Close Menu
  • USA
  • Canada
  • Mexico
  • Brazil
  • Colombia
  • Argentina
  • Submit Press Release
  • News Feed
  • About Fintech News Network
  • FNN Media Kit
  • America Fintech Newsletter
  • Submit Press Release
  • Contact Us
LinkedIn Facebook X (Twitter) RSS
  • About Fintech News Network
  • Contact Us
  • Work With Us
  • FNN Media Kit
  • Submit Press Release
  • Newsletter
Fintech News America

Fintech News Network

LinkedIn Facebook X (Twitter) Instagram RSS
Free Newsletter
  • USA
  • Canada
  • Mexico
  • Brazil
  • Colombia
  • Argentina
  • Submit Press Release
Fintech News America

Fintech News Network

Home » News » Third-Party Risks Drive Nearly Half of Fintech Breaches
USA

Third-Party Risks Drive Nearly Half of Fintech Breaches

SecurityScorecard’s 2025 report reveals structural vulnerabilities in the fintech supply chain, urging stronger oversight of vendors and shared infrastructure
Fintech News AmericaFintech News America21 May 20253 Mins Read
Share LinkedIn Facebook Twitter Telegram Copy Link Email
Third-Party Risks Drive Nearly Half of Fintech Breaches
Share
LinkedIn Facebook Twitter Telegram Copy Link Email
Free Newsletter

Subscribe to the most important Fintech America News

SecurityScorecard has published its 2025 sector report, Defending the Financial Supply Chain: Strengths and Vulnerabilities in Top Fintech Companies, highlighting that 41.8% of cybersecurity breaches affecting leading fintech firms stemmed from third-party vendors.

The report, based on an in-depth analysis of the cybersecurity posture of 250 of the world’s top fintech companies, underscores a growing disparity between robust internal controls and external supply chain vulnerabilities.

Ryan Sherstobitoff
Ryan Sherstobitoff

“Fintech companies anchor global finance, but one exposed vendor can take down critical infrastructure,”

said Ryan Sherstobitoff, Senior Vice President of SecurityScorecard’s STRIKE Threat Research and Intelligence Unit.

“Third-party breaches aren’t edge cases, they reveal structural risk. In fintech, that means operational outages across payment systems, digital asset platforms, and core financial infrastructure.”

Among the key findings, 18.4% of fintech companies had experienced publicly reported breaches, with 28.2% of those reporting multiple incidents.

Third-party vectors were responsible for 41.8% of breaches, while fourth-party exposures accounted for an additional 11.9%, more than double the global average.

Technology products and services played a significant role in third-party breaches, particularly file transfer software and cloud platforms.

Source: SecurityScorecard
Source: SecurityScorecard

Despite these challenges, fintech firms recorded the strongest cybersecurity posture of any industry studied, with a median SecurityScorecard rating of 90.

Notably, 55.6% of companies received an “A” grade.

However, application security and DNS health were cited as the most prevalent weaknesses.

Nearly 46.4% of companies scored lowest in application security, with issues such as unsafe redirect chains, misconfigured storage, and missing SPF records being common.

In response to these findings, the STRIKE team outlined several recommendations for the fintech sector.

First, firms should enhance oversight of third- and fourth-party risks by classifying vendors based on their exposure and breach history, rather than just financial value or business importance.

Including contractual clauses for breach notifications and disclosing downstream dependencies can help mitigate the risk of cascading incidents.

Additionally, fintechs are encouraged to secure shared infrastructure and technical enablers, especially file transfer systems, cloud storage, and communication tools.

Source: SecurityScorecard
Source: SecurityScorecard

Regular audits and requiring partners to follow secure implementation practices are advised.

Closing critical application security and DNS gaps should be a priority, with an emphasis on securing customer-facing assets.

To address credential-based threats, companies should enforce multi-factor authentication (MFA), monitor for reused credentials, and act swiftly to take down spoofed domains.

These steps are essential in combating credential stuffing and typosquatting attacks, which have impacted a majority of firms.

Finally, the report stresses the importance of treating repeat breaches as a significant risk signal.

Vendors with a history of multiple incidents, particularly involving third-party exposure, should be subjected to stricter scrutiny during onboarding and contract renewals.

 

Featured image credit: Edited by Fintech News America, based on image by Evgenymedia via Freepik

SecurityScorecard
Share. LinkedIn Facebook Twitter Telegram Copy Link Email

Author

Avatar photo
Fintech News America
  • Facebook
  • X (Twitter)
  • LinkedIn

Related Posts

Top Fintech Events in North America to Attend in H2 2026

Top Fintech Events in North America to Attend in H2 2026

3 September 2026
NewCo Capital Bizcap US

NewCo Capital Rebrands to Bizcap US, Strengthening Support for Brokers, ISOs

8 July 2026
Alpaca Raises $150M, Reaches Unicorn Status

Alpaca Raises $150M, Reaches Unicorn Status

15 January 2026
Fintech Outsourcing Philippines The 2026 Guide to BPO Success

Fintech Outsourcing Philippines: The 2026 Guide to BPO Success

13 January 2026
Rain Raises $250M to Expand Stablecoin Payments Infrastructure

Rain Raises $250M to Expand Stablecoin Payments Infrastructure

12 January 2026
Societe Generale Completes First US Digital Bond Using Broadridge Tokenisation

Societe Generale Completes First US Digital Bond Using Broadridge Tokenisation

19 November 2025
Bizcap Acquires 8fig to Bolster Global Fintech Expansion

Bizcap Acquires 8fig to Bolster Global Fintech Expansion

22 October 2025
PayPal Ventures Invests in Stable to Expand Reach of PayPal USD Stablecoin

PayPal Ventures Invests in Stable to Expand Reach of PayPal USD Stablecoin

23 September 2025
Newsletter
Follow Us
  • LinkedIn
  • Facebook
  • X / Twitter
  • Instagram
Search
Recent Posts
  • Revolut Gains Colombia Banking Licence as 200,000 Join Waitlist
  • Top Fintech Events in North America to Attend in H2 2026
  • Booya Named Most Innovative Digital Lending Platform for Financial Inclusion in Mexico
  • Wise Expands Digital Remittance Services to Chile
  • NewCo Capital Rebrands to Bizcap US, Strengthening Support for Brokers, ISOs
Navigation
  • About Fintech News Network
  • Work With Us
  • FNN Media Kit
  • America Fintech Newsletter
  • Contact Us
  • Privacy Policy / Disclaimer
Other Publications by Fintech News Network
Fintech News America
Fintech News Switzerland
Fintech News Baltic
Fintech News Nordics
Fintech News Singapore
Fintech News UAE
Fintech News Africa
Fintech News Hong Kong
Fintech News Malaysia
Fintech News Philippines
Fintech News Network Indonesia
Fintech News Network Australia
Get Informed

Subscribe to Updates

Subscribe to the most important Fintech America News

  • About Fintech News Network
  • Work With Us
  • FNN Media Kit
  • America Fintech Newsletter
  • Contact Us
  • Privacy Policy / Disclaimer
© 2015 - 2026 Copyright CK Finanzpro GmbH. All Rights reserved.

Type above and press Enter to search. Press Esc to cancel.