§ The Long Read

The deep work behind
the wire.

Research-led explainers, breach postmortems, regulatory briefs, and playbooks. Long-form work from the Supplier Shield desk and Abilene Advisors partners.

§ Archive

Every long read.

All59Uncategorized59
Jscrambler's own npm package was hijacked: a trusted supplier became a supply-chain vectorLong read

Jscrambler's own npm package was hijacked: a trusted supplier became a supply-chain vector

An attacker hijacked Jscrambler's npm package with a stolen publishing credential and shipped an infostealer to developers between 11 and 13 July 2026. The malware harvested cloud tokens, wallets and AI-assistant credentials from any machine that installed it. For third-party risk teams, the lesson is that a trusted dependency is a supplier, and its release channel can become the attack path.

Supplier Shield teamJul 15, 2026
Lidl online shop data breach started at an IT service provider, not the retailer's own systemsLong read

Lidl online shop data breach started at an IT service provider, not the retailer's own systems

Lidl has told online shop customers in Germany, Belgium and the Netherlands that their data was stolen in a breach at an IT service provider, not in its own systems. Names, phone numbers, email addresses, dates of birth and customer numbers were taken; payment data is not yet ruled out. Under GDPR the controller stays accountable for a processor's breach.

Supplier Shield teamJul 15, 2026
Progress tells ShareFile customers to pull the plug: an ICT supplier's threat becomes everyone's downtimeLong read

Progress tells ShareFile customers to pull the plug: an ICT supplier's threat becomes everyone's downtime

On 10 July 2026 Progress Software told ShareFile customers running Storage Zone Controllers to shut down the hosting Windows servers over a credible external threat. No patch, no CVE, and cloud access to affected accounts disabled. The pattern is concentration risk: one widely used file-sharing supplier is a single point of exposure, and its emergency is inherited by everyone downstream, including firms that only touch it through a vendor.

Supplier Shield teamJul 14, 2026
AdaptHealth breach reached patient data through a third-party contractor's stolen credentialsLong read

AdaptHealth breach reached patient data through a third-party contractor's stolen credentials

AdaptHealth told the SEC that attackers reached patient data through a third-party contractor's stolen credentials, obtained by social engineering. The number of affected individuals is not yet confirmed. For third-party risk teams, contractor and vendor accounts are part of the attack surface.

Supplier Shield teamJul 14, 2026
Deutsche Bank incident began at a third-party marketing platform, not the bank's networkLong read

Deutsche Bank incident began at a third-party marketing platform, not the bank's network

A cyber incident tied to Deutsche Bank started at a third-party marketing and incentive platform in Germany, not the bank's own network. The Unsafe ransomware group posted alleged employee records; Deutsche Bank says its systems were not affected and the scope is unconfirmed. For financial firms, the lesson is a DORA register one: an edge supplier that holds employee or partner data still belongs in scope.

Supplier Shield teamJul 14, 2026
Hemmersbach ransomware claim: why a breach at an IT services supplier reaches toward its clientsLong read

Hemmersbach ransomware claim: why a breach at an IT services supplier reaches toward its clients

A ransomware group has claimed a breach of Hemmersbach, a German IT services provider that works inside its clients' technology estates. Researchers say the exposed data includes credentials to the firm's own identity systems. Hemmersbach has not confirmed the attack and the scope is unverified. For third-party risk teams, the lesson is about vendor access: a supplier's stolen login can become a route toward the clients it serves.

Supplier Shield teamJul 13, 2026
Fake Paysafe, Skrill and Neteller SDKs on npm and PyPI turned payment developers into a supply-chain targetLong read

Fake Paysafe, Skrill and Neteller SDKs on npm and PyPI turned payment developers into a supply-chain target

Researchers found 17 fake Paysafe, Skrill and Neteller packages on npm and PyPI that steal API keys and CI tokens from developer and build machines. Nothing was breached at the payment firms. The exposure came through a poisoned dependency, which shows why the package registry is a supplier.

Supplier Shield teamJul 13, 2026
Accenture breach: source code and cloud keys claimed stolen from a supplier many firms rely onLong read

Accenture breach: source code and cloud keys claimed stolen from a supplier many firms rely on

Accenture confirmed a security incident on 8 July 2026 after a threat actor listed about 35 GB of source code and cloud access keys for sale. The company called it isolated and remediated, but did not confirm scope or client-data impact. For third-party risk teams, the exposure is the client pipelines and cloud tenants a services provider touches.

