The biggest data breaches of the decade share a root cause: no MFA, stale credentials, and unpatched systems attackers found before your IT team did.
Written by
Trio Content Team
Published on
30 Sep 2025
Modified on
07 Oct 2026
U.S. organizations reported a record 3,322 data breaches in 2025, and the numbers keep climbing. The biggest data breaches making those headlines were not freak accidents or acts of unstoppable sophistication. They were the result of specific, identifiable failures that investigators documented in detail after the fact.
The biggest data breaches in the last 5 years cluster around a surprisingly short list of root causes: missing MFA on remote access systems, unpatched vulnerabilities, reused or stolen credentials, and third-party accounts nobody was watching. These failures appear in government-linked incidents and Fortune 500 companies with the same regularity.
The financial damage from a major data breach makes the case for prevention bluntly. IBM's 2025 Cost of a Data Breach Report puts the global average at $4.88 million per incident and the U.S. average at $10.22 million, both figures from the same study. That covers only direct costs: regulatory fines, class action settlements, and reputational damage stack on top.
This article breaks down 15 of the most consequential breaches of the 2020s, identifies the root cause behind each one, covers the regulatory and financial fallout, and maps the controls that could have changed the outcome.
TL;DR
The biggest data breaches of the 2020s — from Change Healthcare to AT&T to Medibank — were almost universally caused by missing MFA, unpatched systems, or unguarded third-party access.
The average U.S. data breach now costs $10.22 million (IBM 2025), and regulatory fines can add tens or hundreds of millions on top of that.
Human error contributed to 95% of 2024 breaches (Mimecast/Infosecurity Magazine) — but most of those errors are preventable with the right access controls and automated policy enforcement.
Third-party and supply chain involvement in breaches doubled from 15% to 30% in a single year (Verizon 2025 DBIR).
Shadow SaaS and AI applications employees install without IT approval are now among the fastest-growing breach vectors, according to the Verizon 2025 DBIR.
Device management, access control policies, and encryption enforcement are among the most effective technical controls organizations can put in place today.
What Counts as a Data Breach (and Why the Definition Matters)
If you already understand how data breaches are classified and reported, jump ahead to the breach breakdown. For everyone else: a data breach is unauthorized access to or disclosure of sensitive data, whether that access came from an external attacker, a malicious insider, or an accidental misconfiguration.
That last category is where people sometimes get confused. Some of the biggest data leaks on record — like Optus's open API endpoint or Facebook's phone number lookup vulnerability — did not involve an attacker breaking through a firewall. The data was simply accessible. Accidental data breach examples like these are sometimes called "data leaks" when no active intrusion occurred, but the regulatory treatment is nearly identical. GDPR requires notification to data protection authorities within 72 hours regardless of whether the exposure was intentional.
The practical implication: your compliance obligations don't hinge on whether someone malicious was involved. If personal data was exposed — by an attacker, a contractor, or a misconfigured API — regulators expect you to know about it fast and document what controls you had in place. That documentation burden is one reason technical controls and compliance visibility matter far beyond the breach moment itself.
15 of the Biggest Data Breaches of the 2020s, and the Root Causes Behind Each One
Look across the biggest data breaches of the past five years and you'll notice a pattern before you reach the third entry. These biggest security breaches span ransomware, credential theft, supply chain compromise, and accidental exposure, but the entry points repeat. The attack surface is not random. It's predictable, which means it's addressable.
Each entry below covers what happened, the scale of impact, the confirmed root cause, and the key takeaway for organizations trying to avoid the same outcome.
Change Healthcare Ransomware Attack (2024)
What happened: The ALPHV/BlackCat ransomware group accessed a Citrix remote access application using stolen credentials. No MFA was required on that application.
Scale: 6TB of data exfiltrated; approximately 100 million patients' records exposed. Change Healthcare processes roughly 40% of all U.S. medical claims, its nine-day outage cascaded across the entire healthcare system. A second ransomware group, RansomHub, later demanded a second ransom.
