A growing share of this year's largest breaches didn't start with a hacked password or a phishing email at the victim company at all. They started somewhere else entirely: a smaller, third-party app that the victim had connected to their email, CRM, or file storage — and never thought about again after setup day.
The pattern is consistent enough to name. A business connects a scheduling tool, a marketing app, or an AI assistant to their core systems — granting it an access token so it can read calendars, pull contact lists, or send messages on their behalf. That third-party app gets breached. The attacker doesn't need to touch the victim's own defenses at all; they simply use the stolen token, which is often still valid, to walk in through the front door the business opened for a tool it trusted.
Why this has accelerated
Two trends are colliding. Businesses are connecting more third-party and AI-powered tools to their core systems than ever, each one requesting its own slice of access. At the same time, those smaller vendors are frequently a softer target than the large platforms they connect to — fewer security resources, less mature monitoring, and, from an attacker's perspective, a single breach that can unlock access at hundreds of downstream companies at once. Industry reporting has tracked a sharp multi-year rise in exactly this kind of third-party and supply-chain breach.
What you can actually control
For individuals, the same logic applies smaller-scale
You've likely clicked "Continue with Google" or "Allow access" dozens of times for apps you've since forgotten. Each one is a live connection to your account. A periodic look through your Google or Microsoft account's connected-apps page, removing anything you don't recognize or no longer use, closes the same kind of gap at home.
The takeaway
The strongest lock on your own front door doesn't help if you handed a copy of the key to a smaller company with a weaker one. Supply-chain risk isn't solved by better passwords — it's solved by treating every connected app as a standing grant of access that needs periodic review, not a one-time setup step.