The Change Healthcare attack exposed data tied to roughly 190 million people HHS Breach Portal, meaning patients could be swept up without ever choosing UnitedHealth as an insurer. AT&T later said criminals downloaded call and text records covering nearly all its wireless customers AT&T, meaning an ordinary phone bill became a map of whom someone contacted and when. Different industries, same uncomfortable lesson.
Vertical software has quietly become shared infrastructure.
Verizon’s 2026 Data Breach Investigations Report Verizon DBIR is useful less as a catalogue of villainy than as an incident-reporting framework: identify the actor, initial access, compromised asset and affected data, then follow the dependency chain. Where does that chain end when a vendor handles claims, payments, customer records and regulatory workflows for an entire industry? It often does not end at the breached company. The customer’s customer is already inside.
UnitedHealth recorded roughly $3.1 billion in direct response costs and business disruption from the Change attack during 2024 UnitedHealth SEC Filings, enough to move a cyber incident from an IT budget problem into a board-level earnings event. Axios’s reporting on the outage documented nationwide prescription disruption and described consolidation around a mission-critical provider as a central vulnerability. For hospital finance teams, the damage was more immediate: claims stopped moving, reimbursement slowed and a vendor relationship that had looked like routine plumbing suddenly sat between patient care and payroll.
Vertical applications are rarely just databases with nicer menus. A healthcare clearinghouse translates claims formats, checks eligibility, routes payments and reconciles denials; a telecom data platform ingests identity, billing and network metadata across systems that were never designed to share a security boundary. The engineering can be excellent (and often is), while the resulting concentration remains dangerous. Mandiant connected the Snowflake-focused theft campaign to as many as 165 potentially exposed organizations Google Cloud Threat Intelligence, meaning stolen credentials at scattered customers could be industrialized into a campaign against a common platform. You can see where this is going.
A platform’s integration advantage becomes the attacker’s aggregation advantage.
Why do buyers still model vendor cyber risk as though it were confined to the vendor? Because procurement scores controls, investors reward retention and management teams prefer discussing “mission-critical workflows” to estimating correlated failure. This is a mistake.
The FTC’s breach-response guidance tells companies to preserve evidence, secure operations, notify law enforcement and determine obligations to affected parties FTC, but those steps begin after the architecture has already set the blast radius. And public notices collected by state attorneys general (California’s searchable database is particularly useful) show the recurring legal choreography: an outside service provider discovers unauthorized access, the customer investigates, counsel drafts a notice and individuals learn months later that their data lived somewhere they had never heard of California Attorney General.
For allocators, the diligence question is not whether a vertical SaaS company has security certifications. Ask what percentage of customer workflow stops when the service is unavailable, which identity controls are optional, whether tenant credentials can bypass platform safeguards and how quickly customers can export usable data during an incident. Then map common subcontractors across the portfolio—cloud warehouses, managed file-transfer tools, identity providers, payment processors and claims networks. Credit where it’s due—the best operators already run tabletop exercises with customers rather than staging a tidy internal drill for the audit committee.
Most do not.
The Identity Theft Resource Center counted 3,322 U.S. data compromises during 2025 UpGuard, meaning breach notifications now arrive with the emotional force of credit-card marketing mail. Not great. Volume numbs boards precisely when dependency matters more than incident count.
Vertical SaaS vendors spent years persuading customers to consolidate workflows because integration lowers cost and raises switching barriers. The attackers read the same pitch deck—and circled the switching barriers.