
Your Vendor's Vendor Can Burn You
The Lighthouse IT Podcast - August 21st, 2026 Your Vendor's Vendor Can Burn You In this episode of the #LighthouseITPodcast, Matt and Griff discuss how major cybersecurity incidents often stem from trusted vendors rather than direct breaches, comparing three recent cases: Ernst & Young, a Salesforce-related data theft wave, and Framework Laptops. They go through EY’s third-party IT support ticketing platform compromise, the 83-day delay between detection and disclosure, and exposed sensitive data, including Social Security numbers and tax documents, followed by a class action lawsuit and 24 months of identity monitoring. They then cover a social-engineering “vishing” campaign leading employees to approve malicious connected apps, affecting Salesforce customers, including Alcon (25M records), Questel (21M), and Luminus, with claims of up to 1B records across 40 companies! Finally, they highlight Framework’s vendor-based Metabase SQL injection zero-day (CVSS of 10.0!), noting only 17 minutes from discovery to disclosure and discussing practical steps like verifying IT calls, not approving unexpected MFA/app prompts, and asking vendors about incident response and disclosure timelines. Don't miss out on our discussions and more! https://hub.lighthousesol.com/blog/lighthouse-podcast-2/your-vendor-s-vendor-can-burn-you-474 00:00 Framework Laptop 13 Pro 02:47 Vendor Breach? 04:52 Third and Fourth Party Risk Explained 06:31 EY Breach Timeline 07:55 Stolen Data Fallout 11:11 Salesforce Wave Begins 12:24 Vishing App Approvals 14:18 Record Counts Ransom 16:20 Why Not Pay Ransom 17:16 Vendor Breach Reality Check 18:00 Framework Breach Timeline 18:57 What Data Was Exposed 19:38 Vendor Trust Lessons 21:54 EY / Saleforce vs Framework Contrast 24:22 Questions To Ask Vendors 27:31 MFA Fatigue And Vishing 28:26 Verify With Callbacks 30:07 Vendor Risk Tools Rising 32:21 Podcast Wrap Up





