Third-party identity risk is the exposure created when a supplier reaches your SaaS consoles and crown-jewel data using their own credentials, tokens, or service accounts – from devices and integrations you neither manage nor monitor, outside every zero-trust control you apply to your own staff. That gap – a trusted identity you cannot enforce controls on – is why a vendor’s identity is now the most common path into your data. Nearly half of all breaches (48%) now involve a third party, up roughly 60% in a single year (Verizon 2026 DBIR via SecurityWeek). This post explains how a vendor’s identity becomes a bridge into your data, why questionnaires cannot see it, and what continuous monitoring catches instead.
Why is a vendor’s identity the most common path into your data?
A vendor’s identity is the most common path because it bypasses the boundary you defend: your zero-trust architecture governs the identities you manage, and a supplier brings their own. That asymmetry is now the dominant breach mechanic – third-party involvement climbed to 48% of the 2026 DBIR’s 22,000-plus confirmed breaches. One shift matters: vulnerability exploitation (~31%) overtook credential abuse (13%) as the leading initial vector. Identity is no longer always the first step, but it is the enabler that turns a foothold into standing access to your consoles.
How do attackers use a vendor’s device and credentials to reach your systems?
They harvest valid credentials from the vendor’s unmanaged device, then sign in as a trusted supplier – no exploit required. The 2024 Snowflake campaign is the textbook case. Threat actor UNC5537 compromised roughly 165 Snowflake customer instances using credentials lifted by infostealer malware – much of it, Mandiant found, from “contractor systems that were also used for personal activities, including gaming and downloads of pirated software.”
Three identity-hygiene failures made it work: no MFA, stolen credentials still valid years later because nobody rotated them, and no network allow-lists. Every zero-trust control the customer applied to its own staff was irrelevant – the contractor authenticated with a valid identity from a laptop the customer could never see. And the supply is not slowing: infostealer email delivery rose 84% year-on-year in 2024 (IBM X-Force).
Why does third-party access bypass zero trust and MFA?
Third-party access bypasses zero trust because zero trust governs the identities and devices you own, and a supplier’s sits outside that boundary. The exposure is wider than stolen passwords: it includes stale-but-valid credentials (Snowflake), stolen session tokens that walk past MFA because the session is already authenticated, and compromised OAuth tokens that need no human at all.

Why can’t a security questionnaire catch the identity bridge?
A security questionnaire cannot catch the identity bridge because it captures a vendor’s self-description, not a live read of their identities. “Do you enforce MFA on all accounts?” returns a “Yes” describing policy – not the contractor whose unrotated credentials are sitting in a stealer-log dump this morning.
The 2026 DBIR quantifies the gap: among third parties, only 23% had fully remediated missing or improperly secured MFA on their cloud accounts – fewer than one in four had closed the exact failure their answers claim is handled. Credentials leak and tokens are abused continuously; a point-in-time form cannot track either.
Questionnaire vs. Reality
- Questionnaire Says: “All access to customer environments requires multi-factor authentication, and credentials are rotated on a 90-day cycle.”
- Reality Shows: “A contractor’s valid admin credentials sit in a fresh stealer-log dump, unrotated for 18 months, with no MFA and no allow-list on the console – the configuration behind the 165 Snowflake instances breached in 2024.”
What are third-party non-human identities, and why are they the 2026 frontier?
Third-party non-human identities are the OAuth tokens, API keys, and service accounts a supplier’s integration uses to reach your data. They are the 2026 frontier because they have no device, no MFA prompt, and no off-boarding – standing access with nothing to challenge it.
OWASP lists “Vulnerable Third-Party NHI” at NHI3 in its 2025 Non-Human Identity Top 10. The Salesloft–Drift breach is the live proof: between 8 and 18 August 2025, threat actor UNC6395 abused compromised OAuth tokens from the Salesloft Drift integration to pull Salesforce data from more than 700 organisations, including Cloudflare, Palo Alto Networks, Zscaler, and Proofpoint. No password was phished and no endpoint was breached – one compromised non-human identity was the whole bridge.
What does UK and EU law require on third-party identity risk?
