Report finds the sectors’ shared supply chain is the greatest risk, as attackers view wholesale and retail as an interconnected target landscape BOSTON, Jan. 21Report finds the sectors’ shared supply chain is the greatest risk, as attackers view wholesale and retail as an interconnected target landscape BOSTON, Jan. 21

Black Kite’s 2026 Wholesale & Retail Report Reveals Over 70% of Major Retailers, Nearly 60% of Wholesalers, and 52% of the Supply Chain Have Exposed Credentials

2026/01/21 19:32
4 min read

Report finds the sectors’ shared supply chain is the greatest risk, as attackers view wholesale and retail as an interconnected target landscape

BOSTON, Jan. 21, 2026 /PRNewswire/ — Black Kite, the leader in third-party cyber risk management, today announced the release of its 2026 Wholesale & Retail Report: Cyber Exposure in the Age of Digital Supply Chain Attacks, which delves into the cyber risk for retail and wholesale companies that rely on many of the same essential vendors, including IT service providers, software platforms, and financial services. The report found a significant overlap in threat actors actively targeting these two sectors, confirming that they see wholesale and retail not as separate markets but rather as one large, interconnected system of targets.

“When we think about the supply chain, we often picture logistics and warehouses, but today the real threat is the expanded ecosystem,” said Ferhat Dikbiyik, Chief Research & Intelligence Officer, Black Kite. “The bottom line is that wholesale and retail’s greatest risk is their shared supply chain, and as we have seen time and time again, just one vulnerability in a common vendor can create systemic impact affecting both simultaneously. The era of checklist compliance is over. Third party risk management programs must evolve by securing the weak points across every partner in the ecosystem.”

The interconnectedness between wholesale and retail is aggressively exploited by threat actors that view the landscape as a single, lucrative target likely to pay out to minimize supply chain disruption. Additionally, with attackers seeing wholesale and retail as one target, they have developed universal attack tools and malware, such as Stealer Logs and MFT exploits, capable of working across both. Their goal is simply to find the easiest entry point into the system, regardless of which sector that entry point belongs to. For defenders, this tactic means their defense strategies must be unified. For instance, a successful breach into a wholesaler can create an easy entry point leveraged by the same group to be used against a major retailer that uses that particular wholesaler.

One of the report’s most critical findings is the widespread presence of compromised credentials, meaning that initial access has already been granted to a majority of the industry. In fact, over 70% of major retailers, nearly 60% of wholesalers, and 52% of the supply chain have exposed credentials.

Additional key findings include:

  • 17% of retail ransomware victims had revenue over $1B, demonstrating that threat actors prioritize ‘big game hunting’ in the retail sector – a specific target for high-value extortion.
  • 39% of wholesale ransomware victims had revenue in the mid-market range of $20M–$100M as attackers play a ‘volume game’ on smaller enterprises.
  • 42% of critical supply chain vendors are exposed to at least one vulnerability from the CISA Known Exploited Vulnerabilities (KEV) Catalog, listing flaws currently under active attack.
  • 2 vendor categories – Professional & Technical Services (793) and Information (705) –  totaling 1,498 companies, dominate the supply chain, outnumbering physical categories by a significant margin.

The report’s findings are conclusive. The shared supply chain is the new threat, and credential theft is the dominant access vector. In order to protect themselves, wholesalers, retailers and their vendors must urgently prioritize patching the specific vulnerabilities listed in the CISA KEV catalog, particularly those granting Remote Code Execution (RCE), which are the exact flaws active ransomware groups are weaponizing today.

Black Kite’s report empowers cybersecurity leaders and business executives to understand today’s emerging threats and learn how to proactively manage their third-party cyber risk to protect their organizations from supply chain disruptions.

To read the report, visit https://content.blackkite.com/ebook/wholesale-retail-tprm-report-2026/.

About Black Kite
Black Kite is the AI-native third-party cyber risk management platform trusted by over 3,000 customers to manage every supplier and every risk across their extended ecosystem. Powered by the industry’s highest-quality risk intelligence, spanning over 40 million companies, Black Kite is differentiated by the accuracy, transparency, and actionability of its data. The platform automates vendor monitoring and risk assessments, surfacing reliable insights into ransomware susceptibility, regulatory gaps, financial exposure, and more. With Black Kite, security and risk teams gain always-on visibility and trusted intelligence to act early, reduce exposure, and stay ahead of third-party threats. Black Kite has received numerous industry awards and recognition from customers. Learn more at www.blackkite.com, or on the Black Kite blog.

