30% of confirmed data breaches traced back to a third party or SaaS vendor in 2025, twice the 15% share recorded a year earlier, according to Verizon's 2025 Data Breach Investigations Report. That jump lines up with a run of vendor-linked incidents, including the 2024 breaches tied to stolen Snowflake customer credentials that exposed data at several large companies. For any business running its stack on outside SaaS platforms, that statistic reframes compliance: the biggest privacy risk in 2026 often sits one vendor away.
How many data breaches now trace back to a SaaS or third-party vendor?
30% of confirmed breaches in 2025 involved a third party, up from 15% in Verizon's 2024 edition, a jump the report attributes largely to compromised cloud and SaaS vendor credentials rather than direct attacks on the victim organization's own network. Verizon's 2025 Data Breach Investigations Report is built from a working dataset of 22,052 security incidents and 12,195 confirmed data breaches contributed by dozens of partner organizations worldwide, making it the largest sample the report has ever analyzed.
Figure 1: Third-party involvement in confirmed breaches doubled year over year. Source: Verizon, Data Breach Investigations Report, 2024 and 2025 editions.
Doubling in a single year is a fast move for any metric this large, and it points at a structural shift rather than a one-off event: attackers increasingly target the SaaS vendors that hold data for hundreds of customers at once, because one compromised vendor credential can open a door into many downstream companies simultaneously.
What does the average data breach cost a SaaS company today?
The global average cost of a data breach was $4.44 million in 2025, a 9% decline from the record $4.88 million reported in 2024, according to IBM and the Ponemon Institute's Cost of a Data Breach Report, based on research covering 600 breached organizations across 17 industries. US organizations paid far more, averaging $10.22 million per breach, more than double the global figure.
Figure 2: Average breach cost climbed for four straight years before its first decline in 2025. Source: IBM and Ponemon Institute, Cost of a Data Breach Report, annual editions.
IBM's report does not break out a dedicated "SaaS" industry segment, so the global and US averages remain the most directly applicable benchmark for a software company weighing its own breach exposure. A small business running a SaaS product carries the same headline exposure as any other data controller, since breach costs are driven by incident response, downtime, and notification obligations rather than company size alone.
Who is responsible when a SaaS platform has a data breach?
Responsibility splits along a fixed line. The provider secures the physical infrastructure, network, host operating system, and platform uptime, while the customer, as the data controller, remains responsible for its own access controls, data classification, consent handling, and privacy policy disclosures. Gartner's widely cited 2019 cloud security research projected that 99% of cloud security failures through 2025 would fall on the customer's side of that line, not the provider's, because most cloud and SaaS breaches trace back to customer-side misconfiguration or weak account controls rather than a flaw in the underlying platform.
Figure 3: What a SaaS provider secures versus what the customer, as data controller, must still disclose and configure. Source: Gartner cloud shared-responsibility research, adapted for SaaS compliance obligations.
That 2019 prediction's five-year horizon has now passed, and it has held up directionally even as it aged: most disclosed SaaS-linked incidents since have involved stolen customer credentials, misconfigured access, or an outdated privacy disclosure rather than a break-in at the provider itself. The provider's SOC 2 report never covers the customer's own legal-basis or retention disclosures, which is why an accurate, current privacy policy stays the customer's job regardless of which cloud the data sits on. A privacy policy generator built to cover subprocessor lists, legal basis, and retention periods keeps that half of the split current without a manual rewrite every time a vendor list changes.
How common are cloud data breaches among SaaS-reliant companies?
44% of organizations reported experiencing a cloud data breach in the past 12 months, according to the Thales Cloud Security Study, a survey conducted with S&P Global Market Intelligence's 451 Research. Thales does not publish a fixed year-over-year sample size in every edition, so treat that figure as a snapshot of the 2024 survey wave rather than a tracked trend line. It sits well above Verizon's 30% third-party involvement figure because it counts self-reported cloud incidents broadly, not only confirmed breaches with a documented third-party cause.
Figure 4: More than half of the incidents Verizon investigated in 2025 were confirmed data breaches with a documented data disclosure. Source: Verizon, 2025 Data Breach Investigations Report.
The gap between the two surveys is a reminder that "breach statistics" is not one single number. Verizon counts confirmed breaches with a documented cause; Thales counts any reported cloud security incident. Both point the same direction: a SaaS-heavy stack multiplies the number of parties that can trigger a compliance-relevant incident on your behalf.
What compliance milestones have shaped SaaS privacy since 2019, and do customers actually care?
