Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news.
Recently Added Articles as of July 30
Vendor risk assessments miss credential hygiene that caused Klue breach. The breach that exposed Klue customers' Salesforce data traced back to a forgotten, still-active service account credential from an old pilot project. Compliance certifications and completed questionnaires often don’t say whether a vendor retires dormant credentials or rotates secrets on an ongoing basis. Third-party risk programs should ask vendors directly about credential lifecycle management and privileged account governance, not just certification status.
Financial innovation expands compliance obligations, increasing the burden on mid-market firms. Every payments advance, from ACH to cloud banking to open banking, has added governance requirements rather than reducing them: cloud infrastructure introduced vendor risk management and operational resilience programs, and APIs and embedded finance added new third-party risk and data governance demands on top of that. Mid-market firms increasingly face those same obligations without the specialist staff larger enterprises can hire to absorb them. AI is expected to be the next major compliance expansion, requiring model validation, vendor oversight, and audit readiness investments before firms can deploy it in production.
Contracts need to better address fourth-party risk. Fourth-party risk is a blind spot for many vendor programs. Contracts rarely require vendors to name their sub-vendors or push the same security standards down the chain. SOC 2 reports are a good starting point and should be backed with detailed questionnaires and hard breach-notification timelines. Oversight doesn't stop at onboarding: Runs quarterly vendor reviews, verify cyber insurance annually, and stress-tests response plans with tabletop exercises.
Under-resourced sub-tier suppliers are becoming the weak point in agentic AI adoption. With AI agent adoption expected to reach 68% of businesses by year end, smaller Tier 2 through Tier 4 suppliers often lack the resources to defend against AI-driven attacks, and a single compromised sub-supplier can expose an entire customer network. Continuous monitoring and centralized supplier data make the difference between catching a risk early and learning about it after a breach. Vendor risk programs that stop assessments at the first tier of suppliers are missing exactly this exposure.
Servicers own the liability when an AI vendor gets it wrong, and most vendor contracts don't reflect that. Mortgage servicers can't shift AI liability to their vendors. Under the three AI governance standards in effect, the servicer owns the outcome when an AI tool gets an account decision wrong. Enforcement may look quiet, but the compliance bar keeps rising, and most vendor contracts still lack basic protections like data-use limits, change notifications, and audit rights. Servicers that can't produce a current AI use-case inventory or model-specific denial reasoning today carry real exposure regardless of the federal enforcement lull.
Executive order gives CIOs a fresh vendor due diligence checklist. A June executive order creates a voluntary framework letting AI developers submit models for a classified federal benchmarking process that flags "covered frontier models" based on advanced cyber capability. Since the threshold is classified, vendors confirm participation and confidentiality terms — not where their models land. Gold Eagle, the order's vulnerability coordination initiative, evaluates vendors on vulnerability intake, patching, and customer notification, giving procurement teams a federal reference point for evaluating frontier-model risk, even without mandatory enforcement.
Recently Added Articles as of July 23
EY's third-party ticketing platform exposed financial-institution tax data. Ernst & Young disclosed a breach with their third-party IT support ticketing platform that went undetected for about two weeks. Documents tied to the tax services EY provides were downloaded. Support tickets on the platform can include client tax and financial information, and EY said an unspecified number of clients across the 150+ countries where it operates were affected.
Cyber insurers say vendor risk is still the biggest blind spot. Panelists at InsuranceFest 2026 said vendor risk remains one of the most overlooked exposures in cyber insurance, since many organizations still assume risk transfers to a supplier once a contract is signed. AI exclusions and quantum computing were flagged as the other open questions shaping this year's cyber coverage.
TruStage outage draws its first class action from a credit union. After the TruStage outage, one credit union has filed the first proposed class action, alleging TruStage's security fell short of its own stated safeguards. The suit seeks damages and reimbursement on behalf of a nationwide class of credit unions and individuals. TruStage says it has seen no evidence of ongoing threat-actor activity since containment but hasn't disclosed how the incident occurred or if any data was stolen.
Fourth bank failure of 2026 traces back to enforcement actions. The Federal Reserve's original 2023 cease-and-desist order against a Kansas bank cited deficiencies spanning credit risk, IT security, and third-party risk management, among other findings. Two more enforcement actions followed, including a "significantly undercapitalized" designation this June, and the bank failed on July 17, becoming the fourth FDIC-supervised failure of 2026. The FDIC estimates the failure will cost the Deposit Insurance Fund roughly $5.7 million.
Two npm attacks expose supply chain risks. Two npm supply-chain attacks hit developers directly instead of blockchains: a popular Injective SDK was compromised via a trusted GitHub account and days later a stolen credential let attackers push a fake update to Jscrambler, a security vendor, which kept spreading for hours before anyone noticed. The real lesson is about vendor risk: even a trusted, security-focused vendor can become the attack vector, and a single compromised account or token can turn any dependency you rely on into a threat within minutes.
