An outage recovery, regulators' growing appetite for vendor answers, and a vendor script quietly rerouting cryptocurrency. Here's what's happening this month in third-party risk management news.
Recently Added Articles as of August 20
1.2 million exposed in third-party cloud breach. A consumer lending company discovered in early May that a third-party cloud-based platform it used to store customer data was breached. The stolen data includes names, Social Security numbers, driver's license numbers, and bank account information. The company says its loan management systems and internal networks were untouched, and no ransomware group has claimed responsibility.
NYDFS fines a money transmitter $250,000 over a threadbare risk assessment. Order Express's cybersecurity program grew out of a risk assessment that never actually evaluated the company's own threats or existing controls, according to a consent order tied to a 2022 ransomware attack that encrypted more than half its servers. NYDFS also found the company's patch management policy covered only some of the third-party software products running on its network, leaving the rest exposed to known vulnerabilities. Order Express qualified for a limited exemption under New York's cybersecurity rule, but regulators held it to the same basic risk assessment and third-party patching standards as larger covered entities.
Vendor risk management can be a growth lever, not just a compliance shield. On a recent Credit Union Connection podcast episode, Ncontracts CEO Michael Berman and risk expert Michael Carpenter said credit unions treating third-party risk management as a pure defensive checklist are missing its strategic upside. The pair, drawing on their new book on the topic, pushed credit unions to align vendor relationships directly with institutional mission and member value rather than stopping at examiner-minimum compliance.
Fourth-party breach impacts hardware wallets company. A fulfillment company that ships Trezor hardware wallets, told Trezor customer order data was compromised after a third-party analytics platform was breached. It exposed information of nearly 14,000 customers. Trezor's devices and private keys were never touched, and the company says a 90-day data retention policy, which it also requires of fulfillment partners, kept the exposure limited to recent orders instead of its full customer history. The incident is a reminder that a vendor's own vendor can end up mattering as much as the vendor itself.
3.8 million exposed in health tech vendor breach. Unlimited Technology Systems, a back office software provider used by more than 4,500 oncology offices and 6,500 specialty providers, discovered hackers inside one of its data centers in October 2025 but didn't notify federal regulators until late July 2026. Stolen data includes insurance policy numbers, claims and benefits information, Social Security numbers, and scanned copies of driver's licenses and government IDs. Under HIPAA's Breach Notification Rule, covered entities must notify HHS within 60 days of discovering a breach affecting 500 or more people.
Treat AI as a vendor risk, not a product feature. Much of the AI risk inside financial institutions arrives without a distinct procurement decision, either through employees adopting unapproved tools or through vendors quietly adding AI features to products already under contract. FINRA's 2026 oversight report calls for firms to maintain an AI vendor inventory, monitor for undisclosed model changes, and account for fourth-party exposure when a vendor's AI relies on a model provider the institution never directly contracted with. Legacy vendor contracts frequently say nothing about AI use, training data, or human review, leaving firms to answer for a vendor's AI-driven decision even when they never saw the model behind it.
UK regulators start directly overseeing the cloud vendors banks depend on. The Bank of England, PRA and FCA began supervising Amazon Web Services, Google Cloud, Microsoft and Oracle as Critical Third Parties in July, a shift from banks managing cloud risk contract-by-contract to regulators overseeing the shared providers directly. The concern is concentrated dependency: thousands of institutions can look diversified on paper while relying on the same identity systems, databases, and disaster recovery tools underneath. Genuine multi-cloud portability is harder than it sounds, since data costs and deep use of a provider's proprietary tools make switching expensive even when a contract technically allows it.
Recently Added Articles as of August 13
LexisNexis pulls three services offline after vendor server incident. LexisNexis pulled three products offline after spotting suspicious activity on servers run by a third-party vendor. The company disconnected from the vendor's systems to stop the problem from spreading and is now working with a digital forensics firm to rebuild the affected infrastructure before bringing the services back up. This marks the third security incident LexisNexis has faced in just over a year.
Vendor breach exposes wealth management client data. A breach at an SEC-registered investment advisory firm originated with a third-party vendor. Client names, Social Security numbers, account numbers, and other financial information may have been viewed when an unauthorized actor accessed a system.
AI risk shows up in governance decisions before security controls ever apply. AI governance decisions, including the selection of a third-party AI provider, occurs before technical security controls come into play, making governance itself an important security control. Vendor risk management should be extended to cover AI, rather than building a separate program from scratch, especially since vendors are increasingly adding AI capabilities into products organizations already use, often without the visibility organizations expect from other technologies.
Recently Added Articles as of August 6
State regulators are zeroing in on vendor management after breaches. State attorneys general and bodies like the New York Department of Financial Services are treating vendor management as a top area of scrutiny, according to a legal industry report on state cybersecurity enforcement trends. States take the position that a company can't contract away its obligation to safeguard data, so investigators are asking how vendors are tiered, whether critical vendors get real due diligence and audit rights, and whether the company has a plan for when a vendor becomes the point of failure. Reserve deeper scrutiny for critical vendors, which holds up better under investigation than a one-size-fits-all approach. Regulators also expect a documented exit plan for any vendor relationship that fails or gets breached, not just an onboarding checklist.
TruStage targets mid-August for basic outage recovery. TruStage expects to restore basic billing and claims servicing during the first half of August, weeks after the outage forced it to shut down parts of its network. President and CEO Terrance Williams said the company is rebuilding its technology environment in isolated phases rather than simply restarting systems, with recurring debt-protection payments now in testing with eight credit unions. Interim processes are available for certain annuity transactions, and retirement disbursement testing is underway, though the life insurance platform remains more complex to recover. Forensic investigators still haven't determined whether member data was compromised.
Actively exploited flaw hands attackers admin access to MSP consoles. A remote monitoring platform widely used by managed service providers (MSPs) to manage client IT networks discovered an actively exploited vulnerability that lets attackers bypass login and gain full administrative control. Once inside, an attacker can reach every network the platform manages, turning one compromised MSP tool into access for dozens of downstream organizations. Financial institutions should confirm with their IT service providers whether they use this type of remote monitoring software and whether the patch has been applied.
Ad-tech vendor breach turned into a cryptocurrency wallet swap. Hackers broke into a piece of tracking code that ad-tech vendor Adform runs on websites for roughly 14,000 businesses and used it to secretly switch out crypto wallet addresses that visitors copied and pasted. So, if someone tried to send funds to their own wallet, the money went to the attacker instead. The code also swapped wallet addresses shown right on the page and sent victims' location and browsing data back to the attacker. Adform removed the code once it was caught and says nothing was installed on visitors' devices, though it hasn't said how many people encountered the tampered version.