Your Vendor Got Hacked. Your Data Went With It.

Sep 2, 2026Incognito CyberSecurity

Your Vendor Got Hacked. Your Data Went With It.

🇲🇽 Leer en Español →

Last week a company most small business owners have never heard of had to tell 9.5 million people that their private information was stolen. The company is Aesto Health, based in Birmingham, Alabama. They do not treat patients. They do not run a clinic. They sell software that helps medical practices move old patient records around when they switch systems or buy another practice.

Attackers got into that company’s Amazon cloud environment and walked away with names, Social Security numbers, medical histories, billing records and insurance details belonging to patients at more than twenty different healthcare organizations. Those twenty organizations did nothing wrong. Their passwords were fine. Their firewalls were fine. They simply handed data to a vendor, which is something every business on earth does every single day.

That is the part I want you to sit with, because it applies to your business too.

Your vendors are holding your data right now

Take sixty seconds and count. Your payroll company has your employees’ Social Security numbers. Your bookkeeper has your bank details. Your scheduling app has your customer list. Your marketing agency has your email database. Your CRM has every note you ever wrote about a client. Your file storage has your signed contracts.

Most owners I sit down with here in Tucson can name three vendors off the top of their head. When we actually walk through the credit card statement together, the real number is usually somewhere between fifteen and forty.

Your customers do not call the vendor

Here is the uncomfortable truth about a vendor breach: your customers do not know and do not care who your software provider is. They gave their information to you. When the notification letter goes out, your name is the one they remember, and your phone is the one that rings.

Neither do regulators or your insurance carrier

If you work in healthcare, finance, or law, you are usually still responsible for data you handed to somebody else. And if you carry cyber insurance, expect the carrier to ask what due diligence you performed on that vendor before you shared anything. “I assumed they were secure” is not an answer that pays a claim.

This is not a rare event anymore

Verizon’s 2026 Data Breach Investigations Report found that a third party was involved in 48% of all breaches, roughly double the share from the year before. Researchers tracking these incidents also found that for every vendor that gets breached, an average of five downstream companies are publicly exposed along with it.

Put plainly: one of the fastest growing ways to get hacked in 2026 is to not get hacked at all, and simply do business with somebody who did.

Infographic with three cards: ask before you sign, limit what they hold, know your list

What you can do this week

  1. Build the list. Open your bank and credit card statements for the last twelve months and write down every software subscription and service provider you pay. That list is your real risk surface, and most owners are genuinely surprised by how long it is.
  2. Mark who holds the sensitive material. Star every vendor that touches customer records, employee records, or banking information. Those are the ones that matter. The rest can wait.
  3. Ask the starred vendors three questions. Do you require multi-factor authentication on my account? Is my data encrypted where you store it? How quickly will you notify me if you are breached? Ask by email so you have the answers in writing.
  4. Shut off what you stopped using. That trial you abandoned two years ago still has your data and probably still has an active login. Cancel it, and ask them in writing to delete what they hold.
  5. Decide who you would call. If a vendor emails you on a Tuesday afternoon to say they lost your data, who is your first call? Your attorney? Your insurance broker? Us? Decide that now, while nothing is on fire.

Where this connects to everything else

Vendor risk is not a separate problem. It sits right next to the basics we handle for our small business clients every day. Solid endpoint protection stops an attacker from using a stolen vendor login to spread onto your computers. Reliable secure data backups mean you still have your records even when a vendor loses theirs. Good spam and virus filtering catches the wave of phishing that always follows a big breach, when criminals use the stolen details to sound convincing. And security awareness training keeps your staff from becoming the weak link in somebody else’s supply chain.

It is the same lesson as the patching gap I wrote about last week, and the same lesson in most of what I publish on our blog: the boring maintenance work is what keeps you out of the headlines.

The bottom line

You cannot audit a cloud provider the way a Fortune 500 company does, and you should not try. But you can know exactly who holds your data, ask them a few pointed questions in writing, and stop feeding information to companies you no longer use. That is an afternoon of work, and it puts you ahead of most businesses your size.

Not sure who has your data?

We will sit down with you, build the vendor list together, and tell you honestly which ones are worth worrying about. No charge and no pressure.

Book a complimentary visit →

Send us a message

Have a question about a vendor you are not sure about, or want a second opinion on a contract before you sign it? Send it over and I will get back to you personally.

ICS Form

🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.

— Nemuel Cruz, Incognito Cyber Security

About the author

Nemuel Cruz

Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.

Questions about this article? Email nemuel@incognitocybersecurity.com or book a complimentary visit.

Related

Latest News