Media Contact:
Michelle Kearney
Hi-Touch PR
443-857-9468
kearney@hi-touchpr.com

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/black-kites-2026-wholesale–retail-report-reveals-over-70-of-major-retailers-nearly-60-of-wholesalers-and-52-of-the-supply-chain-have-exposed-credentials-302661299.html

SOURCE Black Kite

Market Opportunity
Kite AI Logo
Kite AI Price(KITE)
$0.17514
$0.17514$0.17514
-2.36%
USD
Kite AI (KITE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Which Altcoins Stand to Gain from the SEC’s New ETF Listing Standards?

Which Altcoins Stand to Gain from the SEC’s New ETF Listing Standards?

On Wednesday, the US SEC (Securities and Exchange Commission) took a landmark step in crypto regulation, approving generic listing standards for spot crypto ETFs (exchange-traded funds). This new framework eliminates the case-by-case 19b-4 approval process, streamlining the path for multiple digital asset ETFs to enter the market in the coming weeks. Grayscale’s Multi-Crypto Milestone Grayscale secured a first-mover advantage as its Digital Large Cap Fund (GDLC) received approval under the new listing standards. Products that will be traded under the ticker GDLC include Bitcoin, Ethereum, XRP, Solana, and Cardano. “Grayscale Digital Large Cap Fund $GDLC was just approved for trading along with the Generic Listing Standards. The Grayscale team is working expeditiously to bring the FIRST multi-crypto asset ETP to market with Bitcoin, Ethereum, XRP, Solana, and Cardano,” wrote Grayscale CEO Peter Mintzberg. The approval marks the US’s first diversified, multi-crypto ETP, signaling a shift toward broader portfolio products rather than single-asset ETFs. Bloomberg’s Eric Balchunas explained that around 12–15 cryptocurrencies now qualify for spot ETF consideration. However, this is contingent on the altcoins having established futures trading on Coinbase Derivatives for at least six months. This includes well-known altcoins like Dogecoin (DOGE), Litecoin (LTC), and Chainlink (LINK), alongside the majors already included in Grayscale’s GDLC. Altcoins in the Spotlight Amid New Era of ETF Eligibility Several assets have already met the key condition, regulated futures trading on Coinbase. For example, Solana futures launched in February 2024, making the token eligible as of August 19. “The SEC approved generic ETF listing standards. Assets with a regulated futures contract trading for 6 months qualify for a spot ETF. Solana met this criterion on Aug 19, 6 months after SOL futures launched on Coinbase Derivatives,” SolanaFloor indicated. Crypto investors and communities also identified which tokens stand to gain. Chainlink community liaison Zach Rynes highlighted that LINK could soon see its own ETF. He noted that both Bitwise and Grayscale have already filed applications. Meanwhile, the Litecoin Foundation indicated that the new standards provide the regulatory framework for LTC to be listed on US exchanges. Hedera is also in the spotlight, with digital asset investor Mark anticipating an HBAR ETF. Market observers see the decision as a potential turning point for broader adoption, bringing the much-needed clarity and accessibility for investors. At the same time, it boosts confidence in the market’s maturity. The general sentiment is that with the SEC’s approval, the next phase of crypto ETFs is no longer a question of ‘if,’ but ‘when.’ The shift to generic listing standards could expand the US-listed digital asset ETFs roster beyond Bitcoin and Ethereum. Such a move would usher in new investment vehicles covering a dozen or more altcoins. This represents the clearest path yet toward mainstream, regulated access to diversified crypto exposure. More importantly, it comes without the friction of direct custody. “We’re gonna be off to the races in a matter of weeks,” ETF analyst James Seyffart quipped.
Share
Coinstats2025/09/18 12:57
Zhongchi Chefu acquired $1.87 billion worth of digital assets from a crypto giant for $1.1 billion.

Zhongchi Chefu acquired $1.87 billion worth of digital assets from a crypto giant for $1.1 billion.

PANews reported on February 10th that Autozi Internet Technology (Global) Ltd. (AZI), a US-listed Chinese company, has successfully acquired approximately $1.87
Share
PANews2026/02/10 20:36
XRP news: Ripple expands RLUSD stablecoin use in UAE via Zand Bank

XRP news: Ripple expands RLUSD stablecoin use in UAE via Zand Bank

Ripple has expanded the reach of its RLUSD stablecoin in the Middle East through a new strategic partnership with UAE-based digital bank Zand, a move that could
Share
Crypto.news2026/02/10 20:08