July 31st, 2025
When 3rd Party Platforms Turn Cybersecurity Toxic: A Cautionary Tale About Shipping Company Websites
Chad Adams, President of Intrust IT
It’s a Thursday. You are at work, sifting through your Inbox when your phone rings. It’s one of your colleagues from another office asking you about the package you shipped to Baghdad that recently got returned as undeliverable.
“Baghdad?”, you ask, inquisitively. “I haven’t shipped anything to Baghdad in my entire life. What is it?”
You have no recollections of shipping anything outside the U.S. in the last 30 days, and you’ve never shipped anything to Iraq. Your colleague opens the package, and an eerie silence comes over the phone. “Uhhh… it looks like drugs… like illegal packaged drugs!!”. It’s true, the package contains over 6 pounds of illegal narcotics shipped using your corporate FedEx or UPS account. While it may sound like the beginning of a movie, this happened.
In an increasingly interconnected world, third-party software integrations are the gears that keep many businesses running efficiently. From logistics and invoicing to marketing automation and payroll, popular 3rd-party platforms allow companies to scale, streamline, and stay competitive. But with great convenience comes great risk.
In the scenario above, not only is this a technical violation that could result in your privileges to use the service being suspended, but it could also land your company in a legal nightmare and a scramble to protect its reputation.
Hidden Dangers Behind Your Trusted Tools
Third-party tools are often overlooked in traditional cybersecurity planning. We tend to focus on endpoints, email phishing, or ransomware threats. But bad actors increasingly target “backdoors”—the accounts and platforms companies rely on daily, often with weak or outdated credentials and limited visibility into their operations.
Third-party Software as a Service (SaaS) platforms are trusted by default within networks, allowing malicious activity to go undetected for extended periods. In the case mentioned above, the shipping platform was used to create and print legitimate labels, thereby bypassing many detection mechanisms and incurring thousands of dollars in fraudulent shipping charges for the company. Not only was the account abused, but this attack also carried the potential to drag the company into a federal investigation and jeopardize its partnerships, incurring a financial burden that could be catastrophic.
Should I Be Concerned?
Even if your company isn’t in logistics or shipping, the threat is very real. Any 3rd-party platform—be it QuickBooks, Salesforce, DocuSign, or even Zoom—can be leveraged for nefarious purposes once compromised. The consequences can range from compliance violations and data exposure to international legal implications and reputational damage.
What Can I Do?
Here are some key steps every business should take to secure third-party tools:
- Maintain an inventory of 3rd-party services. You can’t protect something that you don’t know you have, nor can you understand the associated risk.
- Enable Multi-Factor Authentication (MFA) on all accounts. It’s your first line of defense.
- Use strong, unique passwords managed by a company-wide password manager. This can’t be stressed enough. If available, consider using a Passkey.
- Limit access rights—not everyone needs admin privileges on every platform. Ensure that users have only the required permissions to perform their job-related tasks.
- Monitor account activity with alerts for unusual usage patterns, such as high-volume actions or logins from unfamiliar regions.
- Audit third-party integrations regularly. Know what’s connected, who has access, and how it’s being used. Keep your inventory updated.
- Educate your team. Human error and lax practices are often the weak links that lead to a compromise like the one mentioned above.
Final Thoughts
Cyber threats are evolving rapidly. They’re no longer just about stealing credit card numbers or deploying ransomware. Attackers are thinking bigger and using your tools, trust, and infrastructure for their illicit purposes. It’s not just a security issue. It’s a business continuity, compliance, and ethical responsibility issue. Now, more than ever, end-user cybersecurity awareness training is essential for the uninterrupted operation of your organization. You owe it to yourself, your employees, your customers, and your vendors to defend against ever-increasing threats that could compromise or harm your organization.