{
  "id": 9434589,
  "title": "The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors",
  "url": "https://urgent.news/2026/09/23/the-credential-relay-economy-how-supply-chain-attacks-chain-through",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-23T22:40:12.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jeffreyciend/the-credential-relay-economy-how-supply-chain-attacks-chain-through-saas-vendors-lbm"
  },
  "original_language": "en",
  "account": "In the world of business, third-party vendors play a crucial role in the operations of many companies. However, a report from 2026 reveals that 48% of breaches are linked to third-party involvement, an increase of 60% year over year. This surge in vulnerability is often due to stolen credentials from one vendor being used against that vendor's customers.\n\nA notable case is the Telus Digital breach in March 2026, where attackers stole Google Cloud Platform credentials from a previous Salesloft Drift breach. The attackers then used these credentials to infiltrate Telus Digital's systems, exfiltrating data from BigQuery instances and scanning support tickets for additional secrets. The attackers then moved laterally across the network, causing damage to 760 companies.\n\nAnother concerning incident occurred in August 2026 with the LiteLLM API gateway, which was compromised in a supply chain poisoning attack. This attack lasted for roughly 40 minutes and affected around 2,500 organizations, exposing over 195TB of password data. The attackers transmitted the compromise to all these companies within the time it takes for a meeting to run long.\n\nThe implications of these events are severe. The average time to identify and contain breaches that start at an infected supplier is 258 days, which is 11 days longer than the global average. This delay in detection is exacerbated by the fact that stolen credentials from one vendor can be replayed against that vendor's customers, creating a \"credential relay economy.\"\n\nTo mitigate these risks, companies should treat vendor breach disclosures as rotation triggers rather than mere news items. They should also maintain an inventory of SaaS platforms and integration credentials to ensure that the rotation list is up-to-date. Additionally, companies should closely monitor for secret-scanning activity in their own data, as attackers often use such tools to find vulnerabilities. The 258-day containment time highlights the cost of learning about a supplier compromise from the outside, underscoring the importance of proactive measures to prevent such breaches.",
  "summary": "The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors The 2026 Verizon DBIR put third-party involvement in confirmed breaches at 48 percent, up 60 percent year over year after doubling the year before. IBM's Cost of a Data Breach 2026 report added the response-side number: breaches that begin at an infected supplier take an average of 258 days to identify and contain,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}