Close Menu
    What's Hot
    AI Events

    Billion-Dollar AI Decisions: How C-Suite Leaders Balance Innovation, Risk and National Priorities

    By Art RyanJune 29, 20260

    Artificial intelligence is no longer just an experimental technology for enterprises. It is becoming a…

    AI in 2030: Transforming Development Pathways for a New Era in Saudi Arabia

    June 29, 2026

    Global AI Show Riyadh 2026: Why data quality will be the winners of the AI era

    June 29, 2026

    Global AI Show Riyadh 2026 Opens Today in Saudi Arabia

    June 29, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Breaking AI News
    Tuesday, June 30
    • Home
    • Events
    • Videos
      • Machine Can Think Summit 2026
      • Step Dubai Conference 2026
    • Technology & Innovation

      Billion-Dollar AI Decisions: How C-Suite Leaders Balance Innovation, Risk and National Priorities

      June 29, 2026

      AI in 2030: Transforming Development Pathways for a New Era in Saudi Arabia

      June 29, 2026

      Global AI Show Riyadh 2026: Why data quality will be the winners of the AI era

      June 29, 2026

      Global AI Show Riyadh 2026 Opens Today in Saudi Arabia

      June 29, 2026

      xAI Grok 4.5 Enters Private Beta at Tesla and SpaceX

      June 29, 2026
    • Business & Marketing

      xAI Grok 4.5 Enters Private Beta at Tesla and SpaceX

      June 29, 2026

      Meta Gemini AI Tokens: Why Meta Is Asking Staff to Use Gemini More Efficiently

      June 29, 2026

      MGX Raises Nearly $50 Billion to Accelerate Global AI Investments

      June 28, 2026

      Google Demand Gen Campaigns Get Gemini AI Guidance to Improve Ad Performance

      June 28, 2026

      Tech Equity Sales Renew AI Debt Binge Worries as AI Infrastructure Spending Accelerates

      June 28, 2026
    • Industry Applications

      Microsoft Launches MAI-Code-1-Flash for GitHub Copilot Users

      June 29, 2026

      DeepSeek Launches DSpark to Boost AI Inference Speed by Up to 80%

      June 29, 2026

      XLSMART and Tencent Cloud Complete Major AI-Driven Cloud Migration Project

      June 28, 2026

      NVIDIA Supercomputers Now Power Over 400 of the World’s 500 Fastest Systems

      June 27, 2026

      NVIDIA Vera CPU to Power Agentic Scientific AI at Los Alamos

      June 27, 2026
    • Trends & Insights

      Claude’s Agentic Work Reshapes Anthropic Economic Index

      June 28, 2026

      Tech Equity Sales Renew AI Debt Binge Worries as AI Infrastructure Spending Accelerates

      June 28, 2026

      UAE Investors Lead the World in AI Adoption, HSBC Survey Finds

      June 26, 2026

      Google Says Generative AI Is Creating a New Language for Marketing and Creativity at Cannes Lions 2026

      June 24, 2026

      OpenAI Reveals Future Ad Plans as ChatGPT Moves Toward the Intelligence Economy

      June 24, 2026
    • AI in Travel

      Global AI Show Riyadh 2026 Opens in 2 Days as Saudi Arabia Prepares for Major AI Conference

      June 27, 2026

      Agoda AI Travel Features Bring Real-Time Updates and Smarter Trip Planning

      June 26, 2026

      AI Travel Agents Could Disrupt Brand Loyalty as Travelers Embrace Smarter Booking Decisions

      June 26, 2026

      Jamaica Tourism 3.0 Uses AI to Transform Visitor Economy Into National Development Platform

      June 26, 2026

      Southwest Airlines Teams Up with AWS to Speed Up AI and Cloud Modernization

      June 21, 2026
    Breaking AI News
    Home » Third-Party Risk and AI Gave Cyberattacks the Upper Hand in 2025
    Technology & Innovation

    Third-Party Risk and AI Gave Cyberattacks the Upper Hand in 2025

    Art RyanBy Art RyanDecember 18, 2025No Comments5 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The threats snowballed in 2025. Cyberattacks stopped being episodic crises and instead became a persistent condition of doing business.

    A persistent and costly condition. So much so that one of the world’s largest cyber insurance firms, Beazley, announced last month it was reducing its U.S. cyber business in order to maintain underwriting discipline and rate adequacy in the face of unsustainable rates in the cyber market following several high-profile breaches.

    Still, Beazley may not have much luck elsewhere around the globe. In the U.K. alone, cyber insurance claim payouts are up 230% from the year prior.

    There was the $2.5 billion-plus Jaguar Land Rover cyberattack this fall, which is thought to be the most economically damaging attack in the U.K.’s history; high-profile breaches across airlines, crypto platforms, cloud providers and blue-chip firms like Apple, Google and even McDonald’s.

    For CFOs and CISOs alike, the lesson was not simply that attacks are growing more frequent or sophisticated. It was that traditional models such as annual audits, static controls, perimeter-focused defenses, and siloed ownership of risk are no longer aligned with how modern attacks unfold.

    Fault Lines

    The most consequential incidents of 2025 revealed common fault lines: AI-powered adversaries exploiting cloud complexity, fragile supply chains riddled with third-party exposure, and organizations that could not see, in real time, how risk was accumulating across their digital ecosystems.