94% of privacy and security professionals said their customers would not buy from a company that fails to protect data properly, according to Cisco's 2024 Data Privacy Benchmark Study, based on a survey of roughly 2,600 professionals across 12 countries. That figure has stayed high across multiple editions of the same survey, suggesting buyer sensitivity to data protection is now a stable feature of SaaS purchasing decisions, not a passing trend.
Figure 5: Six years of cost records and enforcement trends bracketing the shift toward vendor-linked incidents. Source: IBM/Ponemon Institute, Verizon DBIR, Gartner.
The same buyer scrutiny shows up in retail: e-commerce shoppers abandon checkout over data trust at measurable rates too, which means the pressure to prove data protection now reaches past enterprise procurement teams and down to individual consumers deciding whether to trust a checkout page.
SaaS breach and compliance benchmarks compared
| Metric | Value | Year | Source |
|---|---|---|---|
| Confirmed breaches involving a third party or SaaS vendor | 30% | 2025 | Verizon DBIR |
| Same metric, prior edition | 15% | 2024 | Verizon DBIR |
| Global average cost of a data breach | $4.44M | 2025 | IBM Cost of a Data Breach Report |
| Global average cost of a data breach, US organizations | $10.22M | 2025 | IBM Cost of a Data Breach Report |
| Organizations reporting a cloud data breach in the past 12 months | 44% | 2024 | Thales Cloud Security Study |
| Professionals saying customers would not buy without data protection | 94% | 2024 | Cisco Data Privacy Benchmark Study |
The Bottom Line
The single clearest signal in this year's data is the doubling of third-party involvement in confirmed breaches, from 15% to 30% in one year, per Verizon's 2025 report. Breach costs eased slightly in 2025 after a record 2024, but that decline does not offset the structural shift toward vendor-linked incidents: a compromised SaaS vendor now accounts for roughly one in three confirmed breaches industry-wide. Gartner's shared-responsibility framing still holds, most of that exposure sits on the customer's side of the line, in access controls, consent management, and an accurate privacy policy, not in the provider's infrastructure. For any company built on a SaaS stack, that means the fastest compliance win is not switching vendors. It is closing the disclosure and access-control gaps that sit on your own side of the responsibility split.
Frequently Asked Questions
What share of data breaches involve a third-party or SaaS vendor? 30% of confirmed data breaches involved a third party in 2025, double the 15% recorded a year earlier, according to Verizon's 2025 Data Breach Investigations Report, which analyzed 22,052 security incidents and 12,195 confirmed data breaches worldwide.
How much does the average data breach cost a SaaS company? The global average cost of a data breach was 4.44 million dollars in 2025, and 10.22 million dollars for US organizations specifically, according to IBM and the Ponemon Institute's Cost of a Data Breach Report 2025, based on 600 breached organizations studied.
Who is responsible for a SaaS platform's data breach: the provider or the customer? Both, under a split model. Gartner's widely cited 2019 cloud security research projected that 99% of cloud security failures through 2025 would be the customer's fault, not the provider's, because most cloud and SaaS breaches trace back to customer-side misconfiguration, weak access controls, or an outdated privacy policy rather than a flaw in the provider's infrastructure.
Do SaaS customers actually care whether a vendor protects their data? Yes. 94% of privacy and security professionals said their customers would not buy from a company that does not properly protect data, per Cisco's 2024 Data Privacy Benchmark Study, based on a survey of roughly 2,600 professionals across 12 countries.
Where the Numbers Come From
- IBM Security, in partnership with the Ponemon Institute. (2025). "Cost of a Data Breach Report 2025." Global average cost $4.44 million, US average $10.22 million, based on 600 breached organizations studied.
- Verizon. (2025). "Data Breach Investigations Report 2025." 22,052 security incidents analyzed, 12,195 confirmed data breaches, third-party involvement 30%, up from 15% in the 2024 edition.
- Gartner. (2019). "Is the Cloud Secure?" Research projecting that 99% of cloud security failures through 2025 would be attributable to the customer.
- Cisco. (2024). "Data Privacy Benchmark Study 2024." 94% of respondents said customers would not buy without proper data protection, survey of roughly 2,600 privacy and security professionals across 12 countries.
- Thales, with S&P Global Market Intelligence's 451 Research. (2024). "Cloud Security Study." 44% of organizations reported a cloud data breach in the past 12 months; Thales does not publish a fixed year-over-year sample size across every edition.
Note: All figures verified as of July 2026. Verizon's Data Breach Investigations Report and IBM's Cost of a Data Breach Report both publish new editions annually; figures here are scheduled for refresh at least twice a year to track each new release.