Last month, Texas Parks & Wildlife disclosed that a third-party vendor breach exposed 3 million driver's licenses and passport numbers. The agency itself wasn't hacked. Its security was fine. But a company somewhere in its supply chain wasn't — and 3 million people are dealing with the consequences.

This is the supply chain problem in cybersecurity, and it's getting worse. A 2026 study found that 85% of chief information security officers can't see third-party threats amid increasing supply chain attacks. They know the risk is there. They just can't measure it.

The problem isn't your security. It's theirs.

Most businesses have gotten reasonably good at locking their own doors. You have antivirus software. You probably have someone managing your network. You might even have a written security policy. But your security is only as strong as the weakest vendor in your orbit.

Think about who has your data. Your payroll provider has every employee's Social Security number and bank account. Your email provider has years of confidential correspondence. Your cloud storage provider has customer contracts, financial records, intellectual property. Your point-of-sale vendor processes credit cards. Your HVAC vendor has a network connection to your building management system.

Each of those vendors has its own vendors. And each of those vendors has employees who click on phishing links.

The attack surface you can't see

The FBI recently warned about a group called Silent Ransom — also known as Chatty Spider — that takes supply chain attacks to a physical level. They cold-call employees posing as IT support from a vendor. If the call doesn't work, they show up in person with USB sticks and a cover story. They've targeted law firms specifically, but the technique works against any business that relies on outside technology providers.

The playbook is simple: find a vendor relationship, impersonate that vendor, walk through the door. Most reception desks won't question someone who says they're "from IT" and seems to know which systems the company uses.

What this means for your business

You can't audit every vendor. You can't control their security practices. But you can do a few things that dramatically reduce your exposure:

Know who has your data. Make a list. Not just your obvious vendors — the ones you think of as technology providers. Include your accountant, your lawyer, your benefits administrator, your cleaning service if they have a key card. Anyone who touches your systems or your sensitive information. You can't protect what you don't know you're sharing.

Ask the right questions. When you sign a contract with a vendor who handles sensitive data, ask what happens if they get breached. Who pays for notification costs? Who's liable? If they can't answer those questions clearly, that's a red flag.

Limit what you share. Most vendors ask for more data than they actually need. Your payroll provider needs Social Security numbers. Your marketing consultant probably doesn't need your full customer list with purchase history. Push back on data requests that seem excessive.

Have a plan for when — not if — a vendor breach affects you. Know who you'll call, what you'll tell customers, and how you'll contain the damage. The businesses that handle vendor breaches well aren't the ones with the best security. They're the ones who had a plan before they needed it.

If you don't know which of your vendors have access to your most sensitive data — or what happens if one of them gets breached — have a conversation with someone who can help you map that out. The breach you don't see coming is the one that costs the most.