Supplier Shield teamJul 10, 2026
KDDI email breach: how one shared email platform exposed up to 14.2 million logins across six ISPsLong read

KDDI email breach: how one shared email platform exposed up to 14.2 million logins across six ISPs

One email platform run by KDDI exposed the logins of up to 14.2 million customers across six Japanese internet providers. The lesson for third-party risk teams is concentration and fourth-party risk: many brands on one shared supplier system, breached through a third-party software flaw.

Supplier Shield teamJul 8, 2026
iRhythm breach: how patient data left through third-party-hosted business appsLong read

iRhythm breach: how patient data left through third-party-hosted business apps

Cardiac-monitoring firm iRhythm says attackers took patient health data, proprietary data and personal information from third-party-hosted business applications, not from its clinical systems. For third-party risk teams the lesson is that regulated data often lives with a vendor, and that is where it leaves.

Supplier Shield teamJul 8, 2026
Klue OAuth breach: how one connected app exposed CRM data at Huntress, Jamf and other customersLong read

Klue OAuth breach: how one connected app exposed CRM data at Huntress, Jamf and other customers

The Icarus extortion group stole the OAuth tokens Klue held for its customers and used them to take data from those customers' own Salesforce and Gong accounts. For third-party risk teams the lesson is fourth-party risk: a connected SaaS app can turn a supplier's breach into your data loss.

Supplier Shield teamJul 7, 2026
Vendor due diligence: the 2026 checklist for regulated teamsLong read

Vendor due diligence: the 2026 checklist for regulated teams

A practical vendor due diligence checklist for 2026, tiered by risk and mapped to what DORA, NIS2, and GDPR now expect, including the fourth-party checks most teams skip.

Supplier Shield teamJul 7, 2026
Oracle PeopleSoft zero-day (CVE-2026-35273): how one HR platform breached 100-plus organisationsLong read

Oracle PeopleSoft zero-day (CVE-2026-35273): how one HR platform breached 100-plus organisations

A single Oracle PeopleSoft zero-day let the ShinyHunters group breach more than 100 organisations, from the University of Nottingham to Nissan. The lesson for third-party risk teams is concentration risk: shared vendor software turns one flaw into many incidents at once.

Supplier Shield teamJul 7, 2026
Long read

Cross-Border Data Transfers Between Switzerland and France: A Compliance Guide

Personal data flows freely between Switzerland and France in both directions with no SCCs required. Learn when SCCs and Transfer Impact Assessments apply, how FADP Article 9 compares to GDPR Article 28, and what financial-sector overlays apply.

Supplier ShieldJun 1, 2026
Amazon employee data breach exposes hidden dangers in the digital supply chainLong read

Amazon employee data breach exposes hidden dangers in the digital supply chain

Amazon’s recent data breach reveals hidden risks in third-party vendors. Learn how proactive supply chain security can help prevent such vulnerabilities.

Supplier ShieldApr 29, 2026
Browsers: The new AI battleground and 2025�s biggest security testLong read

Browsers: The new AI battleground and 2025�s biggest security test

Browsers are the new AI security battleground. Anthropic�s Claude for Chrome shows how browser agents can boost productivity but expose enterprises to prompt injection, data leaks, and governance risks. Learn why AI browser security, agentic workflows, and third-party risk management must be built i...

Supplier ShieldApr 29, 2026
Could scrapping IP laws supercharge AI—or leave your business exposed?Long read

Could scrapping IP laws supercharge AI—or leave your business exposed?

As Dorsey and Musk push to scrap IP laws, learn how this AI shift could expose your business to third-party risks—and how to stay protected.

Supplier ShieldApr 29, 2026
Cyber supply chain risk management: From visibility gaps to resilience at scaleLong read

Cyber supply chain risk management: From visibility gaps to resilience at scale

Build a resilient cyber supply chain risk management program. Learn the latest market trends, key challenges, future predictions, and real-world case studies. Get a 90-day plan to reduce vendor risk and meet regulations like NIS2 and DORA.

Supplier ShieldApr 29, 2026
Data transfer regulations: Impact on Swiss and USA companiesLong read

Data transfer regulations: Impact on Swiss and USA companies

Discover how data transfer regulations impact Swiss and U.S. companies. Learn about the Swiss FADP, U.S. national security rules, and how Supplier Shield helps businesses navigate compliance with expert advisory, managed services, and a secure cloud platform.

