TL;DR: An Oracle E-Business Suite zero-day, a subcontractor-account intrusion, and a ransomware-linked fintech breach created cross-organisation exposure across education, telecom, finance, and pharma, according to FireCompass’s weekly report. The pattern is clear: vendor and third-party access now drive most downstream identity and data risk.
At a glance
What this is: This weekly intelligence report highlights several December 2025 breaches where exposed ERP, third-party, and subcontractor access led to multi-organisation data risk.
Why it matters: For IAM, PAM, and NHI practitioners, the report reinforces that third-party identities and internet-facing business systems can create blast radii far beyond the initial victim.
By the numbers:
- Marquis Software’s ransomware breach affected over 74 U.S. banks and credit unions.
- Inotiv’s breach affected at least 9,542 individuals after the August ransomware attack.
👉 Read FireCompass's weekly cybersecurity intelligence report on the December 2 to 10 breach cluster
Context
Enterprise breach reporting increasingly shows the same governance failure pattern: a trusted business system, a third-party account, or a perimeter device becomes the entry point for broader data exposure. In this report, the Oracle E-Business Suite compromise, subcontractor account abuse, and ransomware-linked exfiltration all show how access paths that look operational can still function as high-impact identity control failures.
The first-order problem is not just malware or vulnerability exploitation. It is that enterprise identity governance often treats application access, supplier access, and internal privilege as separate problems, when attackers move across those boundaries very quickly. That makes the identity angle central even in a broader cyber report, especially for organisations relying on third-party accounts, service credentials, or exposed business applications.
Key questions
Q: What breaks when third-party accounts can reach customer or ERP data directly?
A: Direct access turns supplier credentials into high-risk delegated identities, especially when those accounts can query large record sets or operate across multiple systems. The failure is usually scope, not authentication. If behavioural baselines, narrow role design, and rapid disablement are absent, a single valid account can expose data at scale before anyone notices.
Q: Why do internet-facing application flaws often become identity risks?
A: Because web application compromise frequently exposes the components attackers need to reach identity controls, including configuration files, session tokens, admin interfaces, or service credentials. Once those are in play, the incident is no longer only about application security. It becomes a credential, privilege, and account governance problem as well.
Q: How do organisations tell whether ransomware has already become a data theft event?
A: Look for staged exports, unusual archive creation, abnormal outbound traffic, and access to repositories outside normal batch windows. Those signals often appear before encryption and indicate the attack is already a confidentiality incident. If the response only begins after systems are locked, the breach window has already expanded.
Q: What should security teams require from high-concentration third-party providers?
A: They should require per-client exposure evidence, detailed telemetry sharing, segmentation between tenants, and explicit notification timelines for compromised accounts or data movement. When one provider holds records for many customers, the governance question is not only breach response. It is whether the provider can prove blast-radius containment in the first place.
Technical breakdown
Internet-facing ERP applications become identity-rich attack surfaces
Oracle E-Business Suite and similar ERP platforms are not just business applications. They often contain payroll, vendor, customer, and HR data, plus the service accounts and middleware privileges needed to move that data around. When a public-facing endpoint is vulnerable, attackers can combine application exploitation with database access, scheduled exports, and trusted server-side scripts to reach sensitive repositories without needing traditional interactive logins. That is why ERP compromise often looks like an identity failure as much as an application failure.
Practical implication: treat ERP front ends as Tier-0 access paths and continuously verify the privileges attached to middleware, export jobs, and database service accounts.
Third-party accounts act like privileged identities when scope is too broad
The Freedom Mobile case shows how a subcontractor credential can become a high-value access path when it can reach customer records directly. A valid account does not need admin rights to be dangerous if it can query identity-rich data, move across records quickly, or bypass behavioural controls. This is the core NHI lesson for third-party access: the credential may belong to a human contractor, but the runtime access behaves like a machine privilege that must be governed with the same rigour as any other non-human or delegated identity.
Practical implication: enforce narrow scopes, MFA, session monitoring, and rapid disablement for all supplier accounts that can access sensitive customer or operational systems.
Ransomware now routinely includes pre-encryption data theft
The Inotiv breach reflects a familiar modern ransomware pattern. Attackers gain initial access, move laterally, stage data, exfiltrate it, and then encrypt systems to increase pressure for payment. That sequence matters because the operational recovery problem and the privacy notification problem are now linked. Even when encryption is contained, stolen data can still trigger downstream fraud, regulatory, and litigation exposure. Organisations that treat ransomware as only an availability event are missing the broader compromise path.
Threat narrative
Attacker objective: The objective was to harvest sensitive records from trusted enterprise systems and increase leverage through extortion, fraud exposure, or ransomware pressure.
- Entry began through a public Oracle E-Business Suite exposure, a compromised subcontractor account, or a vulnerable perimeter device depending on the incident path described in the report.
- Escalation followed through trusted application privileges, internal account access, or lateral movement into data platforms where attackers could stage and query sensitive records.
- Impact included large-scale data theft, regulatory notification, fraud exposure, and in some cases ransomware encryption that increased operational disruption.
Breaches seen in the wild
- JetBrains Marketplace AI Plugin Campaign — 15 malicious JetBrains Marketplace plugins steal AI API keys from 70,000+ developers via supply chain attack.
- Code Formatting Tools Credential Leaks — Widely used code formatting tools cause massive credential and secrets leaks in enterprise environments.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Third-party access is now a governance problem, not just a vendor-management problem. The Freedom Mobile incident shows that subcontractor credentials can function as privileged access paths when they reach identity-rich systems. That means offboarding, scope control, and behaviour monitoring matter as much as contract terms. For IAM and PAM teams, supplier identities should be treated as governed access assets, not administrative exceptions.
