Kiteworks Agent Marketplace
Which AI assistant do you use?
Checklist

Review what your suppliers can still reach

Three incidents made public in September 2026 ran through vendors and third-party platforms. Here is a folder review your supplier owners can run.

  • Access & Sharing
  • Governance & Retention

Much of the data an organisation loses through a supplier was never taken from its own systems. It was handed over, or reachable through a connection, and nobody revisited that access when the work ended. Three incidents made public in September 2026 follow that shape. The practical response is a regular review of what each outside party can still reach.

Three incidents, one shape

None of these investigations is finished, and none of them tells us what the organisations involved should have done. They do show where the exposure sat.

  • IDScan.net. On September 21, 2026, the Office of the Privacy Commissioner of Canada opened an investigation after reports that an unauthorized party "gained access to the company database and stole personal information, including digital scans of driver's licences". Hospitality and nightlife venues use IDScan.net to check customers' IDs, so the venues' customers were exposed through a supplier. The company's own notice says it learned of the access on or around September 1. The scale in most headlines comes from elsewhere: a dark-web listing advertised more than 153 million licence scans, which KrebsOnSecurity traced to IDScan.net. Neither the regulator nor the company has confirmed a number.
  • McKesson. On August 28, McKesson said it was investigating "a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data". Its September 21 update confirmed the access "was limited to certain third-party applications". A criminal group claimed far more; BleepingComputer reported the claim and noted it had not independently verified it.
  • Aeroméxico. In a statement reported by El Financiero on September 21, the airline linked customer data offered online to an October 2025 incident, and said the unauthorized access occurred on a customer information platform managed by an external provider.

The question behind all three

"Is our vendor secure?" is a question for the vendor. "What can each outside party still reach today, and should it?" is a question you can answer yourself. Frameworks already expect it. The NIST Cybersecurity Framework 2.0 (GV.SC-10) asks that supply chain risk plans "include provisions for activities that occur after the conclusion of a partnership or service agreement". The UK ICO's contract guidance says that at the end of a contract the processor must, at the controller's choice, "delete or return to the controller all the personal data it has been processing for it".

Contracts cover what the supplier holds. Your own side of the exchange, the folders you shared for a project, is something you can check this week.

Start with the folders you share

In Kiteworks, supplier exchange often happens in shared folders. Three marketplace agents cover different parts of a review:

  • Sharing Auditor walks a folder scope you choose and reports which folder trees are shared, where each share starts, and how much of the tree it walked. It does not reveal who the members are or whether they are internal or external, and it does not detect files shared directly or sharing above the top folder the scanning user can see.
  • Folder Expiry Audit reports which folders have an expiry or retention setting and which do not. A project folder with no expiry keeps its sharing until someone removes it. The agent reads only; it cannot set expiry.
  • Sensitive Content Scanner finds sensitive terms and common personal data such as Social Security numbers, card numbers and IBANs, which tells you which shared folders to review first.

All three observe metadata or content and can save a report after you confirm where. None of them changes a share, a member, or a setting.

A review a supplier owner can run

  1. List the suppliers and projects that ended in the last twelve months, and the folders used to exchange files with them.
  2. Run Sharing Auditor on each folder. Record the share origins it found and any part of the tree it could not walk.
  3. Run Folder Expiry Audit on the same scope. Note which shared folders have no expiry.
  4. Run Sensitive Content Scanner on the shared folders to decide the order of review.
  5. For each shared folder, the owner confirms through an approved source who should still have access, since the agents cannot see members. Keep, reduce, or remove the share, and record the decision and the date.
  6. Repeat at every contract end and at a fixed interval, for example each quarter.

The agents shorten the finding. The decision to close access, and the conversation with the supplier, stay with the owner.

If you want to walk through a supplier-folder review with us, email sales@kiteworks.com or start a conversation. You do not need Claude or MCP setup to ask. See also Review sharing exposure with AI.

Sources

  1. Privacy Commissioner of Canada launches investigation into a data breach involving stolen identification details · Office of the Privacy Commissioner of Canada ·
  2. Notification of Data Security Incident · IDScan.net ·
  3. FBI Probes Service Selling 153M+ Drivers Licenses · KrebsOnSecurity ·
  4. Cybersecurity updates · McKesson ·
  5. McKesson discloses breach after ShinyHunters claims patient data theft · BleepingComputer ·
  6. Aeroméxico revela que datos de clientes fueron vulnerados en ciberataque · El Financiero ·
  7. The NIST Cybersecurity Framework (CSF) 2.0 · National Institute of Standards and Technology ·
  8. What needs to be included in the contract? · Information Commissioner's Office (UK)