Root cause: No MFA on a legacy remote access server, confirmed as a compliance failure by JAMA Health Forum.
Consequence: Costs expected to exceed $1 billion. UnitedHealth paid $2B+ to affected providers. 55% of physicians reported using personal funds during the outage, a direct financial consequence of a single missing security control.
Takeaway: This is one of the biggest data breaches of 2024 and the clearest case study for what missing MFA on a single legacy system can cost an entire industry.
National Public Data Breach (2024)
What happened: A hacking group called USDoD claimed to have stolen data from Jerico Pictures, a background check company operating as National Public Data. The stolen data appeared for sale and was then publicly leaked in April 2024.
Scale: Up to 2.9 billion records claimed; 272 million unique Social Security Numbers confirmed by Malwarebytes. The consequences extended through 2025, making this among the biggest data breaches 2025 continued to deal with.
Root cause: A data aggregator holding enormous volumes of consumer data with inadequate security controls and no direct relationship with the individuals whose data it held.
Consequence: Company filed for bankruptcy. Not subject to CIRCIA as a non-critical infrastructure entity.
Takeaway: Third-party data custodians you've never heard of may hold your customers' data. You cannot audit what you don't know exists.
AT&T Data Breaches (2024)
What happened: Two separate incidents. First, a March 2024 breach exposed 72.5 million customer records. Then, between April and May 2024, the call and text metadata of nearly all AT&T wireless customers was accessed via Snowflake cloud storage using stolen credentials.
Scale: 72.5M+ customers across both incidents. Among the largest cybersecurity breaches in U.S. telecommunications history.
Root cause: Credential theft combined with no MFA enforcement on cloud storage accounts.
Consequence: Ongoing litigation. The Snowflake connection linked this breach to a broader wave of credential-based attacks on cloud infrastructure.
Takeaway: Cloud storage accounts are high-value targets. Credentials alone should never be sufficient for access.
Snowflake-Linked Breaches - Ticketmaster and Santander (2024)
What happened: The ShinyHunters group obtained Snowflake employee credentials and used them to access customer accounts that had no MFA or IP allow-listing configured.
Scale: Ticketmaster — 560 million accounts claimed. Santander — 30 million customers claimed.
Root cause: No MFA on Snowflake accounts and no network-level restrictions. Snowflake subsequently required MFA for all human users, a vendor response that confirms the gap was known to be exploitable.
Takeaway: Platform-level MFA requirements are not a substitute for enforcing them yourself. Don't wait for your vendor to mandate what you should already be requiring.
T-Mobile Breaches (2021 and 2023)
What happened: A 2021 breach exposed 76.6 million subscriber records. A 2023 breach revealed 37 million more. T-Mobile experienced 8 known breaches between 2018 and 2023.
Scale: 113 million+ individuals exposed across the two incidents. Combined with earlier breaches, this represents one of the most repeated breach patterns of any major carrier.
Root cause: Plaintiffs alleged T-Mobile repeatedly failed to employ "reasonable and adequate security measures." Having 8 breaches over 5 years is not a technical failure, it is an organizational one. Security investment was deprioritized despite the revenue to fund it.
Consequence: $350 million class action settlement, $150 million security investment commitment, and a $15.75 million FCC fine in 2024.
Takeaway: Repeated breaches are a governance problem as much as a technical one.
MOVEit Transfer Breach (2023)
What happened: The Cl0p ransomware group exploited a SQL injection zero-day vulnerability in Progress Software's MOVEit file transfer tool before any patch existed.
Scale: 2,000+ organizations affected and approximately 60 million individuals impacted by October 2023. Victims included the BBC, British Airways, Amazon, and the U.S. Department of Health and Human Services.
Root cause: A zero-day SQL injection vulnerability exploited at scale. No patch existed when exploitation began. Organizations with disciplined patch management cycles applied the fix faster once it was available, which limited downstream damage.
