§ The Long Read

The deep work behind
the wire.

Research-led explainers, breach postmortems, regulatory briefs, and playbooks. Long-form work from the Supplier Shield desk and Abilene Advisors partners.

§ Archive

Every long read.

All59Uncategorized59
Jscrambler's own npm package was hijacked: a trusted supplier became a supply-chain vectorLong read

Jscrambler's own npm package was hijacked: a trusted supplier became a supply-chain vector

An attacker hijacked Jscrambler's npm package with a stolen publishing credential and shipped an infostealer to developers between 11 and 13 July 2026. The malware harvested cloud tokens, wallets and AI-assistant credentials from any machine that installed it. For third-party risk teams, the lesson is that a trusted dependency is a supplier, and its release channel can become the attack path.

Supplier Shield teamJul 15, 2026
Lidl online shop data breach started at an IT service provider, not the retailer's own systemsLong read

Lidl online shop data breach started at an IT service provider, not the retailer's own systems

Lidl has told online shop customers in Germany, Belgium and the Netherlands that their data was stolen in a breach at an IT service provider, not in its own systems. Names, phone numbers, email addresses, dates of birth and customer numbers were taken; payment data is not yet ruled out. Under GDPR the controller stays accountable for a processor's breach.

Supplier Shield teamJul 15, 2026
AdaptHealth breach reached patient data through a third-party contractor's stolen credentialsLong read

AdaptHealth breach reached patient data through a third-party contractor's stolen credentials

AdaptHealth told the SEC that attackers reached patient data through a third-party contractor's stolen credentials, obtained by social engineering. The number of affected individuals is not yet confirmed. For third-party risk teams, contractor and vendor accounts are part of the attack surface.

Supplier Shield teamJul 14, 2026
Hemmersbach ransomware claim: why a breach at an IT services supplier reaches toward its clientsLong read

Hemmersbach ransomware claim: why a breach at an IT services supplier reaches toward its clients

A ransomware group has claimed a breach of Hemmersbach, a German IT services provider that works inside its clients' technology estates. Researchers say the exposed data includes credentials to the firm's own identity systems. Hemmersbach has not confirmed the attack and the scope is unverified. For third-party risk teams, the lesson is about vendor access: a supplier's stolen login can become a route toward the clients it serves.

Supplier Shield teamJul 13, 2026
Fake Paysafe, Skrill and Neteller SDKs on npm and PyPI turned payment developers into a supply-chain targetLong read

Fake Paysafe, Skrill and Neteller SDKs on npm and PyPI turned payment developers into a supply-chain target

Researchers found 17 fake Paysafe, Skrill and Neteller packages on npm and PyPI that steal API keys and CI tokens from developer and build machines. Nothing was breached at the payment firms. The exposure came through a poisoned dependency, which shows why the package registry is a supplier.

Supplier Shield teamJul 13, 2026
Accenture breach: source code and cloud keys claimed stolen from a supplier many firms rely onLong read

Accenture breach: source code and cloud keys claimed stolen from a supplier many firms rely on

Accenture confirmed a security incident on 8 July 2026 after a threat actor listed about 35 GB of source code and cloud access keys for sale. The company called it isolated and remediated, but did not confirm scope or client-data impact. For third-party risk teams, the exposure is the client pipelines and cloud tenants a services provider touches.

Supplier Shield teamJul 10, 2026
KDDI email breach: how one shared email platform exposed up to 14.2 million logins across six ISPsLong read

KDDI email breach: how one shared email platform exposed up to 14.2 million logins across six ISPs

One email platform run by KDDI exposed the logins of up to 14.2 million customers across six Japanese internet providers. The lesson for third-party risk teams is concentration and fourth-party risk: many brands on one shared supplier system, breached through a third-party software flaw.

Supplier Shield teamJul 8, 2026
Amazon employee data breach exposes hidden dangers in the digital supply chainLong read

Amazon employee data breach exposes hidden dangers in the digital supply chain

Amazon’s recent data breach reveals hidden risks in third-party vendors. Learn how proactive supply chain security can help prevent such vulnerabilities.

Supplier ShieldApr 29, 2026
Browsers: The new AI battleground and 2025�s biggest security testLong read

Browsers: The new AI battleground and 2025�s biggest security test

Browsers are the new AI security battleground. Anthropic�s Claude for Chrome shows how browser agents can boost productivity but expose enterprises to prompt injection, data leaks, and governance risks. Learn why AI browser security, agentic workflows, and third-party risk management must be built i...

Supplier ShieldApr 29, 2026
Could scrapping IP laws supercharge AI—or leave your business exposed?Long read

Could scrapping IP laws supercharge AI—or leave your business exposed?

As Dorsey and Musk push to scrap IP laws, learn how this AI shift could expose your business to third-party risks—and how to stay protected.

Supplier ShieldApr 29, 2026
Cyber supply chain risk management: From visibility gaps to resilience at scaleLong read

Cyber supply chain risk management: From visibility gaps to resilience at scale

Build a resilient cyber supply chain risk management program. Learn the latest market trends, key challenges, future predictions, and real-world case studies. Get a 90-day plan to reduce vendor risk and meet regulations like NIS2 and DORA.

