Your vendor's vendor is your risk: what August's breach wave means for software buyers
EditorialBy TrustList Editorial
Two very different incidents this month made the same point — the software you buy inherits the security of everything behind it.
About Your vendor's vendor is your risk: what August's breach wave means for software buyers
Two incidents in the first days of August looked unrelated. One hit a $20bn logistics operator. The other hit a meeting-notes app. For anyone responsible for choosing software, they made the same uncomfortable point: the questions on most vendor-security checklists stop one layer too early.
A logistics breach that surfaced on retail and banking balance sheets
CEVA Logistics confirmed to affected customers on 1 August that an intrusion — beginning around 29 July — was affecting part of its European contract-logistics operation. TechCrunch reported that at least eight European warehouses were caught up in it, delaying goods moving across the continent.
The more instructive part is who ended up notifying customers. The football club Ajax, the bank ING and the eyewear chain Ace & Tate have all said they were affected, as have the retailers bol and De Bijenkorf, with Zalando confirming exposure to the same incident. The Dutch data protection authority has received breach reports from ten organisations connected to it.
None of those organisations were breached. Their logistics provider was. Yet they are the ones writing to customers, because the data describing their customers sat inside someone else's operation.
An AI notetaker with the front door open
The second incident is smaller in headline terms and arguably more relevant to day-to-day software buying. A researcher found that the meeting-recording tool tl;dv had misconfigured its Firestore security rules — the access rules Firebase explicitly warns developers to lock down before shipping.
The result, as reported by Dark Reading, was that any tl;dv user could query essentially every live call the tool had been invited into, along with metadata including timestamps, recording status and the meeting creator's email address. More than 181,000 recordings were reachable.
Consider how a tool like that enters a company. Rarely through procurement. Usually one person adds a notetaker to a call because it is genuinely useful, colleagues see the summaries, and within a quarter it is sitting silently in board meetings, incident calls and salary discussions. It was never assessed, because it was never bought.
The common thread
In both cases the failure was not that a supplier was careless — suppliers will sometimes be careless. It was that the buying organisation had no visibility into a dependency that was, in practice, handling its most sensitive material.
That distinction matters because the two problems need different fixes. The logistics case is a procurement and contract question: it was a known supplier whose sub-processing and incident-notification terms were not examined closely enough. The notetaker case is a governance question: nobody bought it, so nobody assessed it.
What to actually change
Ask who else touches the data. A vendor questionnaire that asks about the vendor's own controls but not its sub-processors covers the least likely failure. Ask for the sub-processor list, and ask what happens to your data in each.
Treat notification terms as a real negotiating point. In the logistics case, the organisations that looked competent were the ones that told their customers early and specifically. That is far easier when the contract obliges the supplier to tell you fast, with detail.
Inventory the tools nobody bought. Meeting recorders, transcription bots, browser extensions and AI assistants tend to arrive without procurement. A quarterly sweep of what has been granted access to calendars, mail and calls is not bureaucracy — it is the only way to see this category of risk at all.
Prefer suppliers who publish detail. The useful signal is not a trust badge; it is whether a supplier documents its architecture, its sub-processors and its past incidents in a way you can actually evaluate. Vendors who write plainly about how they failed once are usually safer than vendors who have never mentioned failure.
The uncomfortable summary
A security review that ends at your direct supplier measures the wrong boundary. Your real exposure is the union of every system your suppliers depend on, plus every tool your staff attached to a calendar without asking. August produced one example of each in a fortnight.
Buyers cannot audit the whole chain. But they can stop pretending the chain ends at the company whose logo is on the invoice.
Sources: TechCrunch on the CEVA Logistics breach · Dark Reading on the tl;dv notetaker exposure
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.