    Findings from PYMNTS Intelligence in the August edition of the 2025 Certainty Project report, “Vendors and Vulnerabilities: The Cyberattack Squeeze on Mid-Market Firms,” found that attackers frequently compromise a vendor first, then use the trust relationship to infiltrate their target firm. The report found 38% of invoice fraud cases and 43% of phishing attacks stemming from compromised vendors.

    That was the case across the freight economy this year, where the National Insurance Crime Bureau (NICB) estimated that criminals were absconding with $35 billion in cargo theft losses annually in just the U.S.

    The NICB noted that attackers are using sophisticated social engineering to impersonate legitimate carriers, freight brokers and even shipper contacts. They trick carriers into downloading legitimate remote monitoring and management (RMM) tools under false pretenses, then leverage these compromised tools to unlock access to systems like load boards, dispatch platforms and fleet management software.

    Elsewhere, a TransUnion third-party data breach affected more than 4.4 million customers this summer. The breach followed a series of cybersecurity incidents at big companies involving third-party vendors. For example, firms such as Google, Cisco and Workday have also seen thefts of customer data kept on Salesforce’s cloud recently.

    In March, news broke that the FBI was probing a cyberattack at Oracle that led to the theft of 6 million records, taken from 140,000 Oracle cloud tenants.

    This August, the luxury retailers Pandora and Chanel were also the victims of third-party data breaches; and in July, a system breach at Allianz Life impacted most of the insurer’s U.S. customers’ personal data. Adidas in the spring reported a data breach tied to a hacker group using voice phishing attacks to steal data from Salesforce CRM instances to power a wave of data breaches.

    “In 2021, there were 400 data breach lawsuits filed,” Philip Yannella co-chair of the privacy, security and data protection practice at Blank Rome and the author of “Cyber Litigation: Data Breach, Data Privacy & Digital Rights,” 2025 edition, said in an interview with PYMNTS. “Last year, there were over 2,000. … Data breaches are always the biggest danger.”

    Attacks on global brands like Air France, and security slip ups leading a data breach at McDonald’s, reinforced the paradox of 2025’s cybersecurity: Size and sophistication do not guarantee immunity.

    Read more: Making Sense of Data Protection Assessments for B2B Firms 

    Continuous Monitoring

    The cryptocurrency sector has long been a canary in the coal mine for cybercrime, and 2025 was no exception.

    To kick the year off, the crypto exchange Bybit in February suffered a hack estimated at nearly $1.5 billion worth of tokens. Meanwhile Coinbase suffered a cybersecurity incident in May that could cost it as much as $400 million.

    In both cases, attackers exploited a mix of social engineering, compromised credentials and cloud misconfigurations. What stood out was the speed: AI-assisted reconnaissance compressed attack cycles from weeks to hours. Defensive teams found themselves responding to threats that evolved faster than human-led processes could track.

    Social engineering fraud has increased by 56% in the past year, according to the PYMNTS Intelligence report, “The State of Fraud and Financial Crime in the U.S. 2024: What FIs Need to Know.”

    Research from the PYMNTS Intelligence report “The AI MonitorEdge Report: COOs Leverage GenAI to Reduce Data Security Losses” shows that 55% of companies are employing AI-powered cybersecurity measures.

    Across nearly every major incident of 2025, one theme recurred: organizations lacked real-time visibility into how risk was evolving. Whether it was delayed detection of lateral movement, slow recognition of third-party compromise, or uncertainty about which assets were affected, time proved to be the most expensive variable.

    Source: https://www.pymnts.com/
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Art Ryan

    Related Posts

    Billion-Dollar AI Decisions: How C-Suite Leaders Balance Innovation, Risk and National Priorities

    June 29, 2026

    AI in 2030: Transforming Development Pathways for a New Era in Saudi Arabia

    June 29, 2026

    Global AI Show Riyadh 2026: Why data quality will be the winners of the AI era

    June 29, 2026

    Comments are closed.

    Latest News

    Billion-Dollar AI Decisions: How C-Suite Leaders Balance Innovation, Risk and National Priorities

    June 29, 2026

    AI in 2030: Transforming Development Pathways for a New Era in Saudi Arabia

    June 29, 2026

    Global AI Show Riyadh 2026: Why data quality will be the winners of the AI era

    June 29, 2026

    Global AI Show Riyadh 2026 Opens Today in Saudi Arabia

    June 29, 2026
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram LinkedIn YouTube Spotify Reddit Snapchat Threads

    AI University

    • Global Universities
    • Universities in Africa
    • Universities in Asia
    • Universities in Europe
    • Universities in Latin America
    • Universities in Middle East
    • Universities in North America
    • Universities in Oceania

    AI Tools & Apps Directory

    • AI Productivity Tools
    • AI Coding Tools
    • AI Voice Tools
    • AI Video Tools
    • AI Image Generators
    • AI Writing Tools

    Info

    • Home
    • About Us
    • AI Organizations & Associations
    • Contact Us
    • Cookie Policy
    • Copyright Policy
    • Disclaimer
    • Editorial Policy
    • Terms and Conditions

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2026 Breaking AI News.
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Sign Up

    Want to stay ahead In Artificial Intelligence?

     Sign up now and get exclusive breaking AI news and special updates—FREE!