Recently Added Articles as of July 16
One of the largest credit union vendors takes network offline after cyber incident. TruStage, one of the largest providers of insurance and financial products to credit unions, took down portions of its network after a cybersecurity incident. For credit unions, TruStage sits at the center of many institutions' insurance programs, payment protection products, and member-facing financial services. The full scope of the incident isn't yet known.
When nobody owns sensitive data, the examiner finds the gap. Identity and access management (IAM) drift — where employee access follows them across role changes, transfers, and departures because no one explicitly owns the update process — is both an exam finding waiting to happen and a data quality problem hiding in plain sight at credit unions. Often security teams treat identity data as HR's responsibility, while HR treats access provisioning as IT's. When third-party applications are involved, the problem compounds since access accuracy then hinges on a partner's data discipline as much as the institution's own.
The Reg S-P deadline passed. The hard part is just starting. The June 3 compliance deadline for smaller investment advisers may have felt like a finish line, but regulators are now shifting focus from whether policies exist to whether controls are operating. The amended rule's sharpest edge for most private fund managers is vendor oversight: 53% of financial services organizations rely on at least 300 external vendors, yet 63% have only one or two employees dedicated to overseeing those relationships. Under Reg S-P, the responsibility for protecting investor data stays with the fund manager regardless of how much is outsourced — which means the vendor oversight gap isn't just a compliance problem, it's an exam exposure.
Courts are holding organizations for AI vendor tools. When a chat vendor recorded Peloton customer conversations to train its own models, the lawsuit named Peloton — not the vendor. When iTutorGroup was accused of using a third-party AI screening tool that discriminated against older applicants, the EEOC sued the employer. Cigna and UnitedHealth face class actions over their use of third-party AI tools in medical claims decisions. The pattern is consistent: accountability follows the organization. There are four under-managed exposures: limited visibility into how vendor models are built and change over time, liability that shifts when a firm customizes a vendor's AI, dependence on vendors that are difficult to replace, and fragmented regulatory demands that don't map cleanly onto vendor contracts.
Recently Added Articles as of July 9
The Fed is pushing for AI regulation calibrated to risk — not one-size-fits-all rules. Federal Reserve Vice Chair for Supervision Michelle Bowman said lower-risk AI applications should receive lighter supervisory scrutiny, with regulatory expectations scaled to bank size and complexity rather than applied uniformly. Bowman made the remarks while talking about the Financial Stability Board report on AI adoption best practices and urged banks to weigh in before the comment period closes. The message to smaller institutions in particular: oversight expectations that make sense for a large bank running complex AI applications don't automatically apply to simpler use cases at community institutions.
The vendor management questions most institutions aren't asking. Most banks and credit unions have vendor management programs in place — the gap is usually in the quality of the questions being asked. Standard assessments tend to focus on vendor financial stability and security controls, but stop short of harder questions: which business processes actually depend on this vendor, where do single points of failure concentrate across the portfolio, and how quickly could the institution keep operating if the vendor became unavailable? Exit planning is consistently underdeveloped — contracts often include termination provisions, but rarely a realistic plan for what happens in the weeks that follow.
Four things banks can do to lessen cyber and third-party risk. As the federal regulatory environment shifts, banks face the risk of mistaking compliance for security. Bad actors increasingly target bank partners and vendors as a backdoor — the 2025 Marquis breach, which exposed data from more than 400,000 bank and credit union customers through an unpatched firewall vulnerability at a marketing vendor, is a direct example. Smaller community banks and credit unions face compounding exposure: proposed CISA budget cuts would reduce the free threat intelligence resources many rely on, making vendor security standards and continuous monitoring more critical, not less.
One phishing email at an insurance MGA exposed policyholder data across its entire agent network. A March phishing attack at an insurance MGA gave attackers access to SSNs, driver's license numbers, auto insurance policy details, and claims records — held not just by the MGA itself but across its distributed retail agent and broker network. That's what makes an MGA breach different from a single-carrier incident: the platform aggregates policyholder data across its entire agent network, so when it's compromised, the notification and remediation obligations extend to every retail agent that feeds it.
Recently Added Articles as of July 2
Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it — a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24–48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors.
A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization — Rochester Regional Health — had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought.
The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm.
The NAIC got breached — and insurance companies are still feeling it. Attackers exploited a vulnerability in the National Association of Insurance Commissioners’ Oracle systems for two weeks before a patch existed, accessing statutory financial reporting data and credit rating information. Credit rating agencies have since paused their data feeds to the NAIC, and insurer investment designation assignments remain suspended — a process that could take months to restore. No personally identifiable information or state department systems were affected, but the incident is a reminder that regulators are targets too, and that third-party software vulnerabilities can create operational disruptions well beyond the initial breach.
A vendor breach just cost a crypto platform $3 million. Attackers breached a third-party vendor supplying frontend code to Polymarket, one of the world's largest crypto prediction markets, and injected a malicious script that tricked users into approving fraudulent transactions on what appeared to be the legitimate site. Polymarket's own infrastructure was untouched. The company is reimbursing all losses, but the incident is a useful reminder to reassess which vendor relationships are in scope for security oversight — a dependency that touches the user interface is a dependency that can touch user funds.
