Last Update: 08/01/2026 at 2:00 PM EST

Third-Party Platforms Expose Customer Data

Coverage from Claim Depot, Precisely Community, and others

Articles

9

Active Days

106

The Topic

Third-Party Platforms Expose Customer Data topic image

Organizations in the United States and Puerto Rico are reporting breaches involving cloud CRM systems, customer-support tools, and third-party financial service providers. Exposed information ranges from names and contact details to Social Security numbers, driver’s license data, health information, and debit card numbers. The pattern highlights how compromise of connected platforms or vendors can affect large customer populations even when an organization’s own core systems are not directly accessed.

First Article: 04/09/26

Latest Article: 07/23/26

History

07/27/20260 new articles

The update sharpens the picture on First National Holdings, turning an unknown nationwide exposure into a confirmed third-party exfiltration affecting at least 34,507 Texas residents. It also newly links Access Information Management to customer-support data in Salesforce Drift and adds monitoring offers, while the broader pattern remains the same.

07/25/20260 new articles

The story now adds several specific 2026 breach disclosures with named victims and incident details, making the vendor-exposure pattern more concrete and data-rich. It also shifts from a broad privacy theme to a clearer focus on cloud, CRM, support, and financial-processing systems as the main exposure points.

  • ADT reported exposure affecting about 5.5 million accounts.
  • Pitney Bowes’ Salesforce CRM was tied to about 8.2 million accounts.
  • Access Information Management found data in Salesforce Drift customer-support records.
  • Evertec incident affected Banco Popular de Puerto Rico customer debit card data.
  • First National Holdings reported possible exposure of Social Security, financial, and health information.
07/24/20264 new articles

The story broadened from a handful of Salesforce-linked privacy breaches into a larger set of third-party and cloud-platform incidents, adding several new companies and showing bigger exposures in identity and financial data. The emphasis also shifted toward more explicit scale, with multi-million-record cases and slower breach notices becoming more central.

  • Pitney Bowes and Popular, Inc. are new breach-related actors.
  • Reported exposures now include financial account details and driver’s license numbers.
  • ADT and Pitney Bowes are described as multi-million-record incidents.
  • Public disclosures are concentrated in April-July 2026.
  • Evertec is newly tied to a third-party processor incident affecting Popular.
05/12/2026Topic Formed

Recent privacy coverage is dominated by company disclosures of breaches tied to Salesforce-connected third-party tools, with exposed personal data, delayed notifications, and legal investigations following the incidents.