Avatier

Attack vector

Third-party or contractor access

Third-party access is a way in that belongs to a vendor, contractor or service provider rather than to the organization itself. Remote support tools, shared accounts and partner connections often carry broad permissions and weaker oversight. When the outside party is compromised, the attacker inherits its trusted path into the organizations it serves.

The path in belonged to a vendor, contractor, or service provider rather than to the filing organization.

How attackers use it

Attackers compromise a supplier's staff account, remote management tool or support portal, then follow the connections that supplier already has into its customers. Vendor accounts can be shared, exempt from the customer's own MFA rules or left active after the contract ends. The traffic arrives from a known partner, so it can blend in with routine work.

What breach letters say

9 distinct incidents in California breach filings name this vector in the letter’s own words (January 1, 2023 – August 14, 2026).

The 3 most recent of 9:

  • “On October 2, 2025, TriZetto Provider Solutions (“TPS”) a Business Associate of our organization, became aware of suspicious activity within a web portal that some of TPS’s healthcare provider customers use to access our systems.”

    LifeLong Medical Care · filed Jan 14, 2026 · letter

  • “The incident occurred at OCHIN’s business associate TriZetto Provider Solutions, a branch of Cognizant Technology Solutions Corporation.”

    County of Santa Barbara Health Department · filed Jan 12, 2026 · letter

  • “On December 12, 2025, San Francisco Community Health Center (SFCHC) was notified by OCHIN, its business associate that supports SFCHC’s Epic electronic health record system, of a data security incident involving one of OCHIN’s subcontractors, TriZetto Provider Solutions (TriZetto), a healthcare eligibility and claims clearinghouse.”

    Asian and Pacific Islander Wellness Center, Inc. dba San Francisco Community Health Center · filed Jan 9, 2026 · letter

See the Identity Attack Ledger

How to stop it

Govern vendor and contractor identities like employee ones: named accounts, MFA, least-privilege access scoped to the engagement, and an end date that removes access automatically. Review third-party access on a fixed schedule.

Terms under this vector

  • Supply chain attack

    A supply chain attack compromises a trusted supplier, such as a software vendor, managed service provider or open-source package, to reach that supplier's customers.

  • Third-party access

    Third-party access is the standing access that vendors, contractors, partners and connected apps hold inside an organization's systems.

  • Vendor email compromise

    Vendor email compromise is a form of business email compromise in which attackers take over or impersonate a supplier's email to defraud the supplier's customers.

Threat actors tied to it

Last reviewed Oct 2, 2026