Key point: Zero-day exploits narrow the window for patch-based defense. This is why layered controls — network segmentation, least-privilege access, and anomaly monitoring — matter beyond patching.
Takeaway: No single control stops everything. The organizations that fared best combined rapid patch deployment with network architecture that limited what an attacker could reach.
Twitter/X Data Breaches (2022–2025)
What happened: A 2022 API vulnerability exposed 5.4 million records. A 2023 dataset of 200 million accounts was published. In 2025, a 400GB dataset of allegedly 2.87 billion user records appeared online, largely scraped and aggregated from earlier incidents.
Root cause: An API vulnerability that was patched in 2022 but whose extracted data kept circulating and being recombined into larger datasets by threat actors, among the biggest security breaches driven by data aggregation rather than a single intrusion event.
Takeaway: Once data leaves your environment, you lose control of it permanently. The 2025 dataset is still being used in phishing and credential-stuffing operations.
Facebook/Meta Data Leak (2021)
What happened: A phone number lookup API vulnerability was patched in 2019. Before it was closed, attackers scraped 533 million user records. That data sat quietly until April 2021, when it was posted publicly on a hacker forum.
Scale: 533 million users across 106 countries. Phone numbers, Facebook IDs, full names, and email addresses.
Root cause: Delayed disclosure of a 2019 vulnerability combined with the delayed surfacing of the scraped dataset years later. No active breach occurred in 2021, the data had already been taken.
Takeaway: Patching a vulnerability after exploitation doesn't undo the data already extracted. Detection and disclosure timelines matter enormously.
LastPass Data Breach (2022)
What happened: A two-stage attack. In August 2022, source code and technical data were stolen. Attackers used that access to target a DevOps engineer's personal device in November–December 2022, capturing the engineer's master password and stealing encrypted vault backups.
Scale: Approximately 30 million encrypted vaults exfiltrated. By 2025, attackers were still cracking vaults, TRM Labs traced $28 million in crypto theft to the LastPass breach, with potential total losses approaching $100 million.
Root cause: Over-privileged access for a DevOps engineer; MFA bypass on the personal device used to target the second stage.
Takeaway: Least-privilege access isn't a compliance checkbox. It's the control that limits what an attacker can reach when one account is compromised.
Medibank Data Breach (2022)
What happened: A Russian REvil-linked group used credentials stolen from a contractor's malware-infected personal device to access Medibank's GlobalProtect VPN. No MFA was required. The attackers extracted 520GB of data over seven weeks before being detected.
Scale: 9.7 million customers. The stolen data included highly sensitive medical records, abortion procedures, drug treatment history, mental health diagnoses.
Root cause: No MFA on the VPN. EDR tools generated alerts during the exfiltration period that were not triaged. Australia's OAIC federal court filing (2024) confirmed both failures.
Consequence: Medibank refused a $10 million AUD ransom. OAIC federal court case filed in 2024 remains ongoing.
Takeaway: The tools existed. The alerts fired. Nobody acted on them. Visibility without response is not a security control.
Optus Data Breach (2022)
What happened: A dormant API endpoint was left accessible on the public internet with no authentication required. Incrementing customer ID values allowed automated mass extraction of records.
Scale: 10–11 million customers, approximately 40% of Australia's population. Passport numbers, driver's licenses, and dates of birth were among the exposed data types.
Root cause: Unauthenticated public API endpoint. The attacker described the breach as not a "sophisticated" attack. It required no exploitation, the data was simply accessible.
Takeaway: Attack sophistication is irrelevant if the door is unlocked. API security audits should be a standard part of any security review cycle.
Uber Data Breach (2022)
What happened: An 18-year-old attacker purchased Uber credentials on the dark web, then used MFA fatigue, repeatedly sending push notification approvals until an employee accepted one. The attacker then posed as Uber IT support over WhatsApp to gather further access.
