Personal data connected to the University of Oxford was exposed through a breach of a third-party platform, CareerConnect. As with so many incidents this year, the weak point wasn’t the institution itself but a supplier holding its data.
The takeaway
This is the supply-chain risk in a nutshell: you can run a tight ship internally and still be exposed by a vendor’s security gap. Every platform you hand data to becomes part of your attack surface.
Know which suppliers hold your data and what they hold, put security expectations into your contracts, and ask for evidence — Cyber Essentials, ISO 27001, breach history. We help clients build that supplier due-diligence into how they buy and manage third-party services.
Supply-chain risk in a nutshell
This is the pattern that has defined so many incidents this year: an organisation can run a tight ship internally and still be exposed because a supplier holding its data was breached. Every platform you hand information to becomes part of your attack surface, whether or not you can see how well it is defended. As services become more interconnected, your security is only ever as strong as that of the third parties you trust with your data — and attackers know a vendor is often the softest way in.
Vendor due diligence that works
Start by knowing which suppliers hold your data and exactly what they hold; you cannot manage a risk you have not mapped. Put security expectations into contracts, and ask for evidence rather than assurances — Cyber Essentials, ISO 27001, a straight answer on breach history. Share the minimum data necessary, review access periodically, and have a plan for being notified if a supplier is compromised. We help clients build this due diligence into how they buy and manage third-party services, so it becomes routine rather than an afterthought.
Source: The Register, 6 June 2026.