Supplier ShieldApr 29, 2026
DeepSeek vs ChatGPT: What they mean for supplier risk managementLong read

DeepSeek vs ChatGPT: What they mean for supplier risk management

DeepSeek AI vs. ChatGPT: A look at features, risks, and data privacy concerns. Learn how supply risk management can help businesses stay secure.

Supplier ShieldApr 29, 2026
Detailed analysis: Why EU and Swiss companies must rely on European-rooted cybersecurity partnersLong read

Detailed analysis: Why EU and Swiss companies must rely on European-rooted cybersecurity partners

In a shifting geopolitical world, discover why European-rooted cybersecurity partners are critical for EU and Swiss organizations. Explore the growing supply chain threats, legal risks with U.S. tech providers, and the importance of digital sovereignty in third-party risk management (TPRM).

Supplier ShieldApr 29, 2026
Empowering procurement-led third-party risk managementLong read

Empowering procurement-led third-party risk management

Learn how procurement-led third-party risk management supports NIS2 compliance, boosts resilience, and improves supplier oversight.

Supplier ShieldApr 29, 2026
Empowering TPRM: Essential resources and tools for effective risk managementLong read

Empowering TPRM: Essential resources and tools for effective risk management

Manage third-party risk with TPRM tools. Automate assessments, ensure compliance, and get real-time threat intelligence. Learn more in our guide.

Supplier ShieldApr 29, 2026
Ensuring continual excellence: Monitoring and managing third-party performanceLong read

Ensuring continual excellence: Monitoring and managing third-party performance

Manage third-party performance with our guide. Set metrics, use monitoring tools, and conduct reviews. Streamline with TPRM solutions like Supplier Shield.

Supplier ShieldApr 29, 2026
EU Digital Operational Resilience Act (DORA) & third-party risk management (TPRM) 2025Long read

EU Digital Operational Resilience Act (DORA) & third-party risk management (TPRM) 2025

Learn how DORA strengthens financial resilience through third-party risk management, compliance, and ICT vendor oversight for EU firms.

Supplier ShieldApr 29, 2026
Financial services vendor risk management under new regulatory pressureLong read

Financial services vendor risk management under new regulatory pressure

Financial services vendor risk under new regulatory pressure: explore banking third‑party risk, DORA compliance for vendors, and vendor risk strategies.

Supplier ShieldApr 29, 2026
From vendor breach to boardroom liability: How the EU AI act changes accountability for suppliersLong read

From vendor breach to boardroom liability: How the EU AI act changes accountability for suppliers

The EU AI Act makes both vendors and buyers liable for supplier AI failures, fines can reach €35M or 7% of turnover. Supplier Shield helps you track and mitigate that risk.

Supplier ShieldApr 29, 2026
How 4.2 Million Internet Hosts Were Hijacked: What You Need to KnowLong read

How 4.2 Million Internet Hosts Were Hijacked: What You Need to Know

Discover how vulnerabilities in tunneling protocols expose 4.2M internet hosts to attacks. Learn about the risks, affected regions, and essential steps to protect your network and supply chain.

Supplier ShieldApr 29, 2026
How can financial risks in a supply chain be managed?Long read

How can financial risks in a supply chain be managed?

Learn how to manage financial risks in supply chains effectively. Discover strategies to mitigate supplier instability, credit risks, and market volatility for resilient operations.

Supplier ShieldApr 29, 2026
How can I identify and assess the risks posed by my third parties?Long read

How can I identify and assess the risks posed by my third parties?

Simplify third-party risk management with Supplier Shield. Identify risks, implement strategies, collaborate, monitor, protect data, and boost efficiency.

Supplier ShieldApr 29, 2026
How Supplier Shield enhances GDPR compliance in vendor managementLong read

How Supplier Shield enhances GDPR compliance in vendor management

Learn how Supplier Shield improves GDPR compliance in vendor management with automated risk assessments, consent tracking, and breach notifications.

Supplier ShieldApr 29, 2026
How Supplier Shield protects against data breach risks from third-party vulnerabilitiesLong read

How Supplier Shield protects against data breach risks from third-party vulnerabilities

Discover how Supplier Shield helps mitigate risks from third-party and supplier vulnerabilities, protecting businesses from different risks.