Root cause: Credential compromise combined with MFA fatigue and excessive permissions on the compromised accounts. The real failure was not that MFA existed, it was that the MFA implementation was susceptible to social engineering, and the accounts had more access than they needed.
Takeaway: MFA fatigue is an argument for phishing-resistant MFA (hardware keys, passkeys), not an argument against MFA. Pair MFA with least-privilege access so that a fatigued approval doesn't open the entire environment.
SolarWinds Supply Chain Attack (2020)
What happened: Russian state-sponsored group APT29/Cozy Bear inserted SUNBURST malware into SolarWinds Orion software updates between March and June 2020. The compromise wasn't discovered until December 2020.
Scale: 17,000–18,000 organizations installed the trojanized software. Several hundred were targeted for secondary payloads. U.S. federal agencies including the Treasury and State Department were among the victims.
Root cause: The trusted software update mechanism was weaponized. Standard perimeter defenses were bypassed entirely because the malware arrived through a legitimate, signed update.
Key point: SolarWinds is why zero trust principles and device posture checks matter beyond perimeter security. Attackers can enter through trusted channels, which means trust cannot be assumed even for patched, monitored systems. Network segmentation limits what they can reach once inside.
Takeaway: A clean software inventory and anomalous behavior monitoring are among the few controls that can surface supply chain compromise after the fact.
Microsoft Exchange Server Breach (2021)
What happened: Chinese state-sponsored group HAFNIUM chained four zero-day vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) to install web shells on on-premises Exchange servers. First exploitation occurred on January 3, 2021, 58 days before Microsoft released the patch on March 2, 2021.
Scale: Approximately 60,000 organizations compromised. By March 22, 2021 — three weeks after the patch release — 92% of exposed Exchange servers had been patched.
Root cause: Zero-day vulnerabilities combined with slow patch adoption in a significant portion of the affected organizations.
Takeaway: The 58-day pre-patch exploitation window was unavoidable. The post-patch adoption lag was not. Organizations that patched fastest had the smallest exposure window.
Colonial Pipeline Ransomware Attack (2021)
What happened: DarkSide accessed Colonial Pipeline's network via a single legacy VPN account whose password appeared on the dark web. No MFA was on that account. Approximately 100GB was exfiltrated before ransomware was deployed.
Scale: 5,500 miles of pipeline shut down for six days. Fuel shortages across the U.S. Southeast. Widespread panic buying at gas stations.
Root cause: An unused legacy VPN account with no MFA and stale credentials that had never been deactivated. If your legacy VPN accounts are not inventoried and audited regularly, you cannot know which ones are active exposure points and which ones are dormant risks.
Consequence: Colonial paid a $4.4 million ransom. The U.S. DOJ later recovered $2.3 million of it.
Takeaway: Deactivating unused accounts is not a complex technical project, it's an access hygiene task that most organizations keep deprioritizing.
Marriott Data Breaches (2018–2020)
What happened: Marriott's 2018 Starwood breach exposed 339 million guest records globally, attackers had been inside the Starwood reservation system since 2014, before Marriott completed the acquisition. A March 2020 breach exposed 5.2 million additional guest records via compromised employee credentials at the property level.
Root cause: Acquired legacy systems that were not subjected to a rigorous security review during or after the acquisition process, combined with compromised employee credentials.
Consequence: $52 million FTC settlement (October 2024), £18.4 million ICO fine (2020), and additional class action settlements reaching $60 million.
Takeaway: Acquisitions transfer liabilities as well as assets. Security due diligence on inherited systems is not optional.
