Third-party involvement in breaches doubled in a year, from 15% to 30%, across Verizon's last two Data Breach Investigations Reports. That rise is riding in on identities you granted access to but never hired — the vendors, contractors, and integrations with standing reach into your environment.
Your identity perimeter now includes identities you don't employ.
Access You Granted, Hygiene You Can't See
A vendor's service account, a contractor's login, and a partner's delegated admin all operate inside your tenant with permissions you approved. But the security around that identity, whether it has MFA, whether it was ever offboarded, whether it was phished last week, lives on the other side of a boundary you don't control. You baseline and monitor your own workforce constantly. For the identities reaching in from outside, you usually have a contract and a hope. When one is compromised, the attacker inherits legitimate access to your systems, and the first sign you get is behavior that looks like a trusted partner doing partner things.
Blast Radius Runs Both Ways
The number rose because the model scaled. One compromised provider can reach every customer it serves, and each of those customers runs its own roster of vendors with their own access. Third-party risk has outgrown the vendor questionnaire. It's a live identity problem now, playing out in your environment, on your logs, against your data. Treating an external identity as trusted because the relationship is legitimate is exactly the assumption attackers are pricing in.
Abnormal's VendorBase builds behavioral baselines for external identities the same way it does for employees — so when a vendor account starts behaving like an attacker, it shows up as a deviation, not a trusted session.
The identities most likely to breach you next may not be on your org chart at all. They're the ones you invited in and stopped watching.
See the latest from Abnormal's product and engineering teams.
