Third-Party Platforms Expose Customer Data
Coverage from Claim Depot, Precisely Community, and others
Articles
9
Active Days
106
The Topic

Organizations in the United States and Puerto Rico are reporting breaches involving cloud CRM systems, customer-support tools, and third-party financial service providers. Exposed information ranges from names and contact details to Social Security numbers, driver’s license data, health information, and debit card numbers. The pattern highlights how compromise of connected platforms or vendors can affect large customer populations even when an organization’s own core systems are not directly accessed.
First Article: 04/09/26
Latest Article: 07/23/26
Summary
- ADT said an unauthorized actor accessed cloud environments and exposed data tied to about 5.5 million accounts.
- Pitney Bowes reportedly had approximately 8.2 million Salesforce CRM accounts extracted, including contact and address data.
- First National Holdings reported a third-party exfiltration event affecting at least 34,507 Texas residents, with potentially sensitive identity, financial, and health information involved.
- Access Information Management linked unauthorized access to customer-support data stored in Salesforce Drift and offered affected people credit and identity monitoring.
- Evertec’s incident exposed certain Banco Popular de Puerto Rico customer data, including debit card numbers, while Popular said its own systems were not accessed.
- Several incidents remain subject to investigation, with affected populations, access methods, and the full scope of exposed data not yet established.
History
The update sharpens the picture on First National Holdings, turning an unknown nationwide exposure into a confirmed third-party exfiltration affecting at least 34,507 Texas residents. It also newly links Access Information Management to customer-support data in Salesforce Drift and adds monitoring offers, while the broader pattern remains the same.
The story now adds several specific 2026 breach disclosures with named victims and incident details, making the vendor-exposure pattern more concrete and data-rich. It also shifts from a broad privacy theme to a clearer focus on cloud, CRM, support, and financial-processing systems as the main exposure points.
