Supply Chain Statistics

165 stats64 sources

Latest Statistics

Cloud-related threats (40%), third-party breaches (34%), and ransomware (33%) rank after AI as major preparedness gaps.

Cloud SecurityThird-Party RiskRansomwarePreparadnessCyber Resilience

Half of organisations are making changes to vendor, third-party, and supply chain risk management, while 49% are making changes to cyber insurance, incident response, and crisis management.

Supply Chain RiskIncident ResponseCyber InsuranceCrisis Management

Six previously resolving MCP hostnames were unregistered and available for purchase for $4 to $12 per year.

Domain SecuritySupply Chain RiskAI Infrastructure

21% of financial services organizations fully segment third-party access with enforced policy controls.

Third-Party RiskAccess ControlNetwork SecurityFinancial Services

37% of security leaders cited "detecting more than we can fix" as their organization's single biggest obstacle to improving software supply chain security

Software Supply Chain SecuritySupply ChainVulnerabilities

54% of CVE instances observed in third-party production code come from CVEs published more than a year ago.

Contrast SecurityAppSec Overflow 2026·1mo ago
Third-Party RiskVulnerability ManagementSoftware Supply ChainCVEs

Small and midsize companies carry 414 unsanctioned AI tools per 1,000 employees.

AI AdoptionThird-Party RiskAI ToolsAI Risk

79% of third-party applications are authorized.

Third-Party RiskSaaS Governance

31% of manufacturers affected by supplier cyber attacks reported delays to customer deliveries.

ManufacturingUKSupply ChainCyber Incident

30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.

ManufacturingUKSupply ChainCyber Incident

DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.

Supply Chain SecurityAI FrameworksState-Sponsored Threats

In 1H 2026, 87% of identified software registry threats involved malicious npm packages.

Software Supply ChainMalicious Packagesnpm

eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Supply Chain SecurityCredential Theft

Supply chain attacks generated 280.6 million victim notices from 38 initial breach events, impacting 206 entities.

Identity Theft Resource CenterITRC H1 2026 Data Breach Report·2mo ago
Supply ChainVictim NoticesData Breaches

Organisations that knowingly work with risky suppliers are more than four times as likely to experience a supplier-originated cyber incident.

Data Health Check 2026Databarracks·2mo ago
Third-Party RiskSupply Chain

48% of organisations continue working with suppliers despite known resilience or security concerns.

Data Health Check 2026Databarracks·2mo ago
Third-Party RiskBusiness Resilience

26% of organisations identify dependence on suppliers as a main barrier to improving resilience.

Data Health Check 2026Databarracks·2mo ago
Supply ChainBusiness Resilience

Nearly a quarter (24%) of 17,651+ tracked Model Context Protocol (MCP) servers carry at least one vulnerability.

Supply ChainServer VulnerabilitiesMCP

28.6% of 130,667 cataloged tools are classified as high risk.

Tooling RiskSupply ChainAI Tools

38% of restaurant chains say reliance on third-party vendors increases their cyber risk.

Third-Party RiskRestaurantsCyber Risk

62% of restaurant chains work with six or more third-party vendors per location.

Third-Party RiskSupply ChainRestaurants

28% of restaurant chains had third-party platform data exposed in the past year.

Data ExposureThird-Party RiskRestaurants

28% of the top 100 vendors most commonly used by universities have experienced a data breach since 2024.

Data BreachThird-Party RiskHigher EducationThird-Party Supply Risk

95% of universities have at least one vendor with embedded AI exposure.

AI ExposureHigher EducationThird-Party RiskAI Exposure

Around 50% of universities have detectable third-party AI embedded in their services.

AI IntegrationHigher EducationThird-Party Risk

64 European organisations were drawn into a ransomware or data extortion incident through a third party.

Third-Party RiskRansomwareSupply Chain

Among organizations with confirmed AI-related security incidents, Shadow AI contributed to 44% of incidents, data or model poisoning 41%, improper output handling 41%, supply chain vulnerabilities 35%, and prompt injection 34%.

AI SecurityAttack VectorsSupply ChainShadow AI

53% of the organisations drawn into third-party ransomware or data extortion incidents traced to a single event: the August 2025 compromise of Miljödata.

Third-Party RiskRansomwareSupply Chain

36% of security and IT leaders identify third-party vendor or supply chain breaches involving integrated AI or agents as security incidents tied to AI systems.

Supply ChainAI Security

63% of healthcare practices do not continuously monitor their digital supply chains.

Supply ChainHealthcare

38% of organizations in MEA report reliance on third-party ecosystems and vendors, increasing supply-chain blind spots.

Third-Party RiskSupply ChainMiddle EastAfricaMEA

33% of organizations identify third-party vendors as a major visibility gap.

Third-Party RiskOperational Visibility

16% of security professionals say supply chain and third-party risk is the boardroom cyber priority boards ask about most.

Supply ChainBoardroom RiskThird-Party Risk

41% of cybersecurity professionals identify AI-powered attacks at scale as their biggest security concern, compared with 21% citing supply chain risk and 21% citing unknown threats.

AI ThreatsSupply ChainAI-Powered Attacks

70% of security leaders say their organizations apply risk controls only to key suppliers.

Third-Party RiskSupply Chain

98% of security leaders are concerned about the risks of giving third-party AI-based systems, including large language models, access to company data.

Data SecurityThird-Party AIThird-Party RiskLLMs

79% of security leaders are concerned or very concerned that suppliers' and partners' AI tool use poses a cybersecurity risk to their organization.

Third-Party RiskThird-Party RiskAI

The Axios NPM package was downloaded 100 million times per week.

Open SourceSupply ChainSoftware Distribution

Malware operators compromised 350 GitHub repositories to inject malicious code into JavaScript and Python projects.

Supply ChainOpen SourceSoftware SecurityGitHub

72% of organizations are structurally incapable of auditing embedded AI Software Development Kits (SDKs) hidden inside everyday mobile applications.

Supply ChainMobile Security