key supplier, the cascade effects can be profound for businesses throughout the chain,” said Chris Butler, Resilience Director at Databarracks.

That risk is becoming more important as cyber threats continue to grow.

Cyber attacks remain a major business threat

Supply chain attacks are only one part of a larger cybersecurity challenge.

The report found that cyber incidents remain the leading cause of downtime for organizations, with 30 percent identifying cyber as their biggest source of disruption.

Ransomware also continues to hit businesses. One in four organizations experienced a ransomware attack during the last 12 months.

However, more companies are refusing to pay attackers. Among ransomware victims, 59 percent recovered from backups instead of paying the ransom, while only 18 percent paid attackers.

The rise of artificial intelligence is adding another challenge. Databarracks found AI-driven cyber attacks more than doubled in frequency over the past year.

At the same time, many organizations see AI as a useful security tool. Seventy-nine percent said they believe AI is more of a security benefit than a threat.

Trusting vendors means trusting their security

Businesses have always depended on outside companies, but technology has made those relationships much deeper. A single vendor can have access to sensitive data, internal systems, or critical operations.

That means cybersecurity is no longer just about protecting your own servers and employees. It also means understanding who has access to your systems and whether those companies are prepared for an attack.

A business might have strong defenses, but if a trusted technology supplier gets compromised, attackers may still find a way inside.

Support independent tech journalism

NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.

Support NERDS.xyz
Avatar of Brian Fagioli
Written by

Brian Fagioli

Technology journalist and founder of NERDS.xyz

Brian Fagioli is a technology journalist and founder of NERDS.xyz. A former BetaNews writer, he has spent over a decade covering Linux, hardware, software, cybersecurity, and AI with a no nonsense approach for real nerds.

Leave a Comment