Supplier ShieldApr 29, 2026
Let’s talk about the landscape of third-party risks: A comprehensive overviewLong read

Let’s talk about the landscape of third-party risks: A comprehensive overview

Effectively manage third-party risks with TPRM tools. Identify and mitigate cybersecurity, financial, and compliance risks. Learn more with our guide.

Supplier ShieldApr 29, 2026
Mastering NIS2 compliance: A no-nonsense guide for businessesLong read

Mastering NIS2 compliance: A no-nonsense guide for businesses

Learn how NIS2 changes cybersecurity rules for EU businesses, the risks of non-compliance, and how real-world strategies can help you meet the 2024 deadline and strengthen your security posture.

Supplier ShieldApr 29, 2026
Mastering supplier risk management: Your ultimate guide to building resilient and transparent supply chainsLong read

Mastering supplier risk management: Your ultimate guide to building resilient and transparent supply chains

Learn how to effectively manage supplier risks by identifying, assessing, and mitigating potential disruptions to ensure smooth operations and compliance.

Supplier ShieldApr 29, 2026
Maximizing efficiency and cost-effectiveness in TPRM programsLong read

Maximizing efficiency and cost-effectiveness in TPRM programs

Prioritize high-risk vendors, use advanced TPRM tools, and standardize processes. Save costs and mitigate risks. Learn more in our guide.

Supplier ShieldApr 29, 2026
Navigating regulatory waters: Key compliance considerations for TPRMLong read

Navigating regulatory waters: Key compliance considerations for TPRM

Struggling with TPRM? Our guide covers GDPR, HIPAA, PCI DSS, and more. Learn robust strategies and advanced solutions. Stay compliant and secure.

Supplier ShieldApr 29, 2026
NIS2 compliance in manufacturing: how to secure your supply chain and meet EU requirementsLong read

NIS2 compliance in manufacturing: how to secure your supply chain and meet EU requirements

Discover how manufacturers can achieve NIS2 compliance, secure their supply chains, and reduce third-party risk. Learn practical steps and see how Supplier Shield simplifies compliance.

Supplier ShieldApr 29, 2026
Responding to third-party security breaches: A clear action planLong read

Responding to third-party security breaches: A clear action plan

Prepare for third-party breaches. Create a response plan, activate a team, and use advanced tech for monitoring. Learn more in our guide.

Supplier ShieldApr 29, 2026
Secure onboarding and contracting: TPRM best practicesLong read

Secure onboarding and contracting: TPRM best practices

Simplify third-party onboarding. Learn to create frameworks, conduct due diligence, use TPRM tools, and establish clear contracts. Enhance resilience.

Supplier ShieldApr 29, 2026
Showcasing TPRM success: Communicating effectiveness to stakeholdersLong read

Showcasing TPRM success: Communicating effectiveness to stakeholders

Win stakeholder support for TPRM by tracking KPIs, risk reduction, demonstrating compliance, improving vendor performance, and leveraging technology.

Supplier ShieldApr 29, 2026
Starbucks faces cyber attack fallout: Could your coffee routine be at risk?Long read

Starbucks faces cyber attack fallout: Could your coffee routine be at risk?

Ransomware hits Starbucks supply chain—barista pay and schedules disrupted. Could your daily coffee fix be next? Here's what you need to know!

Supplier ShieldApr 29, 2026
Supplier risk management best practices to protect your supply chain in 2025Long read

Supplier risk management best practices to protect your supply chain in 2025

Explore supplier risk management best practices to mitigate disruptions, build resilient supply chains, and embrace future trends like blockchain and IoT.

Supplier ShieldApr 29, 2026
The best third-party risk management software for teams still stuck in ExcelLong read

The best third-party risk management software for teams still stuck in Excel

Still managing vendor risk in Excel? This guide compares the top TPRM software of 2025, and shows why Swiss-built Supplier Shield is the go-to choice for lean teams ready to scale.

Supplier ShieldApr 29, 2026
The hidden costs of Inadequate TPRM: A Swiss perspectiveLong read

The hidden costs of Inadequate TPRM: A Swiss perspective

Uncover the hidden costs of poor TPRM in Switzerland. Learn how to protect your business from financial, reputational, and operational risks

Supplier ShieldApr 29, 2026
The hidden risks of AI: What businesses can learn from AI cheating in chessLong read

The hidden risks of AI: What businesses can learn from AI cheating in chess

AI isn't perfect�learn from chess AI cheating incidents and find out how to safeguard your business against emerging cyber threats

Supplier ShieldApr 29, 2026
The Importance of third-party risk management in Switzerland's strict regulatory frameworkLong read

The Importance of third-party risk management in Switzerland's strict regulatory framework

Discover how Swiss regulations impact third-party risks. Learn to protect your business, ensure compliance, and thrive in a complex regulatory landscape.