ERP compromise is a non-human identity problem hiding inside application security. Oracle E-Business Suite and similar platforms depend on service accounts, middleware privileges, and automated exports that attackers can abuse once they get execution. This is where NHI governance intersects with application and data security: the compromise is often enabled by standing credentials and over-permissioned backend automation. Practitioners should assume that ERP blast radius is determined by identity design, not just patch status.
Ransomware has become a data governance failure as much as an endpoint failure. Inotiv’s case shows the familiar shift from intrusion to exfiltration to encryption, where stolen data becomes the leverage point. That sequence demands controls aligned to NIST CSF, MITRE ATT&CK, and NIST SP 800-53, with logging and segmentation tied to data sensitivity. The practical conclusion is simple: response planning must assume exfiltration before encryption.
Multi-organisation compromise exposes concentration risk in shared service providers. Marquis Software’s breach affected more than 74 banks and credit unions because one provider concentrated regulated data across many customers. That concentration is a structural risk in the identity and data stack, especially where shared platforms hold multiple clients’ records under a single administrative model. Security teams should re-evaluate third-party segmentation, telemetry sharing, and contractual incident evidence requirements.
Shared trust boundaries are the real attack surface here. Once attackers can use a legitimate account, a trusted integration, or an exposed ERP endpoint, traditional perimeter assumptions collapse. The lesson for identity governance is to reduce the number of long-lived access paths that can reach high-value data, and to make every delegated privilege observable and time-bound.
From our research:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months. This signals that NHI governance is moving from niche concern to programme planning.
- Another finding in The State of Non-Human Identity Security shows that only 1.5 out of 10 organisations are highly confident in securing NHIs, underscoring the maturity gap behind delegated and machine access.
- That gap makes Top 10 NHI Issues useful forward reading for teams reworking third-party access, service accounts, and credential lifecycle controls.
What this signals
Shared trust boundaries are becoming the dominant failure mode across identity and data security. As more business systems expose data through vendors, contractors, and backend automation, the programme question shifts from access review to access containment. Teams should expect more scrutiny on delegated accounts, supplier telemetry, and cross-system correlation, especially where identity-rich applications sit outside classic IAM tooling.
A useful way to frame this is as delegated access blast radius, meaning the gap between who is authorised and how far their access can actually reach. When that radius is wide, a single compromised account can affect many customers or business units. The practical response is tighter scoping, stronger monitoring, and faster offboarding of third-party access paths.
For practitioners
- Classify ERP environments as high-value identity systems Map Oracle EBS, CRM, payroll, and supplier portals as sensitive identity-rich assets, then place them under emergency patching, WAF coverage, and continuous attack-surface monitoring.
- Constrain subcontractor and supplier access to the minimum record set Remove broad customer lookup rights, use role-specific entitlements, and review whether each third-party account can reach data it does not operationally need.
- Correlate application, database, and outbound traffic telemetry Join web access logs, database exports, and egress monitoring so bulk data extraction from ERP and customer platforms can be detected before extortion or fraud disclosure.
- Assume ransomware includes exfiltration until proven otherwise Update incident playbooks so containment, legal review, and notification workflows begin as soon as staging or export behaviour appears, not after encryption is observed.
Key takeaways
- The report shows how exposed business systems, supplier accounts, and ransomware-linked exfiltration can turn one intrusion into multi-organisation identity and data risk.
- The scale matters because the incidents touched banks, telecom customers, ERP records, and thousands of individuals, which is exactly why concentration risk keeps surfacing.
- The control that changes outcomes is blast-radius reduction through scoped access, telemetry correlation, and faster disablement of delegated identities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access; TA0008 , Lateral Movement; TA0010 , Exfiltration | The incidents use exploited applications, valid accounts, lateral movement, and exfiltration. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Third-party and delegated identity exposure are core NHI governance issues here. |
| NIST CSF 2.0 | PR.AC-4 | The report centers on access scope, trust boundaries, and third-party identity governance. |
| NIST SP 800-53 Rev 5 | IA-5 | Credential lifecycle and authenticator management are central to the third-party and ERP cases. |
| CIS Controls v8 | CIS-5 , Account Management | Third-party account control and offboarding are directly implicated. |
Map exposed endpoints and account abuse to ATT&CK tactics so detection and containment align to real attack stages.
Key terms
- Delegated Identity: Delegated identity is when one actor acts on behalf of another with explicit permission and bounded authority. In AI-assisted commerce, it requires clear consent, limited scope, and traceable records so the retailer can distinguish authorised delegation from unauthorised automation.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
- OAuth Scope: An OAuth scope is a permission string that defines what an application can do on behalf of a user. In practice, scopes set the blast radius of delegated access, because the token carries the right to read, write, or administer resources until it is revoked or expires.
- Data exfiltration risk: Data exfiltration risk is the possibility that sensitive information leaves approved systems and enters an environment the organisation does not control. With Shadow AI, that often happens through ordinary user behaviour, which makes identity governance and data governance tightly linked rather than separate problems.
What's in the full analysis
FireCompass's full weekly report covers the operational detail this post intentionally leaves for the source:
- Incident-by-incident chronology for the Oracle E-Business Suite, Marquis, Leroy Merlin, Freedom Mobile, and Inotiv cases
- MITRE ATT&CK mappings and observable indicators tied to each breach pattern
- Victim counts, disclosure dates, and regulatory context for each reported incident
- Expanded commentary on how each breach affected different sectors and customer groups
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners translate identity controls into operational discipline across modern security programmes.
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org