Every story tagged Third Party Risk, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
4 stories · open in the command center
Android app developers are unknowingly sharing users' location data with advertisers and data brokers through third-party SDKs that inherit app permissions by default, creating significant privacy, security, and regulatory risks for organizations. This widespread practice—affecting apps downloaded hundreds of millions of times—exposes sensitive location data to unauthorized third parties including government agencies and intelligence services, creating liability exposure and potential compliance violations under data protection regulations. IT and security leaders must establish vendor management protocols and SDK auditing practices to prevent unauthorized data sharing and mitigate organizational risk.
Yoti's age verification service shares sensitive user data—including facial photos and device fingerprints—with third-party vendors, creating significant privacy and compliance risks for organizations implementing this technology. This practice raises critical concerns for IT leaders regarding vendor data handling, regulatory exposure under GDPR and similar frameworks, and potential reputational damage if customer data is misused. Technology organizations must reassess their identity verification vendor partnerships and establish stricter data governance requirements to minimize liability and maintain customer trust.
The cloud development platform Vercel was hacked, with attackers potentially gaining access to sensitive data like employee names, email addresses, and activity timestamps. The breach originated from a compromised third-party AI tool, highlighting the security risks associated with reliance on third-party services. This incident underscores the need for IT organizations to closely monitor their third-party integrations and take proactive measures to secure their cloud-based development environments.
Rockstar Games experienced a data breach through its third-party cloud service providers (Snowflake via Anodot), with hacking group ShinyHunters claiming responsibility and demanding ransom. The company states the breach was limited to corporate data rather than player information, with no operational impact expected. This incident highlights the growing vulnerability of enterprise cloud infrastructure through third-party vendor relationships, representing a critical supply chain security risk that affects even major gaming companies.