Supplier ShieldApr 29, 2026
The ultimate guide to building a risk-aware culture: strategies top companies useLong read

The ultimate guide to building a risk-aware culture: strategies top companies use

Learn how top companies build a risk-aware culture to navigate emerging risks, improve decision-making, and boost resilience through training, technology, and certifications.

Supplier ShieldApr 29, 2026
The ultimate guide to cybersecurity vendor risk management (VRM) in 2024Long read

The ultimate guide to cybersecurity vendor risk management (VRM) in 2024

Discover the importance of cybersecurity vendor risk management (VRM) in safeguarding your organization. Learn key strategies, best practices, and how to mitigate risks from third-party vendors effectively.

Supplier ShieldApr 29, 2026
The ultimate guide to supplier compliance management: Mastering TPRM in 2025Long read

The ultimate guide to supplier compliance management: Mastering TPRM in 2025

Master supplier compliance management with this comprehensive guide. Explore key components, best practices, challenges, and future trends to enhance risk mitigation and ensure regulatory adherence.

Supplier ShieldApr 29, 2026
Third-party risk management software: What you need to know in 2025Long read

Third-party risk management software: What you need to know in 2025

Compare top third-party risk management software for EU & Swiss companies. Discover tools aligned with NIS2, GDPR & DORA—without enterprise complexity.

Supplier ShieldApr 29, 2026
Top 7 UK third-party risk management challenges: overcoming compliance hurdlesLong read

Top 7 UK third-party risk management challenges: overcoming compliance hurdles

Third-party relationships drive innovation but introduce risks. A KPMG survey found 72% of financial services firms faced operational disruptions from third-party incidents. UK companies must manage these risks while complying with regulations like GDPR.

Supplier ShieldApr 29, 2026
UBS and DSM-Firmenich hit by employee data theft in major cyberattackLong read

UBS and DSM-Firmenich hit by employee data theft in major cyberattack

UBS and DSM-Firmenich data breach exposes 7.9M employees. Learn how proactive vendor risk management can prevent third-party vulnerabilities.

Supplier ShieldApr 29, 2026
Understanding TPRM: Managing third-party risks for organizational resilienceLong read

Understanding TPRM: Managing third-party risks for organizational resilience

Discover TPRM: what it is, why it matters, and how to implement it. Learn how to identify and mitigate risks from outsourcing to third-party vendors.

Supplier ShieldApr 29, 2026
What if your private conversations were leaked? Worst telecom hack in USA history.Long read

What if your private conversations were leaked? Worst telecom hack in USA history.

Protect your business from telecom hacks like Salt Typhoon. Secure networks, protect data, and build trust with proactive cybersecurity solutions.

Supplier ShieldApr 29, 2026
What is Supplier Shield? Your guide to streamlining supplier risks and complianceLong read

What is Supplier Shield? Your guide to streamlining supplier risks and compliance

Discover what Supplier Shield is and how our managed service helps businesses reduce supplier risks, ensure compliance, and improve efficiency.

Supplier ShieldApr 29, 2026
What is the Best TPRM Software for European Companies in 2026?Long read

What is the Best TPRM Software for European Companies in 2026?

Compare 10 top TPRM software solutions for NIS2 and DORA compliance. Honest reviews, pricing, EU features, and implementation times. Updated Mar 2026.

Supplier ShieldApr 29, 2026
What Is the EU AI Act? Complete Guide (2025)Long read

What Is the EU AI Act? Complete Guide (2025)

EU AI Act is the world's first AI regulation with penalties up to €35M. Learn risk categories, compliance deadlines (2025-2027), and high-risk AI requirements.

Supplier ShieldApr 29, 2026
What Is TPRM? Third-Party Risk Management Explained (2025)Long read

What Is TPRM? Third-Party Risk Management Explained (2025)

TPRM manages risks from vendors, suppliers, and partners. Learn why 30% of breaches involve third parties and how to implement TPRM for NIS2 and DORA compliance.

Supplier ShieldApr 29, 2026
The Daily Brief

Get every new long read in your inbox.

One email a day. Five disclosures from the Breach Wire plus every new long read from the desk.