Back to the blog
supply-chainSeptember 7, 2025 5 min read

September 2025 Security Review: Supply Chain Vulnerabilities and Data Exposure

September 2025 saw a surge in third-party supply chain compromises and critical hardware vulnerabilities, highlighting the urgent need for zero-knowledge security architectures.

By SecureIDsafe Threat Team · SecureIDsafe Threat Research#data-exposure

The security landscape in September 2025 was defined by systemic failures in third-party vendor management and the exploitation of hard-coded credentials in IoT devices. These incidents demonstrate that even when organizations secure their own perimeters, their reliance on external SaaS providers and unpatched hardware creates significant, often invisible, attack surfaces.

What happened

Salesloft Supply Chain Breach (September 2025)

In September 2025, a massive supply chain breach involving Salesloft-owned Drift impacted numerous companies [8]. Attackers compromised GitHub repositories to gain access to OAuth tokens, leading to the exposure of customer data stored within Salesforce CRM instances across more than 760 organizations [1].

EDITOR: Add a brief explanation of how OAuth token theft bypasses traditional password-based security.

Volvo Group HR Data Breach (August/September 2025)

Volvo Group confirmed a data breach resulting from a ransomware attack on its third-party human resources software provider, Miljödata [5]. The attack, attributed to the DataCarry ransomware group, began in late August, with forensic confirmation of data exfiltration by September 2, 2025 [5].

EDITOR: Insert a screenshot or summary of the public disclosure notice from Volvo regarding the third-party vendor risk.

Stellantis Salesforce Breach (September 24, 2025)

Automaker Stellantis confirmed a data breach tied to a Salesforce hack [3]. The incident resulted in the exposure of sensitive customer and employee data, further illustrating the risks associated with centralized enterprise cloud platforms [3].

Why this matters

These incidents confirm that the "trust-but-verify" model for third-party vendors is failing. When a vendor is compromised, the data they hold—often including credentials, PII, and internal communications—becomes immediately accessible to attackers. The reliance on centralized cloud storage means that a single point of failure at a provider like Salesforce or a smaller HR vendor can result in the mass exposure of data across hundreds of unrelated enterprises.

How zero-knowledge changes this

SecureIDsafe’s architecture is designed to neutralize these risks through client-side encryption. Because we utilize AES-256 encryption with keys derived directly from the user's device, the service provider never holds the keys to decrypt user data. Even if a third-party integration or our own infrastructure were compromised, an attacker would only ever access ciphertext. Furthermore, our non-bypassable 24-word BIP-39 seed recovery ensures that even in the event of a total system failure, the user retains sole ownership of their data, rendering stolen databases useless to unauthorized parties.

Editor's checklist

  • EDITOR: Add a brief explanation of how OAuth token theft bypasses traditional password-based security.

  • EDITOR: Insert a screenshot or summary of the public disclosure notice from Volvo regarding the third-party vendor risk.

  • EDITOR: Verify the specific number of records exposed in the Stellantis breach if updated figures are available.

  • EDITOR: Add a section detailing the remediation steps for users affected by the Salesloft incident.

supply-chaindata-breachzero-knowledgeransomwarecve

Build your Fortress of Sovereignty.

Single users, business teams and enterprise perimeters — the same non-bypassable security, scaled to your vault.