Nsight Blog | Ncontracts

August 2026 Vendor Management News

Written by Ncontracts | Aug 6, 2026, 1:36:44 PM

An outage recovery, regulators' growing appetite for vendor answers, and a vendor script quietly rerouting cryptocurrency. Here's what's happening  this month in third-party risk management news.

Recently Added Articles as of August 6

State regulators are zeroing in on vendor management after breaches. State attorneys general and bodies like the New York Department of Financial Services are treating vendor management as a top area of scrutiny, according to a legal industry report on state cybersecurity enforcement trends. States take the position that a company can't contract away its obligation to safeguard data, so investigators are asking how vendors are tiered, whether critical vendors get real due diligence and audit rights, and whether the company has a plan for when a vendor becomes the point of failure. Reserve deeper scrutiny for critical vendors, which holds up better under investigation than a one-size-fits-all approach. Regulators also expect a documented exit plan for any vendor relationship that fails or gets breached, not just an onboarding checklist.

TruStage targets mid-August for basic outage recovery. TruStage expects to restore basic billing and claims servicing during the first half of August, weeks after the outage forced it to shut down parts of its network. President and CEO Terrance Williams said the company is rebuilding its technology environment in isolated phases rather than simply restarting systems, with recurring debt-protection payments now in testing with eight credit unions. Interim processes are available for certain annuity transactions, and retirement disbursement testing is underway, though the life insurance platform remains more complex to recover. Forensic investigators still haven't determined whether member data was compromised.

Actively exploited flaw hands attackers admin access to MSP consoles. A remote monitoring platform widely used by managed service providers (MSPs) to manage client IT networks discovered an actively exploited vulnerability that lets attackers bypass login and gain full administrative control. Once inside, an attacker can reach every network the platform manages, turning one compromised MSP tool into access for dozens of downstream organizations. Financial institutions should confirm with their IT service providers whether they use this type of remote monitoring software and whether the patch has been applied.

Ad-tech vendor breach turned into a cryptocurrency wallet swap. Hackers broke into a piece of tracking code that ad-tech vendor Adform runs on websites for roughly 14,000 businesses and used it to secretly switch out crypto wallet addresses that visitors copied and pasted. So, if someone tried to send funds to their own wallet, the money went to the attacker instead. The code also swapped wallet addresses shown right on the page and sent victims' location and browsing data back to the attacker. Adform removed the code once it was caught and says nothing was installed on visitors' devices, though it hasn't said how many people encountered the tampered version.