Last Update: 08/01/2026 at 1:00 PM EST

Third-Party Platforms Expose Customer Data

Coverage from Claim Depot, Precisely Community, and others

Articles

9

Active Days

106

The Topic

Third-Party Platforms Expose Customer Data topic image

Organizations in the United States and Puerto Rico are reporting breaches involving cloud CRM systems, customer-support tools, and third-party financial service providers. Exposed information ranges from names and contact details to Social Security numbers, driver’s license data, health information, and debit card numbers. The pattern highlights how compromise of connected platforms or vendors can affect large customer populations even when an organization’s own core systems are not directly accessed.

First Article: 04/09/26

Latest Article: 07/23/26

Summary

  • ADT said an unauthorized actor accessed cloud environments and exposed data tied to about 5.5 million accounts.
  • Pitney Bowes reportedly had approximately 8.2 million Salesforce CRM accounts extracted, including contact and address data.
  • First National Holdings reported a third-party exfiltration event affecting at least 34,507 Texas residents, with potentially sensitive identity, financial, and health information involved.
  • Access Information Management linked unauthorized access to customer-support data stored in Salesforce Drift and offered affected people credit and identity monitoring.
  • Evertec’s incident exposed certain Banco Popular de Puerto Rico customer data, including debit card numbers, while Popular said its own systems were not accessed.
  • Several incidents remain subject to investigation, with affected populations, access methods, and the full scope of exposed data not yet established.

History

07/27/2026

The update sharpens the picture on First National Holdings, turning an unknown nationwide exposure into a confirmed third-party exfiltration affecting at least 34,507 Texas residents. It also newly links Access Information Management to customer-support data in Salesforce Drift and adds monitoring offers, while the broader pattern remains the same.

07/25/2026

The story now adds several specific 2026 breach disclosures with named victims and incident details, making the vendor-exposure pattern more concrete and data-rich. It also shifts from a broad privacy theme to a clearer focus on cloud, CRM, support, and financial-processing systems as the main exposure points.

Full History

Featured

Timeline: 106 Days

Apr 9Apr 30May 21Jun 11Jul 2Jul 23

Additional Articles

⭐⭐⭐⭐⭐

Stock Titan06-09-2026
Popular, Inc. disclosed an Evertec cybersecurity incident in Puerto Rico in which debit card numbers of certain Banco Popular de Puerto Rico customers were compromised.
Cory Watson Attorneys04-14-2026
OneDigital Investment Advisors disclosed in April 2026 a data breach affecting 28,414 clients after third-party Drift and Salesloft connections exposed Social Security and financial account data.

⭐⭐⭐

GS Legal07-23-2026
First National Holdings reported a third-party data exfiltration event on July 10, 2026, to the Texas Attorney General, potentially affecting at least 34,507 Texas residents.
Federman & Sherwood / Caroline Chesher05-07-2026
Federman & Sherwood and Access Information Management disclosed a Salesforce Drift-linked breach involving unauthorized access to personal data in August 2025, reported to California officials.
ClassAction.org04-09-2026
OneDigital Investment Advisors reported a Salesforce Drift compromise to the Maine Attorney General, with 28,414 affected people and Social Security number exposure.
Wealth Management / Patrick Donachie04-10-2026
OneDigital Investment Advisors reported to Maine's Attorney General that up to 28,414 people were affected by a Salesforce incident involving the Drift connection.