15 Biggest Data Breaches: Scale, Root Cause, and Consequence at a Glance
Organization
Year
Records / People Affected
Root Cause
Regulatory / Financial Consequence
Change Healthcare
2024
~100M patients; 40% of U.S. claims disrupted
No MFA on legacy remote access
$1B+ costs; double extortion by second group
National Public Data
2024
272M unique SSNs confirmed
Inadequate data aggregator security controls
Company bankruptcy
AT&T
2024
72.5M+ customers
Credential theft; no MFA on cloud storage
Ongoing litigation
Ticketmaster / Santander
2024
560M + 30M accounts claimed
Stolen credentials; no MFA on Snowflake accounts
Regulatory investigations ongoing
MOVEit (Cl0p)
2023
~60M individuals; 2,000+ organizations
Unpatched SQL injection zero-day
BBC, Amazon, HHS among victims; widespread settlements
LastPass
2022
~30M encrypted vaults
Over-privileged access; MFA bypass on personal device
$28M–$100M+ in crypto theft (ongoing)
Medibank
2022
9.7M customers
No MFA on VPN; EDR alerts not triaged
OAIC federal court case filed 2024
Colonial Pipeline
2021
Critical infrastructure shutdown; U.S. Southeast affected
Unused VPN account; no MFA; stale credentials
$4.4M ransom paid; $2.3M recovered by DOJ
SolarWinds
2020
17,000–18,000 orgs installed; ~300 targeted
Trojanized trusted software update
$90M+ recovery costs; U.S. federal agencies compromised
The Root Causes Behind the Biggest Data Breaches (and What They Have in Common)
Across the biggest data breaches covered above, the root causes group into five categories. That's not a simplified view, it's the actual pattern. The Verizon 2025 DBIR confirmed it statistically. IT practitioners in post-mortem discussions confirm it informally: the same five gaps keep appearing in every breach report.
1. Missing or Bypassed MFA
Change Healthcare, AT&T, Snowflake, Colonial Pipeline, Medibank, and Uber all share this root cause. Credential abuse was the number one initial attack vector at 22% of confirmed breaches (Verizon 2025 DBIR). The Uber case specifically shows that MFA fatigue is an argument for phishing-resistant MFA, not an argument against it. The non-technical bottleneck here is also worth naming: the most common reason MFA isn't enforced on legacy systems is not technical, it's that nobody assigned ownership of legacy account auditing, and the project kept getting deprioritized.
2. Unpatched or Zero-Day Vulnerabilities
MOVEit and Microsoft Exchange are the clearest examples. Edge devices and VPNs now represent 22% of vulnerability exploitation targets, up from 3% in 2024, an 8x increase per the Verizon 2025 DBIR. The median time to mass exploitation for edge device vulnerabilities is zero days, which means organizations cannot rely on a response window after a vulnerability is disclosed.
3. Third-Party and Supply Chain Access
SolarWinds, Marriott's acquired Starwood systems, and the Snowflake-linked breaches all involved third-party access points that organizations trusted without verifying. Third-party involvement in breaches doubled from 15% to 30% in a single year according to the Verizon 2025 DBIR. The risk is not that vendors exist, it's that organizations extend system access without confirming the security posture of the devices and accounts doing the accessing.
4. Unchecked Shadow IT and Unauthorized Applications
The Verizon 2025 DBIR identifies shadow SaaS and AI applications as one of the most pressing issues security teams will face over the next five years. When employees connect work data to unapproved tools, the organization loses visibility into where that data goes and whether those tools meet its security standards. Getting visibility into your shadow IT landscape is the first step, you can't make policy decisions about tools you don't know exist. Trio MDM's Software Policy feature addresses the downstream risk: once you know which apps employees are running, IT can define an approved list and block unauthorized apps from running on managed devices.
A second-order consequence worth noting: data processed by unapproved tools may fall outside your organization's documented security boundary, invalidating compliance certifications that depend on accurate data flow mapping.
5. Human Error and Insider Negligence
Human error contributed to 95% of 2024 breaches (Mimecast/Infosecurity Magazine). The framing matters: these were not judgment failures by reckless employees. They were policy failures. No MFA was configured. Accounts weren't deactivated. Alerts weren't triaged. The Medibank EDR alerts that fired during a seven-week exfiltration window and were never acted on represent exactly this pattern, the tool worked; the process didn't. These are systems problems with systems solutions.
