Third-Party Breaches Surge 60% Year-over-Year, Verizon 2026 Report Finds
Verizon's latest data breach report reveals third parties were involved in 48% of breaches, marking a dramatic 60% increase from the previous year.
AI-generated summary. This news item was written automatically by an AI pipeline from published reporting and was not reviewed by a person before publication. It may contain errors. Read the original source.
Third-Party Breach Involvement Reaches Critical Levels
Verizon’s 2026 Data Breach Investigations Report has identified a stark escalation in third-party involvement across security incidents. According to the report, third parties were involved in 48% of all breaches tracked, representing a 60% year-over-year increase—a troubling trajectory for organisations relying on external vendors and service providers.
This surge underscores growing risks in supply chain security and the expanding attack surface created by interconnected business ecosystems. Organisations across Europe and beyond must reassess vendor security assessments and contractual accountability measures.
Business Email Compromise Remains a Top Threat
Meanwhile, business email compromise (BEC) continues to exact a severe financial toll. The FBI’s Internet Crime Complaint Center recorded roughly $3 billion in reported BEC losses in 2025, making it the second-costliest crime category tracked by IC3, behind only investment fraud.
AI-Driven Attacks Accelerate into Production
Prompt injection and indirect attacks against AI systems are moving from theoretical concern to active exploitation. In March 2026, Palo Alto Networks’ Unit 42 identified 22 distinct techniques attackers used in the wild to construct prompt injection payloads. Attacker goals across these campaigns ranged from SEO poisoning and phishing site promotion to unauthorized transactions, sensitive information leakage, and system prompt leakage.
OWASP’s GenAI Exploit Round-up Report Q1 2026 concluded that the AI security landscape from January through early April 2026 shows a clear transition from theoretical risks to real-world exploitation. The report further noted that attackers and system failures are increasingly targeting agent identities, orchestration layers, and supply chains rather than just model outputs.
Check Point Research has also cited a rise in indirect prompt injection attacks, observing that the attack path is increasing in operational relevance to attackers.
Pervaziv AI Advances Multi-Agent Orchestration
On October 9, 2026, Pervaziv AI announced a major expansion of its Cortex platform, moving from assistance centred on individual prompts toward continuous, coordinated work connected to an objective across time, tools, teams, and review points. The expanded Cortex platform combines multi-agent orchestration with isolated Git worktrees.
Source: Dark Reading