UK and EU law treats access control as a security duty you cannot delegate away. UK GDPR Article 32(1)(b) requires controllers and processors to maintain “the ongoing confidentiality, integrity, availability and resilience of processing systems and services”, and Article 28(3) requires the processor to act only on documented instructions. A vendor reaching personal data from an unmanaged, malware-infected device fails both.
Finance is held tighter. DORA, in force since 17 January 2025, requires financial entities to limit logical access to approved functions only and to operate strong authentication mechanisms (Article 9) – a bar the vendor’s access must clear, which a questionnaire cannot verify. NIS2 names multi-factor authentication and access-control policies among its baseline measures (Article 21(2)).
The cleanest practitioner test remains the NCSC Cyber Assessment Framework, Principle A4: be “aware of all third-party connections and have assurance that they meet your organisation’s security requirements”. You cannot have assurance over a connection you cannot see.
How do you monitor third-party access from unmanaged devices?
You monitor from the outside, because you cannot place an agent on a device you do not own. Elasticito uses Black Kite, the continuous cyber-risk-ratings platform, whose Credential Management and Hacktivist Shares categories detect leaked and stealer-log-sourced credentials on a supplier’s external surface before reuse and with no agent.
Across the vendor surfaces we monitor with Black Kite, we have seen valid session tokens – not just credentials – exposed in stealer-log dumps, the exact artefact that walks past MFA. External monitoring catches that exposure while the questionnaire still reads “Yes”.
FAQ
What is third-party identity risk?
Third-party identity risk is the exposure created when a supplier reaches your systems and data using their own identity – credentials, session tokens, OAuth tokens, or service accounts – from a device or integration you do not manage or monitor. It sits outside your zero-trust controls, which govern only the identities you own, and now features in 48% of breaches (Verizon 2026 DBIR via SecurityWeek).
How do attackers use a vendor’s credentials or device to get into your systems?
Attackers harvest valid credentials from a supplier’s unmanaged device with infostealer malware, then sign in as the trusted vendor – no exploit required. In the 2024 Snowflake campaign, UNC5537 used infostealer credentials from contractor laptops to reach around 165 customer instances that had no MFA and unrotated credentials.
What is a non-human identity, and why are third-party OAuth tokens a supply-chain risk?
A non-human identity is an OAuth token, API key, or service account that authenticates software rather than a person. Third-party ones are a supply-chain risk: standing access with no device, no MFA prompt, and no off-boarding. OWASP ranks this as NHI3, “Vulnerable Third-Party NHI”; Salesloft–Drift exposed Salesforce data across 700-plus organisations via a single compromised token.
Why does third-party access bypass zero trust and MFA?
Zero trust governs only the identities and devices you own. A supplier’s credentials, session tokens, and OAuth tokens sit outside that boundary – you cannot enrol them in your MFA or device compliance policy. A stolen session token bypasses MFA entirely: the session was already authenticated before the theft, and the token is reused with no prompt.
How do you monitor third-party identity risk from unmanaged devices?
You monitor from the outside. Elasticito uses Black Kite‘s Credential Management and Hacktivist Shares categories to detect leaked credentials and valid session tokens on a supplier’s external surface before reuse – with no agent on the supplier’s device required.
Are you liable when a supplier accesses your data insecurely?
Yes. Under UK GDPR you remain accountable throughout the chain. Article 32 requires you to protect the “confidentiality, integrity, availability and resilience” of processing systems – so a vendor reaching personal data from an unmanaged, infected device is a failure of that duty whoever owns the laptop. The NCSC CAF confirms it: an organisation relying on third parties “remains accountable for the protection of any essential function”.
Conclusion: why your zero-trust controls stop at your own front door
Your zero-trust architecture assumes the identity reaching your data is one you manage, and for your suppliers it never is – so the access you cannot enforce is the access you most need to watch from outside.
Join Elasticito on 15 July 2026 for Your Questionnaire Won’t Save You: Discover the Vendors Most Likely to Breach You Next.
Created: 2026-06-05 / Reviewed: 2026-06-05