Which root cause is most relevant to your organization right now?
You use remote access tools (VPN, RDP, Citrix) without mandatory MFA → Close the MFA gap first. Every hour that gap remains open is a Colonial Pipeline or Change Healthcare scenario waiting to happen.
Employees install apps or connect cloud services without IT approval → Get visibility into your shadow SaaS and unauthorized application landscape before you can govern it.
Third-party vendors or contractors have access to internal systems → Audit third-party account privileges and require managed or compliant devices for vendor access.
Not sure where to start? → Run a device compliance audit. Surfacing which devices are unpatched or out-of-policy is the fastest way to identify your highest-risk exposure points.
What the Biggest Data Breaches Cost in Fines, Settlements, and Regulatory Action
Breach costs don't end with remediation. The biggest data breach fines and class action settlements represent a separate category of damage that frequently exceeds what organizations spend cleaning up the technical incident itself.
Key settlements and fines from the breaches covered in this article:
Marriott: $52M FTC settlement (2024) + £18.4M ICO fine (2020) + $60M class action
Meta/Texas: $1.4 billion for biometric data collection under Texas state law, a figure that reflects the fine structure regulators can apply even outside GDPR jurisdiction
23andMe: $30M class action settlement following a 2023 credential-stuffing breach exposing 6.9 million users; company filed for bankruptcy in 2025
T-Mobile: $350M class action + $15.75M FCC fine + $150M committed security investment
GDPR cumulative fines: €7.1B+ since 2018; fines through early 2025 totaling approximately €1.2 billion (CMS GDPR Enforcement Tracker)
The regulatory notification requirements that apply in most organizations today:
GDPR: 72-hour notification to data protection authorities; maximum fine of €20M or 4% of global annual turnover, whichever is higher
HIPAA: 725 breaches reported in 2024, affecting 275 million records; maximum civil penalty of $1.9M per violation category per year; average healthcare breach cost of $10.22M
U.S. state laws (2025): Texas and Florida now require 30-day breach notification to affected individuals; CIRCIA mandates 72-hour reporting for critical infrastructure operators
Organizations that experience a GDPR-reportable breach without documented, automated security controls face not only the breach fine but enhanced supervisory scrutiny going forward, meaning future compliance reviews become significantly more invasive. The compliance reporting requirement that creates the most organizational friction is rarely the technical control itself. It's the fact that nobody owns the responsibility for generating and documenting the evidence when an auditor asks for it. That's where compliance automation tools earn their ROI, by making the documentation a byproduct of normal operations, not a fire drill.
How Trio MDM Helps Prevent the Failures Behind the Biggest Data Breaches
The root causes behind the biggest data breaches map directly to technical controls that organizations can implement at the device and access management layer. Trio MDM addresses several of those controls specifically.
Remote lock and wipe. If a device is lost or stolen — the exact scenario that gave Medibank attackers their initial foothold via a contractor's compromised device — Trio MDM can remotely lock or wipe the device, preventing unauthorized access to corporate data stored on it.
Encryption and password policy enforcement. Trio MDM enforces disk encryption and password policies across managed devices. Even if a device is accessed, encrypted data is unusable without the decryption credentials, limiting the damage from physical device theft or unauthorized cloud storage access.
Application allowlisting via Software Policy. Trio MDM's Software Policy feature lets IT teams define an approved application list and block unauthorized apps from running on managed devices. This directly addresses the shadow SaaS and unauthorized AI application risk the Verizon 2025 DBIR identifies as a growing breach vector.
Compliance automation for technical frameworks. Trio MDM automates the technical implementation domain of compliance frameworks including CIS Level 1 and CIS Level 2, with continuous, automated monitoring of security controls. This matters for the regulatory scenarios above: being able to show an auditor that controls were active and monitored at the time of a breach changes the conversation significantly. Note that Trio MDM covers the technical implementation domain; non-technical compliance requirements fall outside its scope.
