Supply Chain vs Insider Threat

Supply Chain

156

statistics from 57 sources

Insider Threat

144

statistics from 26 sources

Latest Supply Chain

The Axios NPM package was downloaded 100 million times per week.

Open SourceSupply ChainSoftware Distribution

Malware operators compromised 350 GitHub repositories to inject malicious code into JavaScript and Python projects.

Supply ChainOpen SourceSoftware SecurityGitHub

DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.

Supply Chain SecurityAI FrameworksState-Sponsored Threats

In 1H 2026, 87% of identified software registry threats involved malicious npm packages.

Software Supply ChainMalicious Packagesnpm

eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Supply Chain SecurityCredential Theft

Supply chain attacks generated 280.6 million victim notices from 38 initial breach events, impacting 206 entities.

Identity Theft Resource CenterITRC H1 2026 Data Breach Report·1mo ago
Supply ChainVictim NoticesData Breaches

48% of organisations continue working with suppliers despite known resilience or security concerns.

Data Health Check 2026Databarracks·1mo ago
Third-Party RiskBusiness Resilience

26% of organisations identify dependence on suppliers as a main barrier to improving resilience.

Data Health Check 2026Databarracks·1mo ago
Supply ChainBusiness Resilience

89% of businesses assess supplier resilience at onboarding.

Data Health Check 2026Databarracks·1mo ago
Supply ChainRisk Management

Nearly a quarter (24%) of 17,651+ tracked Model Context Protocol (MCP) servers carry at least one vulnerability.

Supply ChainServer VulnerabilitiesMCP

28.6% of 130,667 cataloged tools are classified as high risk.

Tooling RiskSupply ChainAI Tools

38% of restaurant chains say reliance on third-party vendors increases their cyber risk.

Third-Party RiskRestaurantsCyber Risk

62% of restaurant chains work with six or more third-party vendors per location.

Third-Party RiskSupply ChainRestaurants

28% of restaurant chains had third-party platform data exposed in the past year.

Data ExposureThird-Party RiskRestaurants

28% of the top 100 vendors most commonly used by universities have experienced a data breach since 2024.

Data BreachThird-Party RiskHigher EducationThird-Party Supply Risk
View all Supply Chain

Latest Insider Threat

Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.

Identity Theft Resource CenterITRC H1 2026 Data Breach Report·1mo ago
Insider Threat

50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments

Insider RiskAI GovernanceFederal agenciesAgentic AI

41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.

Insider ThreatAIHuman Risk

68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.

Human RiskAIInsider Threat

40% of CISOs fear employees are sharing sensitive information with generative AI platforms.

Data SecurityGenerative AIInsider RiskHuman Risk

38% of security and IT leaders report attacker activity mirrors legitimate, authorized workflows and processes, delaying critical alerts.

Insider ThreatDetectionCritical Alerts

12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.

Access ControlInsider RiskPrivileged Access

80% of organizations report shadow AI (employees connecting AI tools without security or IT review).

Shadow AIInsider RiskAI Security

17% of Nordic CISOs cited insiders & human error as their primary concern.

TruesecNordic CISO Report 2026·2mo ago
The NordicsInsider RiskHuman ErrorSecurity Concerns

Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.

Shadow AIAI AdoptionInsider RiskAgentic AI

Shadow AI is now the third most common non-malicious insider action detected in Verizon's data loss prevention (DLP) dataset in 2025

Shadow AIInsider Risk

13% of employees say they’ve sold or know someone who has sold company login details – often under the belief it’s harmless

CredentialsLogin DetailsInsider ThreatInsider Risk

90% of organizations experienced at least one insider incident in the past 12 months.

Gurucul2026 Insider Risk Report·5mo ago
Insider RiskInsider Incidents

74% of organizations rank negligent insiders as their top concern, surpassing compromised accounts (65%) and malicious insiders (59%).

Gurucul2026 Insider Risk Report·5mo ago
Insider RiskCompromised AccountsMalicious InsiderNegligent Insiders

45% of organizations classify AI copilots and generative AI tools as insider risk.

Gurucul2026 Insider Risk Report·5mo ago
AIInsider RiskAI CopilotsGen AI
View all Insider Threat