Supplier ShieldApr 29, 2026
DeepSeek vs ChatGPT: What they mean for supplier risk managementLong read

DeepSeek vs ChatGPT: What they mean for supplier risk management

DeepSeek AI vs. ChatGPT: A look at features, risks, and data privacy concerns. Learn how supply risk management can help businesses stay secure.

Supplier ShieldApr 29, 2026
Detailed analysis: Why EU and Swiss companies must rely on European-rooted cybersecurity partnersLong read

Detailed analysis: Why EU and Swiss companies must rely on European-rooted cybersecurity partners

In a shifting geopolitical world, discover why European-rooted cybersecurity partners are critical for EU and Swiss organizations. Explore the growing supply chain threats, legal risks with U.S. tech providers, and the importance of digital sovereignty in third-party risk management (TPRM).

Supplier ShieldApr 29, 2026
From vendor breach to boardroom liability: How the EU AI act changes accountability for suppliersLong read

From vendor breach to boardroom liability: How the EU AI act changes accountability for suppliers

The EU AI Act makes both vendors and buyers liable for supplier AI failures, fines can reach €35M or 7% of turnover. Supplier Shield helps you track and mitigate that risk.

Supplier ShieldApr 29, 2026
How 4.2 Million Internet Hosts Were Hijacked: What You Need to KnowLong read

How 4.2 Million Internet Hosts Were Hijacked: What You Need to Know

Discover how vulnerabilities in tunneling protocols expose 4.2M internet hosts to attacks. Learn about the risks, affected regions, and essential steps to protect your network and supply chain.

Supplier ShieldApr 29, 2026
How can financial risks in a supply chain be managed?Long read

How can financial risks in a supply chain be managed?

Learn how to manage financial risks in supply chains effectively. Discover strategies to mitigate supplier instability, credit risks, and market volatility for resilient operations.

Supplier ShieldApr 29, 2026
How Supplier Shield protects against data breach risks from third-party vulnerabilitiesLong read

How Supplier Shield protects against data breach risks from third-party vulnerabilities

Discover how Supplier Shield helps mitigate risks from third-party and supplier vulnerabilities, protecting businesses from different risks.

Supplier ShieldApr 29, 2026
Mastering supplier risk management: Your ultimate guide to building resilient and transparent supply chainsLong read

Mastering supplier risk management: Your ultimate guide to building resilient and transparent supply chains

Learn how to effectively manage supplier risks by identifying, assessing, and mitigating potential disruptions to ensure smooth operations and compliance.

Supplier ShieldApr 29, 2026
NIS2 compliance in manufacturing: how to secure your supply chain and meet EU requirementsLong read

NIS2 compliance in manufacturing: how to secure your supply chain and meet EU requirements

Discover how manufacturers can achieve NIS2 compliance, secure their supply chains, and reduce third-party risk. Learn practical steps and see how Supplier Shield simplifies compliance.

Supplier ShieldApr 29, 2026
Starbucks faces cyber attack fallout: Could your coffee routine be at risk?Long read

Starbucks faces cyber attack fallout: Could your coffee routine be at risk?

Ransomware hits Starbucks supply chain—barista pay and schedules disrupted. Could your daily coffee fix be next? Here's what you need to know!

Supplier ShieldApr 29, 2026
Supplier risk management best practices to protect your supply chain in 2025Long read

Supplier risk management best practices to protect your supply chain in 2025

Explore supplier risk management best practices to mitigate disruptions, build resilient supply chains, and embrace future trends like blockchain and IoT.

Supplier ShieldApr 29, 2026
The hidden risks of AI: What businesses can learn from AI cheating in chessLong read

The hidden risks of AI: What businesses can learn from AI cheating in chess

AI isn't perfect�learn from chess AI cheating incidents and find out how to safeguard your business against emerging cyber threats

Supplier ShieldApr 29, 2026
The ultimate guide to building a risk-aware culture: strategies top companies useLong read

The ultimate guide to building a risk-aware culture: strategies top companies use

Learn how top companies build a risk-aware culture to navigate emerging risks, improve decision-making, and boost resilience through training, technology, and certifications.

Supplier ShieldApr 29, 2026
What Is the EU AI Act? Complete Guide (2025)Long read

What Is the EU AI Act? Complete Guide (2025)

EU AI Act is the world's first AI regulation with penalties up to €35M. Learn risk categories, compliance deadlines (2025-2027), and high-risk AI requirements.

Supplier ShieldApr 29, 2026
What Is TPRM? Third-Party Risk Management Explained (2025)Long read

What Is TPRM? Third-Party Risk Management Explained (2025)

TPRM manages risks from vendors, suppliers, and partners. Learn why 30% of breaches involve third parties and how to implement TPRM for NIS2 and DORA compliance.

Supplier ShieldApr 29, 2026
The Daily Brief

Get every new long read in your inbox.

One email a day. Five disclosures from the Breach Wire plus every new long read from the desk.