BYOD work/personal data separation. For organizations running Windows BYOD devices, Trio MDM creates a dedicated managed work account on personal devices, isolating corporate data from personal use. When a device is unenrolled, the work account and all associated data are deleted cleanly.
EDR integration and layered security. Trio MDM integrates with EDR and DLP tools across managed devices as part of a layered security stack. Trio MDM does not offer a native EDR, but it fits into the stack alongside one, its EDR integration capabilities connect managed device posture to the broader detection ecosystem.
Zero Trust direction. Device-level MFA enforcement is on Trio MDM's Zero Trust roadmap, a planned capability designed for continuous identity verification and context-aware access decisions. In the meantime, Trio MDM's existing controls, encryption enforcement, app allowlisting, and compliance monitoring, address the access hygiene gaps that enabled most of the breaches in this article.
If you're unsure which Trio MDM controls to prioritize first, check your current device compliance score, Trio MDM's compliance dashboard surfaces which devices are out-of-policy and why, giving you a starting point rather than a blank assessment.
Start your free trial to see how Trio MDM's controls map to your specific environment, or book a demo to walk through the breach prevention use cases with the Trio MDM team.
Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.
Don't let inefficiencies hold you back.
Every organization today needs a solution to automate time-consuming tasks and strengthen security. Without the right tools, manual processes drain resources and leave gaps in protection. Trio MDM is designed to solve this problem, automating key tasks, boosting security, and ensuring compliance with ease.
Have questions? We've got answers. This section covers some of the most commonly asked questions related to this topic.
Yes, MDM's value is not only preventive. Compliance dashboards can surface anomalous device states such as unrecognized configurations, new unauthorized applications, or policy violations that indicate post-breach lateral movement. The Medibank incident is the clearest illustration of what happens when visibility exists but isn't acted on, EDR alerts fired during a seven-week exfiltration window and were never triaged. MDM compliance monitoring creates a second layer of visibility that flags these states and can trigger automated remediation responses.
Third-party involvement in breaches doubled from 15% to 30% in a single year per the Verizon 2025 DBIR. The core risk is that organizations extend system access to vendor devices and accounts without verifying their security posture, the Medibank breach began with credentials stolen from a contractor's personal, malware-infected device that had no MFA requirement. Controls that reduce this exposure include requiring vendors to use managed or compliant devices, limiting third-party account privileges to the minimum necessary, and enforcing MFA on all remote access points before access is granted.
The Snowflake-linked breaches all shared the same failure: no MFA and no IP allow-listing on Snowflake accounts. Minimum controls are MFA for all human Snowflake users (Snowflake now mandates this following the 2024 breaches), IP or network range restrictions on account access, conditional access based on device compliance status, and regular auditing of which devices and users are connecting to the Snowflake environment. Managed devices running through an MDM solution let IT verify the health and compliance of anything connecting to cloud data platforms before that connection is permitted.
The 8x increase in edge device vulnerability targeting means VPN appliances, firewalls, and remote access gateways are now higher-priority targets than most internal endpoints. The median time to mass exploitation for edge device vulnerabilities is zero days, which means patch management cannot be the only defensive layer for these systems. Organizations should apply network segmentation so that a compromised edge device doesn't provide lateral access to the broader environment, and monitor the devices connecting through those edge points for behavior that falls outside normal baselines.
A breach typically involves active intrusion or deliberate theft; a leak involves unintentional exposure, usually through misconfiguration, like Optus's unauthenticated public API or Facebook's 2019 phone number vulnerability that was scraped and then posted publicly years later. For compliance purposes, the distinction carries very little weight. GDPR and HIPAA require notification based on whether personal data was exposed, not on whether an attacker was involved. Regulators have consistently treated misconfiguration-based leaks the same as active intrusions when assessing whether organizations had adequate controls in place.
Related
From the blog
The related industry news, interviews, technologies, and resources.